Responsible Disclosure Policy

IAHE takes the security of its website and services seriously. We appreciate the efforts of security researchers and the broader community in responsibly disclosing potential vulnerabilities. This policy outlines how to report security issues and what researchers can expect from us.

Scope

This policy applies to the IAHE website (iahe.com) and its directly operated services. Third-party platforms we integrate with—including NetSuite, Merchant eSolutions, MailChimp, and Google Analytics—are outside the scope of this policy. Please direct reports about those platforms to the respective vendors.

How to Report a Vulnerability

To report a potential security issue, please email security@iahe.com with the following information:

  • A clear description of the vulnerability
  • Steps to reproduce the issue (proof of concept if applicable)
  • The potential impact of the vulnerability
  • Your contact information (optional)

What to Expect

After submitting a report, you can expect the following from us:

  • Acknowledgment of your report within 5 business days
  • Periodic status updates while we investigate
  • Credit on our Security Acknowledgments page, if you would like it

Our Commitments

When you report a vulnerability in good faith under this policy, we commit to the following:

  • We will not pursue legal action against researchers acting in good faith
  • We will not share your personal details without your consent
  • We will work collaboratively with you to understand and resolve the reported issue

Out of Scope

The following activities are explicitly out of scope and must not be performed:

  • Denial-of-service (DoS/DDoS) attacks
  • Social engineering or phishing of IAHE staff or members
  • Physical attacks against IAHE facilities or hardware
  • Automated scanning that generates excessive traffic
Contact Us

Have questions?

Contact Us