iAudit Global vulnerability disclosure programme and security reporting process
Security
August 19, 20268 Min Read
Back To Blog

Inside iAudit Global's Vulnerability Disclosure Programme and Security Reporting Process

iAudit Global has introduced a vulnerability disclosure programme to provide a structured and responsible way for reporting security vulnerabilities across its SaaS platform. The programme defines how security issues in apps.iaudit.global and site-mateai.co.uk should be reported, reviewed, and resolved.

It covers key areas such as authentication security, API endpoints, access control, and data handling, while clearly defining out of scope activities to protect users and system stability.

The process includes safe harbour protection for good faith security research, coordinated disclosure before public release, and a defined lifecycle from report submission through triage and remediation.

Security researchers and users can report vulnerabilities directly to security@iaudit.global, with recognised contributions featured in the iAudit Global Security Hall of Fame.

Security in SaaS platforms is never static. It depends on continuous testing, responsible reporting, and fast remediation when issues are discovered.

A structured vulnerability disclosure programme has been introduced to make that process clearer across iAudit Global systems. It provides a defined way for security researchers and users to report potential vulnerabilities, and ensures that every valid issue is handled through a consistent and coordinated workflow.

This programme applies to platforms including apps.iaudit.global and site-mateai.co.uk, where authentication systems, APIs, and role based access control form the core of the architecture.

What is iAudit Global's vulnerability disclosure programme

iAudit Global vulnerability disclosure programme overview

A vulnerability disclosure programme is a structured way for security issues to be reported and handled.

Instead of vulnerabilities being shared through informal channels, this programme defines a clear reporting route, a defined scope, and a consistent response process.

For iAudit Global, this means security findings are not treated as isolated events. They are part of a wider system of improvement that supports the stability and integrity of our SaaS platform.

This is not a bug bounty programme. There are no financial rewards. The focus is on responsible reporting, timely remediation, and recognition for meaningful contributions.

Why iAudit Global is introducing a vulnerability disclosure programme

We operate a SaaS platform that supports audit management, compliance workflows, and sensitive operational data. These systems rely heavily on authentication, APIs, and role based access control.

Because of this, security issues must be handled with precision and speed.

We are introducing this programme for three key reasons.

First, to clarity for security researchers.

We want anyone who discovers a potential vulnerability to know exactly where to report it and what to expect.

Second, to improved response consistency.

A structured process ensures that valid issues are not lost in general support queues and are handled by the right teams.

Third, to stronger system resilience.

External security research helps identify edge cases that internal testing may not always capture.

What systems are covered under the iAudit Global vulnerability disclosure programme

Systems in scope for iAudit Global security testing

The programme applies only to specific systems that are explicitly in scope.

At present, this includes:

apps.iaudit.global

Hosts our core audit management platform.

site-mateai.co.uk

Supports our AI powered compliance tools.

Within these systems, the programme covers security related issues such as:

  • Authentication

  • Authorisation

  • Session handling

  • API security

  • Data exposure risks

  • Business logic vulnerabilities with a security impact

We do not extend testing to third party systems, external integrations, or any services not owned by iAudit Global.

What security testing is not allowed at iAudit Global

To protect users and maintain system stability, certain activities are not permitted under this programme.

Denial of service testing

Social engineering attempts

Testing against real customer accounts without permission

Automated scanning that impacts platform performance

These restrictions are not there to limit research. They exist to ensure that security testing does not interfere with live users or production data.

How safe harbour protection works in the iAudit Global programme

We recognise that security research sometimes involves controlled interaction with live systems. To support this, we provide safe harbour protection for researchers who follow the programme rules.

This means that if a vulnerability is discovered and reported in good faith, and the researcher operates within the defined scope, we will not pursue legal action related to that research activity.

Safe harbour applies when testing is limited, no real user data is accessed beyond what is necessary for demonstration, and findings are reported responsibly without public disclosure before coordination.

Safe harbour does not apply where there is malicious intent, disruption of services, or unauthorised access to customer data.

How to report a security vulnerability to iAudit Global

How to report a security vulnerability to iAudit Global

All security vulnerabilities should be reported directly to:

To help us triage reports efficiently, please use the following subject format:

[VDP] Vulnerability Type - Affected Asset

For example:

[VDP] IDOR on User Profile Endpoint - apps.iaudit.global

A strong report should include clear reproduction steps, a description of the issue, the affected endpoint or feature, and any supporting evidence such as request logs or screenshots. The more precise the report, the faster it can be validated and resolved.

👉For full reporting guidelines, visit: https://www.iaudit.global/security/vulnerability-disclosure-policy

What happens after you report a vulnerability to iAudit Global

Vulnerability report workflow at iAudit Global

Once a vulnerability report is submitted, it follows a structured internal workflow.

1

Acknowledgement

We acknowledge receipt within two to three business days.

2

Triage

We perform initial triage within five to seven business days to confirm whether the issue is valid, invalid, or requires additional detail.

3

Remediation

If the issue is confirmed, it is assigned to our engineering team for remediation. We may contact the reporter during this stage if further clarification is needed.

4

Closure

Once the issue is resolved, we notify the researcher and close the report.

How iAudit Global recognises security researchers

We value the contribution of security researchers who help improve the resilience of our platform.

Accepted reports may be recognised on our Security Hall of Fame, which lists contributors along with their name or alias, professional profile, and number of accepted submissions.

👉View the Hall of Fame: https://www.iaudit.global/security/hall-of-fame

In addition, researchers who reach contribution milestones may receive formal letters of appreciation issued on official company letterhead. These recognise validated contributions and provide structured acknowledgement of ongoing engagement.

How coordinated disclosure works at iAudit Global

We follow a coordinated disclosure approach to ensure that vulnerabilities are resolved before any public discussion takes place.

This means that any planned public disclosure should only happen after remediation is complete or after a timeline has been agreed with our security team.

If a researcher intends to publish findings, we ask that they contact us in advance so that disclosure can be aligned with remediation timelines.

Why this vulnerability disclosure programme matters

This programme is part of how we maintain the security and reliability of iAudit Global systems.

It creates a clear channel for reporting vulnerabilities, reduces uncertainty for researchers, and ensures that security issues are handled consistently across our platform.

More importantly, it supports continuous improvement. External security input helps us strengthen authentication systems, API security, and data handling processes over time.

Report a security issue in iAudit Global

If you believe you have found a security vulnerability in any iAudit Global system, please report it through our official channel:

👉https://www.iaudit.global/security/vulnerability-disclosure-policy

To view recognised researchers and past contributions, visit:

👉https://www.iaudit.global/security/hall-of-fame

Security works best when it is collaborative, structured, and handled early.

We encourage responsible disclosure from researchers and users who identify potential issues in our systems. Every valid report helps us improve the reliability and security of the platform.

Report a security vulnerability responsibly

Email security@iaudit.global with the subject format [VDP] Vulnerability Type - Affected Asset, or read the full disclosure policy for scope, safe harbour, and reporting guidelines.

Support

Frequently asked questions

Ready to upgrade?

Ready To Upgrade Your
Audit Process?

Join the global community of auditors who have moved beyond spreadsheets. Create oversight in days, not months.

Just pay what you see
No hidden fees
iAuditGLOBAL
OVERVIEW
Dashboard
MANAGEMENT
Company
Users
Self Assessment
Gap Analysis
Audit Program
Findings

Audit Summary

Overall compliance status

49%
Requires Improvement
Comply
OFI
NC

Clause Breakdown

Compliance by ISO clause

4. Context
11%
5. Leadership
90%
6. Planning
33%
7. Support
0%
8. Operation
50%
9. Performance
50%
10. Improvement
60%
Start free trial