Everything, in One Place.
Security, privacy, compliance, and legal — the documents a procurement or security team needs before working with us, all in one place.
Security & Compliance
Where we stand — encryption, human oversight, subprocessors, and the standards we're working toward.
ReadPrivacy Policy
What we collect, why, and the choices you have. Built on PIPEDA and Alberta PIPA.
ReadData Processing Agreement
How we process your data as your processor — available to sign for any engagement.
ReadSubprocessors
The third parties that help us deliver the service, with purpose and region.
ReadMessaging (SMS) Terms
Consent, message types, frequency, rates, and how to opt out of texts.
ReadAcceptable Use Policy
The rules for using our sites, products, and AI features safely and legally.
ReadCookies & Tracking
Essential cookies plus privacy-friendly, cookieless analytics — no advertising or cross-site tracking.
ReadAccessibility
Our commitment to WCAG 2.1 AA and how to request an accommodation.
ReadTerms of Service
The terms that govern use of our site and services.
ReadAI Ethics
The principles behind how we build and deploy AI responsibly.
ReadThe Questions We Settle in Writing.
These get answered for your project specifically and written into the scope agreement, because it differs by build. We would rather set them out as questions than publish a blanket promise that would not hold for every engagement.
Where is it hosted, and where does the data sit?
Named per project, along with the region. Our standing infrastructure and the region of every subprocessor we use are listed on the Security & Compliance page; your build's specific hosting is agreed in the scope rather than assumed from that list.
Who can see and do what?
Role-based access with least privilege is how we build — office, field and management each get the view they need. Which roles exist, and what each one can read and change, is decided with you during discovery and written down.
What does any AI feature actually process?
Which data a feature sends to a model, which provider handles it, and what a person reviews before anything reaches a customer or a ledger. We do not train models on your data. Where AI drafts something with a real cost of being wrong, a human approves it.
What are the backups, and what does restoring look like?
Backup frequency, retention and the restore procedure are set per project against what the business can actually tolerate losing. We would rather agree that explicitly than leave you to discover it during an incident.
Who owns the system and the data in it?
You do. The software is built for your business, and the data in it is yours and exportable on request. Export format and how you get it are part of the agreement, not a favour asked later.
What happens if we stop working together?
Agreed up front: what you keep, how the data comes out, and what handover involves. Your business records stay exportable in an agreed format under every ownership model.
What does support actually cover once it is live?
What we monitor, what counts as a fix versus a change, and what response you can expect — set out in the operating arrangement. We operate what we ship rather than handing over a repository.
Will you sign our DPA or complete our security questionnaire?
Yes. A Data Processing Agreement is available for any engagement, and we complete vendor-security questionnaires. Send yours and we will answer it, including the parts where we do not hold a given certification.
We do not claim certifications we do not hold. SOC 2 Type II and ISO/IEC 42001 are standards we are working toward, and they are described that way on the Security & Compliance page, which also lists every subprocessor we use and the region it operates in.
Your Business Stays Confidential.
The work is real and so are the results. Who it was for stays between us. How your data and rights are handled is set out on Ownership.
Case Studies Stay Anonymous
We don't name clients in our case studies. Each one describes the trade, the city and the result — never the business behind it.
Your Numbers Stay Yours
Your pricing, documents, formulas and operating information are used to build your system and are never reused for another client.
References on Request
Want to hear it from a client directly? Ask on a call and we'll connect you with one.
The AI Does the Work. You Sign Off.
AltaGate is the safeguard layer in every system we build: a set of instructions and parameters that keeps the AI to your real data and holds anything customer-facing until a person approves it.
How AltaGate worksGrounded Answers
Works from your own records, and asks instead of guessing.
Human Sign-Off
Nothing customer-facing goes out until a person approves it.
Permission Levels
Draft-only, ask-first or automatic — money and clients stay owner-approved.
Audit Trail
Every draft, approval and action recorded: what, who and when.
Questions to Ask Any Software Vendor.Including Us.
Custom software can quietly become a dependency rather than an asset: you own something only one firm can maintain, and the ownership is nominal. These are the questions that expose it. Put them to us, and put them to whoever else you are talking to — a vendor who gets uncomfortable here is telling you something.
Do we get the source code?
Under a Client-Owned Build, yes: the project source code, agreed documentation and the rights to operate, modify or transition the system are transferred to your company. Under a build on Alberta Professional Core, AltaPro AI retains the underlying platform and you control your data, workflows and configuration. Which model applies is settled in the agreement before engineering begins — the three models are set out on the Ownership Models page, and the commitment is the clause in the agreement you sign.
Could another developer maintain this without you?
This is the question that separates an asset from a dependency, and it is worth asking us directly. A build that only its author can maintain is a liability no matter what the brochure calls it. Ask what would be handed over, in what form, and whether the agreement permits a third party to work on it.
Where does it run, and could it run somewhere else?
The platforms we build on and the region each operates in are listed on the Security & Compliance page. Whether a given build is deployed into infrastructure you control is a scoping decision — ask for it explicitly if portability matters to you, because it changes how a system is built, not just where it is hosted.
Has it been independently penetration tested?
We do not publish a penetration test report. If that is a requirement for your engagement, raise it early — it is a reasonable thing to ask for and a reasonable thing to scope and pay for, and we would rather tell you that plainly than let you assume one exists.
Nothing above is a contractual commitment — a marketing page is not the place to make one, and you should not accept one from any vendor on that basis. What is written here is how we will answer when you ask, and what ends up in your agreement is what actually binds.
Systems Running in Production.
The most useful trust signal we have is software that has been in daily use by real businesses. Every figure below is reported by the business running the system, not independently audited.
4 hrs → 20 min
Edmonton landscaping company · live in production
Read it2–3 hrs → minutes
A demolition contractor · live in production
Read itFive systems → one
General contractor · live in production
Read it“We were scaling and needed real systems behind it. AltaPro AI built us our own platform from scratch — jobs, crews, clients, map view, syncs to our books. Didn't have to explain how the trades work, they already knew it. Built fast, changes handled same way. Does exactly what we needed.”
“Great experience working with AltaPro AI. Haruun and his team were easy to work with, responsive, and really took the time to understand what we needed. Everything was handled professionally and we're really happy with how it turned out. Would definitely recommend them.”
“Helpful, Professional & Provide Great Service.”
Quotes are published as written by the reviewer and attributed to the client company. We publish no star ratings, review counts or aggregate-rating markup anywhere on this site.
For procurement & security teams
Need a DPA or a Security Review?
Send us your vendor-security questionnaire, request a Data Processing Agreement, or ask anything about how we handle data. We answer straight.