Responsible Disclosure Policy
IAHE takes the security of its website and services seriously. We appreciate the efforts of security researchers and the broader community in responsibly disclosing potential vulnerabilities. This policy outlines how to report security issues and what researchers can expect from us.
Scope
This policy applies to the IAHE website (iahe.com) and its directly operated services. Third-party platforms we integrate with—including NetSuite, Merchant eSolutions, MailChimp, and Google Analytics—are outside the scope of this policy. Please direct reports about those platforms to the respective vendors.
How to Report a Vulnerability
To report a potential security issue, please email security@iahe.com with the following information:
- A clear description of the vulnerability
- Steps to reproduce the issue (proof of concept if applicable)
- The potential impact of the vulnerability
- Your contact information (optional)
What to Expect
After submitting a report, you can expect the following from us:
- Acknowledgment of your report within 5 business days
- Periodic status updates while we investigate
- Credit on our Security Acknowledgments page, if you would like it
Our Commitments
When you report a vulnerability in good faith under this policy, we commit to the following:
- We will not pursue legal action against researchers acting in good faith
- We will not share your personal details without your consent
- We will work collaboratively with you to understand and resolve the reported issue
Out of Scope
The following activities are explicitly out of scope and must not be performed:
- Denial-of-service (DoS/DDoS) attacks
- Social engineering or phishing of IAHE staff or members
- Physical attacks against IAHE facilities or hardware
- Automated scanning that generates excessive traffic