Legal
Vulnerability disclosure policy
We welcome reports of security vulnerabilities in iioet.org and its subdomains. Emailcontact@iioet.org with "Security" in the subject line. Oursecurity.txt carries the same details.
Please
- Give us enough detail to reproduce the issue, and a reasonable time to fix it before disclosing it.
- Test only against your own data; do not access, change or delete other people's data.
- Do not run denial-of-service, spam or social engineering tests, or test physical security.
- Never submit real payment card details.
We will
- Acknowledge your report within five working days and keep you informed.
- Not pursue legal action for good-faith research that follows this policy.
- Credit you, if you wish, once the issue is fixed.
Issues in the member area or payment pages may be in a provider's systems; we will pass them on and coordinate.