Legal

Vulnerability disclosure policy

Last updated: 7 October 2026

We welcome reports of security vulnerabilities in iioet.org and its subdomains. Emailcontact@iioet.org with "Security" in the subject line. Oursecurity.txt carries the same details.

Please

  • Give us enough detail to reproduce the issue, and a reasonable time to fix it before disclosing it.
  • Test only against your own data; do not access, change or delete other people's data.
  • Do not run denial-of-service, spam or social engineering tests, or test physical security.
  • Never submit real payment card details.

We will

  • Acknowledge your report within five working days and keep you informed.
  • Not pursue legal action for good-faith research that follows this policy.
  • Credit you, if you wish, once the issue is fixed.

Issues in the member area or payment pages may be in a provider's systems; we will pass them on and coordinate.