Security

Security at IOthreat

Security is core to what we do. We welcome reports from the community and are committed to working with researchers to keep our systems and our customers safe.

Reporting a vulnerability

If you believe you have found a security vulnerability in any IOthreat property — this website, our applications, or our infrastructure — please report it privately to security@iothreat.com. Where possible, include a description and potential impact, steps to reproduce, and any supporting material.

Please do not open a public issue or post about security matters — private disclosure protects users while we investigate and fix.

Our commitment

  • We acknowledge reports within 2 business days.
  • We provide an assessment and expected remediation timeline within 10 business days.
  • We keep you informed through to a fix, and confirm when it is resolved.
  • With your permission, we are happy to credit you once the issue is remediated.

Scope

In scope: IOthreat-owned websites, applications, APIs, and infrastructure. Out of scope: findings requiring physical access, social engineering of staff, denial-of-service testing, or automated scanner output without a demonstrated, exploitable impact.

Safe harbor

We will not pursue or support legal action against researchers who make a good-faith effort to comply with this policy, avoid privacy violations and service disruption, and give us reasonable time to remediate before any public disclosure.

Thank you for helping keep IOthreat and our customers secure.