TRUST & SECURITY

Security at Actveris

Our public security principles, disclosure boundary and responsible process for reporting suspected vulnerabilities affecting Actveris.

Last updated: 10 September 2026

1. Security at Actveris

Security is central to Actveris’s work on Runtime Authority Infrastructure. Our public security communications are designed to explain our security posture and reporting channels without exposing confidential implementation architecture, source code, credentials, exploitable configuration, customer information or vulnerability-enabling operational detail.

Disclosure boundary. Public descriptions of Runtime Authority are conceptual and assurance-oriented. They are not intended to disclose the internal implementation of Actveris systems or provide instructions for bypassing security controls.

2. Security Principles

Actveris’s security programme is intended to be guided by principles including least privilege, separation of duties, strong identity and access controls, protected execution paths, auditable decision evidence, secure software-development practices, dependency and vulnerability management, environment separation, monitoring, incident response, backup and recovery, and controlled change management.

We will state certifications, audits or formal attestations publicly only when they have actually been obtained and remain applicable. References to frameworks or standards on this website should not be interpreted as certification unless expressly stated.

3. Website and Public Services

The public Actveris website is hosted using third-party infrastructure and may rely on additional providers for content delivery, email, document delivery and related services. We take reasonable measures to reduce security risk, but no public internet service can be guaranteed to be immune from every vulnerability, outage or attack.

4. Reporting a Security Vulnerability

If you believe you have identified a security vulnerability affecting an Actveris public website, service or product, please report it promptly and privately to info@actveris.com with the subject line “Security Vulnerability Report”. We recommend establishing a dedicated address such as security@actveris.com before final publication.

Please include enough information to reproduce and assess the issue, such as the affected asset, date and time observed, vulnerability type, steps to reproduce, potential impact, and any relevant screenshots or logs. Do not include personal data or confidential third-party information unless necessary and lawfully obtained.

5. Responsible Security Research

Actveris welcomes good-faith reporting of suspected vulnerabilities. Unless Actveris has expressly authorised testing in writing, the following activities are outside the permitted scope:

  • accessing, copying, changing or deleting data that does not belong to you;

  • attempting to obtain credentials, secrets or confidential information;

  • social engineering, phishing or physical intrusion;

  • denial-of-service, resource exhaustion or high-volume automated testing;

  • installing persistence, malware or backdoors;

  • testing customer environments or third-party systems without their explicit authorisation;

  • using a vulnerability to move beyond the minimum action necessary to demonstrate that an issue may exist;

  • public disclosure before Actveris has had a reasonable opportunity to investigate and remediate the issue.

Singapore’s Computer Misuse Act 1993 prohibits unauthorised access and other forms of unauthorised computer activity. This Security page does not grant permission to perform any act that would otherwise be unauthorised under applicable law.

6. What You Can Expect From Us

For credible reports submitted in good faith, Actveris intends to acknowledge receipt, assess the reported issue, seek clarification where needed, prioritise remediation based on risk, and coordinate disclosure where appropriate. Response times will depend on the severity, complexity and affected environment.

We do not currently promise a monetary bug bounty unless a specific programme is separately announced in writing.

7. Confidentiality and Coordinated Disclosure

We ask reporters to keep vulnerability information confidential until we have confirmed remediation or agreed an appropriate disclosure timeline. Actveris may coordinate with relevant vendors, customers, service providers, CERTs or authorities where necessary to investigate and mitigate risk.

8. Security Incidents and Personal Data

If an incident involves personal data, Actveris will assess notification obligations under applicable data-protection law. In Singapore, the PDPA requires organisations to assess whether a personal-data breach is notifiable and, where statutory thresholds are met, notify the Personal Data Protection Commission and affected individuals as required.

9. Assurance and Public Claims

Actveris distinguishes conceptual architecture, implementation claims and independently supported assurance claims. Public security or resilience claims should be scoped to the relevant version, environment, test boundary and threat model. We do not treat the absence of a reported incident as proof that a system is invulnerable.

10. Legal and Regulatory Context

Actveris is based in Singapore and is subject to applicable Singapore law. Depending on the services provided, customer sector and deployment context, additional contractual, regulatory or sector-specific requirements may apply. Nothing on this public Security page should be interpreted as stating that Actveris is designated as Critical Information Infrastructure or holds a certification, licence or regulatory status unless expressly confirmed elsewhere.

11. Security Contact

Until a dedicated security mailbox is established, send security concerns to info@actveris.com with the subject line “Security Vulnerability Report”.