Security
Security at IOthreat
Security is core to what we do. We welcome reports from the community and are committed to working with researchers to keep our systems and our customers safe.
Reporting a vulnerability
If you believe you have found a security vulnerability in any IOthreat property — this website, our applications, or our infrastructure — please report it privately to security@iothreat.com. Where possible, include a description and potential impact, steps to reproduce, and any supporting material.
Please do not open a public issue or post about security matters — private disclosure protects users while we investigate and fix.
Our commitment
- We acknowledge reports within 2 business days.
- We provide an assessment and expected remediation timeline within 10 business days.
- We keep you informed through to a fix, and confirm when it is resolved.
- With your permission, we are happy to credit you once the issue is remediated.
Scope
In scope: IOthreat-owned websites, applications, APIs, and infrastructure. Out of scope: findings requiring physical access, social engineering of staff, denial-of-service testing, or automated scanner output without a demonstrated, exploitable impact.
Safe harbor
We will not pursue or support legal action against researchers who make a good-faith effort to comply with this policy, avoid privacy violations and service disruption, and give us reasonable time to remediate before any public disclosure.
Thank you for helping keep IOthreat and our customers secure.