Inside iAudit Global's Vulnerability Disclosure Programme and Security Reporting Process
iAudit Global has introduced a vulnerability disclosure programme to provide a structured and responsible way for reporting security vulnerabilities across its SaaS platform. The programme defines how security issues in apps.iaudit.global and site-mateai.co.uk should be reported, reviewed, and resolved.
It covers key areas such as authentication security, API endpoints, access control, and data handling, while clearly defining out of scope activities to protect users and system stability.
The process includes safe harbour protection for good faith security research, coordinated disclosure before public release, and a defined lifecycle from report submission through triage and remediation.
Security researchers and users can report vulnerabilities directly to security@iaudit.global, with recognised contributions featured in the iAudit Global Security Hall of Fame.
Security in SaaS platforms is never static. It depends on continuous testing, responsible reporting, and fast remediation when issues are discovered.
A structured vulnerability disclosure programme has been introduced to make that process clearer across iAudit Global systems. It provides a defined way for security researchers and users to report potential vulnerabilities, and ensures that every valid issue is handled through a consistent and coordinated workflow.
This programme applies to platforms including apps.iaudit.global and site-mateai.co.uk, where authentication systems, APIs, and role based access control form the core of the architecture.
What is iAudit Global's vulnerability disclosure programme
A vulnerability disclosure programme is a structured way for security issues to be reported and handled.
Instead of vulnerabilities being shared through informal channels, this programme defines a clear reporting route, a defined scope, and a consistent response process.
For iAudit Global, this means security findings are not treated as isolated events. They are part of a wider system of improvement that supports the stability and integrity of our SaaS platform.
This is not a bug bounty programme. There are no financial rewards. The focus is on responsible reporting, timely remediation, and recognition for meaningful contributions.
Why iAudit Global is introducing a vulnerability disclosure programme
We operate a SaaS platform that supports audit management, compliance workflows, and sensitive operational data. These systems rely heavily on authentication, APIs, and role based access control.
Because of this, security issues must be handled with precision and speed.
We are introducing this programme for three key reasons.
First, to clarity for security researchers.
We want anyone who discovers a potential vulnerability to know exactly where to report it and what to expect.
Second, to improved response consistency.
A structured process ensures that valid issues are not lost in general support queues and are handled by the right teams.
Third, to stronger system resilience.
External security research helps identify edge cases that internal testing may not always capture.
What systems are covered under the iAudit Global vulnerability disclosure programme
The programme applies only to specific systems that are explicitly in scope.
At present, this includes:
apps.iaudit.global
Hosts our core audit management platform.
site-mateai.co.uk
Supports our AI powered compliance tools.
Within these systems, the programme covers security related issues such as:
- ✓
Authentication
- ✓
Authorisation
- ✓
Session handling
- ✓
API security
- ✓
Data exposure risks
- ✓
Business logic vulnerabilities with a security impact
We do not extend testing to third party systems, external integrations, or any services not owned by iAudit Global.
What security testing is not allowed at iAudit Global
To protect users and maintain system stability, certain activities are not permitted under this programme.
Denial of service testing
Social engineering attempts
Testing against real customer accounts without permission
Automated scanning that impacts platform performance
These restrictions are not there to limit research. They exist to ensure that security testing does not interfere with live users or production data.
How safe harbour protection works in the iAudit Global programme
We recognise that security research sometimes involves controlled interaction with live systems. To support this, we provide safe harbour protection for researchers who follow the programme rules.
This means that if a vulnerability is discovered and reported in good faith, and the researcher operates within the defined scope, we will not pursue legal action related to that research activity.
Safe harbour applies when testing is limited, no real user data is accessed beyond what is necessary for demonstration, and findings are reported responsibly without public disclosure before coordination.
Safe harbour does not apply where there is malicious intent, disruption of services, or unauthorised access to customer data.
How to report a security vulnerability to iAudit Global
All security vulnerabilities should be reported directly to:
To help us triage reports efficiently, please use the following subject format:
[VDP] Vulnerability Type - Affected AssetFor example:
[VDP] IDOR on User Profile Endpoint - apps.iaudit.globalA strong report should include clear reproduction steps, a description of the issue, the affected endpoint or feature, and any supporting evidence such as request logs or screenshots. The more precise the report, the faster it can be validated and resolved.
👉For full reporting guidelines, visit: https://www.iaudit.global/security/vulnerability-disclosure-policy
What happens after you report a vulnerability to iAudit Global
Once a vulnerability report is submitted, it follows a structured internal workflow.
Acknowledgement
We acknowledge receipt within two to three business days.
Triage
We perform initial triage within five to seven business days to confirm whether the issue is valid, invalid, or requires additional detail.
Remediation
If the issue is confirmed, it is assigned to our engineering team for remediation. We may contact the reporter during this stage if further clarification is needed.
Closure
Once the issue is resolved, we notify the researcher and close the report.
How iAudit Global recognises security researchers
We value the contribution of security researchers who help improve the resilience of our platform.
Accepted reports may be recognised on our Security Hall of Fame, which lists contributors along with their name or alias, professional profile, and number of accepted submissions.
👉View the Hall of Fame: https://www.iaudit.global/security/hall-of-fame
In addition, researchers who reach contribution milestones may receive formal letters of appreciation issued on official company letterhead. These recognise validated contributions and provide structured acknowledgement of ongoing engagement.
How coordinated disclosure works at iAudit Global
We follow a coordinated disclosure approach to ensure that vulnerabilities are resolved before any public discussion takes place.
This means that any planned public disclosure should only happen after remediation is complete or after a timeline has been agreed with our security team.
If a researcher intends to publish findings, we ask that they contact us in advance so that disclosure can be aligned with remediation timelines.
Why this vulnerability disclosure programme matters
This programme is part of how we maintain the security and reliability of iAudit Global systems.
It creates a clear channel for reporting vulnerabilities, reduces uncertainty for researchers, and ensures that security issues are handled consistently across our platform.
More importantly, it supports continuous improvement. External security input helps us strengthen authentication systems, API security, and data handling processes over time.
Report a security issue in iAudit Global
If you believe you have found a security vulnerability in any iAudit Global system, please report it through our official channel:
👉https://www.iaudit.global/security/vulnerability-disclosure-policy
To view recognised researchers and past contributions, visit:
👉https://www.iaudit.global/security/hall-of-fame
Security works best when it is collaborative, structured, and handled early.
We encourage responsible disclosure from researchers and users who identify potential issues in our systems. Every valid report helps us improve the reliability and security of the platform.

