Skip to content

Security

Report a vulnerability.

If you believe you have found a security issue in ISO Assist, tell us privately. A person reads every report and replies to the reporter.

How to report

Email us. Include what we need to reproduce it.

security@isoassist.com
  • Reproduction steps and the affected page, endpoint or email.
  • The impact you observed, and what you believe an attacker could do with it.
  • Your handle or name if you would like to be credited.
  • No customer data. If you encountered any, stop, tell us what you saw and delete your copy.

In scope

  • app.isoassist.com and its API and MCP endpoints
  • isoassist.com
  • Email sent by the platform (invitations, verification, notifications)

Out of scope

  • Denial-of-service, load testing or automated scanning against production
  • Social engineering of our staff or customers
  • Findings that require physical access to a device
  • Reports from automated tools without a demonstrated impact
  • Missing security headers or best-practice notes with no exploit path

What to expect

Our commitments to you.

ACKNOWLEDGE
Within 2 business days of your report
TRIAGE
Within 5 business days, with a severity and a plan
FIX
Critical: as fast as we safely can, usually within days. High: within 30 days. Other: within 90 days
DISCLOSE
Coordinated with you once the fix is deployed. We credit reporters who want credit

Safe harbour

Good-faith research is welcome.

If you follow this policy, act in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before disclosing it, we will not pursue legal action against you and will not refer your research to law enforcement.

We do not run a paid bounty programme. We do credit reporters publicly on request once a fix has shipped.