Information Security
Vulnerability Disclosure Program
Responsible Disclosure Policy | Security Vulnerability Reporting | Version 1.0 | Effective June 2026
1. Introduction
iAudit Global is a UK-based SaaS audit and compliance platform committed to maintaining the highest standards of security for our customers and their data. We take security very seriously and believe that responsible security research plays a vital role in keeping the digital ecosystem safe.
If you believe you've found a security vulnerability in our systems, we encourage you to report it. If you find a security issue, please submit a vulnerability report to our security team. We value security researchers and are committed to working with the white hat community in good faith.
This Vulnerability Disclosure Program (VDP) outlines how researchers can responsibly disclose vulnerabilities to iAudit Global.
By submitting a vulnerability report to iAudit Global, the researcher acknowledges that they have read, understood, and agree to comply with the terms of this Vulnerability Disclosure Program.
2. Scope
In Scope
- apps.iaudit.global — iAudit Global web application including all features, endpoints, and API calls
- site-mateai.co.uk — SiteMate AI platform including web interfaces, authentication flows, and API endpointsImportant — SiteMate account registrationWhen registering for a SiteMate account as part of your research, please enter VDP Hunting as your company name. Account requests submitted with this identifier will be reviewed and approved for vulnerability research under this program.
For both targets the following attack surfaces are in scope:
- Authentication and authorisation mechanisms
- User account and session management
- API endpoints and access control logic
- Data handling and sensitive information exposure
- Business logic flaws with security impact
Out of Scope
- Any subdomain or asset not listed above
- Third-party services, plugins, or integrations not directly owned by iAudit Global
- Physical security testing
- Social engineering attacks against iAudit staff, clients, or partners
- Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks
- Automated scanning that generates excessive load or disrupts service availability
- Testing against real client accounts or data belonging to iAudit customers
- Any action that disrupts or degrades the experience of other users
3. Safe Harbour
iAudit Global will not pursue legal action against security researchers who discover and responsibly disclose vulnerabilities in accordance with this policy. We consider good-faith security research to be a lawful and valuable contribution. Provided you comply with this policy, we will not initiate or recommend legal proceedings against you in connection with your research activities.
For safe harbour protections to apply, researchers must:
- Act in good faith and avoid deliberately accessing, modifying, or deleting data
- Limit testing to their own test accounts or dedicated sandbox environments
- Report vulnerabilities promptly and avoid exploitation beyond what is necessary to demonstrate the issue
- Avoid sharing vulnerability details publicly before iAudit Global has had a reasonable opportunity to remediate
- Not use discovered vulnerabilities for personal gain or to harm iAudit Global, its clients, or end users
4. Prohibited Activities
The following are strictly prohibited and will void safe harbour protections:
- Social engineering, phishing, or vishing of iAudit staff, clients, or partners
- Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks in any form
- Accessing, extracting, modifying, or deleting data belonging to iAudit clients or third parties
- Testing using real end-user accounts without explicit written consent from the account holder
- Introducing malware, backdoors, or persistent access mechanisms
- Publicly disclosing vulnerability details before coordinated disclosure is agreed
- Disrupting service availability or degrading performance for other users
5. What We Accept
We accept vulnerability reports across the full severity range. No vulnerability is too small — if you believe it poses a genuine security risk to iAudit Global or its users, we want to hear about it. We appreciate all security reports and will review every submission.
Accepted vulnerability classes include:
- Authentication and authorisation flaws (IDOR, BAC, privilege escalation)
- Injection vulnerabilities (SQL injection, XSS, SSTI, HTML injection)
- Sensitive data exposure and insecure direct object references
- Security misconfigurations and exposed management interfaces
- Business logic flaws with security impact
- SSRF, XXE, and deserialisation vulnerabilities
- API security issues and broken access controls
- Informational disclosures that enable further attack
Not accepted:
- Missing security headers with no demonstrable impact
- Self-XSS requiring significant user interaction with no realistic attack scenario
- Rate limiting issues on non-sensitive endpoints
- Theoretical vulnerabilities without a working proof of concept
- Reports generated entirely by automated scanners without manual validation
6. How to Report
Submit a Vulnerability Report
Send all security vulnerability reports to: security@iaudit.global
Use the subject line format:
[VDP] <Vulnerability Type> – <Affected Asset>
Example: [VDP] IDOR on User Profile Endpoint – apps.iaudit.global
Report Format
7. Our Process & Response Times
8. Researcher Recognition
Hall of Fame
Every researcher with at least one accepted and validated report will be listed on the iAudit Global Security Hall of Fame. Each listing displays:
- Name or alias
- LinkedIn or X (Twitter) handle
- Number of accepted reports
Researchers may opt out of public listing at any time by contacting security@iaudit.global.
Milestone Letters of Appreciation
Researchers who reach the following milestones will receive an official iAudit Global Letter of Appreciation, issued on official letterhead and signed by our security team. Each letter features a recognition badge and confirms the researcher's name and number of validated reports submitted to iAudit Global.
Letters are issued digitally with a verifiable signature.
9. Coordinated Disclosure
iAudit Global follows a coordinated disclosure model. We ask that researchers allow us a reasonable window to investigate and remediate before any public disclosure. If you intend to publish research related to a vulnerability in our systems, please notify us in advance so we can coordinate timing.
10. Duplicate Reports
In the event that multiple researchers report the same vulnerability, recognition will be granted to the first valid, complete report received at security@iaudit.global. Subsequent reports of the same issue will be acknowledged but will not qualify for Hall of Fame listing or Letters of Appreciation.
11. Legal
Governing Law & Jurisdiction
This Vulnerability Disclosure Program is published by iAudit Global Limited, a private limited company registered in England and Wales (Company No. 15826012), with registered office at Unit 17F, The Lansbury Estates, Lower Guildford Road, Knaphill, Woking, Surrey, GU21 2EP.
This policy is governed by the laws of England and Wales. Any disputes arising in connection with this policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Policy Changes
iAudit Global Limited reserves the right to modify, suspend, or terminate this Vulnerability Disclosure Program at any time without prior notice. Changes will be effective upon publication of the updated policy at iaudit.global/security/vulnerability-disclosure-policy.
12. Contact
Machine-readable security contact: /.well-known/security.txt
Report a security vulnerability to iAudit Global
