Help us protect the ecosystem.
IRIS values good-faith security research. If you believe you have found a vulnerability in a public digital service controlled by IRIS, report it promptly and give us a reasonable opportunity to investigate and remediate before public disclosure.
What is in scope
Publicly accessible websites, applications, and internet-facing services that are owned and controlled by IRIS Technology are in scope unless they state otherwise. Customer environments, partner platforms, employee personal accounts, and third-party services are not authorized targets.
Rules of engagement
- Use the minimum testing needed to confirm the issue.
- Do not access, alter, copy, retain, or disclose data belonging to others.
- Do not use denial-of-service, destructive testing, malware, credential attacks, social engineering, physical intrusion, or automated activity that degrades service.
- Stop immediately if you encounter sensitive data or affect availability.
- Do not demand payment or threaten disclosure.
What to include
Provide the affected URL or asset, vulnerability type, clear reproduction steps, evidence with sensitive information removed, potential impact, test date, and a safe way to contact you. Include suggested remediation when useful.
How to report
Use the appropriate branch email and start the subject with Security Vulnerability Disclosure. Do not send active exploit code, credentials, personal data, or large sensitive attachments in the first message.
What to expect
We aim to acknowledge a complete report, assess severity, coordinate remediation, and communicate material progress when practical. Response time depends on complexity, impact, affected parties, and third-party dependencies. Submission does not create an employment, contractual, or compensation obligation.
Good-faith research
When research follows this policy, is lawful, and is conducted to improve security rather than cause harm, IRIS will treat it as authorized under this policy and will work toward constructive resolution. This does not authorize activity prohibited by applicable law or affecting systems outside our control.
