iAudit Global company logo

Information Security

Vulnerability Disclosure Program

Responsible Disclosure Policy | Security Vulnerability Reporting | Version 1.0 | Effective June 2026

Cybersecurity professional reviewing system security on a monitor
IntroductionScopeSafe HarbourProhibited ActivitiesWhat We AcceptHow to ReportOur ProcessResearcher RecognitionCoordinated DisclosureDuplicate ReportsLegalContact

1. Introduction

iAudit Global is a UK-based SaaS audit and compliance platform committed to maintaining the highest standards of security for our customers and their data. We take security very seriously and believe that responsible security research plays a vital role in keeping the digital ecosystem safe.

If you believe you've found a security vulnerability in our systems, we encourage you to report it. If you find a security issue, please submit a vulnerability report to our security team. We value security researchers and are committed to working with the white hat community in good faith.

This Vulnerability Disclosure Program (VDP) outlines how researchers can responsibly disclose vulnerabilities to iAudit Global.

By submitting a vulnerability report to iAudit Global, the researcher acknowledges that they have read, understood, and agree to comply with the terms of this Vulnerability Disclosure Program.

2. Scope

In Scope

  • apps.iaudit.global — iAudit Global web application including all features, endpoints, and API calls
  • site-mateai.co.uk — SiteMate AI platform including web interfaces, authentication flows, and API endpoints
    Important — SiteMate account registrationWhen registering for a SiteMate account as part of your research, please enter VDP Hunting as your company name. Account requests submitted with this identifier will be reviewed and approved for vulnerability research under this program.

For both targets the following attack surfaces are in scope:

  • Authentication and authorisation mechanisms
  • User account and session management
  • API endpoints and access control logic
  • Data handling and sensitive information exposure
  • Business logic flaws with security impact

Out of Scope

  • Any subdomain or asset not listed above
  • Third-party services, plugins, or integrations not directly owned by iAudit Global
  • Physical security testing
  • Social engineering attacks against iAudit staff, clients, or partners
  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks
  • Automated scanning that generates excessive load or disrupts service availability
  • Testing against real client accounts or data belonging to iAudit customers
  • Any action that disrupts or degrades the experience of other users

3. Safe Harbour

iAudit Global will not pursue legal action against security researchers who discover and responsibly disclose vulnerabilities in accordance with this policy. We consider good-faith security research to be a lawful and valuable contribution. Provided you comply with this policy, we will not initiate or recommend legal proceedings against you in connection with your research activities.

For safe harbour protections to apply, researchers must:

  • Act in good faith and avoid deliberately accessing, modifying, or deleting data
  • Limit testing to their own test accounts or dedicated sandbox environments
  • Report vulnerabilities promptly and avoid exploitation beyond what is necessary to demonstrate the issue
  • Avoid sharing vulnerability details publicly before iAudit Global has had a reasonable opportunity to remediate
  • Not use discovered vulnerabilities for personal gain or to harm iAudit Global, its clients, or end users

4. Prohibited Activities

The following are strictly prohibited and will void safe harbour protections:

  • Social engineering, phishing, or vishing of iAudit staff, clients, or partners
  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks in any form
  • Accessing, extracting, modifying, or deleting data belonging to iAudit clients or third parties
  • Testing using real end-user accounts without explicit written consent from the account holder
  • Introducing malware, backdoors, or persistent access mechanisms
  • Publicly disclosing vulnerability details before coordinated disclosure is agreed
  • Disrupting service availability or degrading performance for other users

5. What We Accept

We accept vulnerability reports across the full severity range. No vulnerability is too small — if you believe it poses a genuine security risk to iAudit Global or its users, we want to hear about it. We appreciate all security reports and will review every submission.

Accepted vulnerability classes include:

  • Authentication and authorisation flaws (IDOR, BAC, privilege escalation)
  • Injection vulnerabilities (SQL injection, XSS, SSTI, HTML injection)
  • Sensitive data exposure and insecure direct object references
  • Security misconfigurations and exposed management interfaces
  • Business logic flaws with security impact
  • SSRF, XXE, and deserialisation vulnerabilities
  • API security issues and broken access controls
  • Informational disclosures that enable further attack

Not accepted:

  • Missing security headers with no demonstrable impact
  • Self-XSS requiring significant user interaction with no realistic attack scenario
  • Rate limiting issues on non-sensitive endpoints
  • Theoretical vulnerabilities without a working proof of concept
  • Reports generated entirely by automated scanners without manual validation

6. How to Report

Submit a Vulnerability Report

Send all security vulnerability reports to: security@iaudit.global

Use the subject line format:

[VDP] <Vulnerability Type> – <Affected Asset>

Example: [VDP] IDOR on User Profile Endpoint – apps.iaudit.global

Report Format

Field
Details
Title
Short descriptive name of the vulnerability
Affected Asset
URL, endpoint, or feature affected
Vulnerability Type
e.g. IDOR, Stored XSS, SQL Injection, BAC
Severity
Critical / High / Medium / Low / Informational
Description
Clear explanation of the vulnerability and its security impact
Steps to Reproduce
Numbered step-by-step instructions to replicate the issue
Proof of Concept
Screenshots, HTTP request/response captures, or video
Impact
What data or functionality could be affected if exploited
Suggested Fix
Optional but appreciated

7. Our Process & Response Times

Stage
Timeline
Acknowledgement
Within 2–3 business days
Initial triage — valid, invalid, or needs more info
Within 5–7 business days
Hall of Fame listing
Upon confirmation of validity and handoff to development team
Closure & notification
Researcher notified once report is formally closed

8. Researcher Recognition

Hall of Fame

Every researcher with at least one accepted and validated report will be listed on the iAudit Global Security Hall of Fame. Each listing displays:

  • Name or alias
  • LinkedIn or X (Twitter) handle
  • Number of accepted reports

Researchers may opt out of public listing at any time by contacting security@iaudit.global.

Milestone Letters of Appreciation

Researchers who reach the following milestones will receive an official iAudit Global Letter of Appreciation, issued on official letterhead and signed by our security team. Each letter features a recognition badge and confirms the researcher's name and number of validated reports submitted to iAudit Global.

Milestone
Recognition
5 accepted reports
Bronze Recognition — Letter of Appreciation with Bronze badge
10 accepted reports
Silver Recognition — Letter of Appreciation with Silver badge
15 accepted reports
Gold Recognition — Letter of Appreciation with Gold badge

Letters are issued digitally with a verifiable signature.

9. Coordinated Disclosure

iAudit Global follows a coordinated disclosure model. We ask that researchers allow us a reasonable window to investigate and remediate before any public disclosure. If you intend to publish research related to a vulnerability in our systems, please notify us in advance so we can coordinate timing.

10. Duplicate Reports

In the event that multiple researchers report the same vulnerability, recognition will be granted to the first valid, complete report received at security@iaudit.global. Subsequent reports of the same issue will be acknowledged but will not qualify for Hall of Fame listing or Letters of Appreciation.

12. Contact

Item
Details
Subject Format
[VDP] Vulnerability Type – Affected Asset
Response SLA
Acknowledgement within 2–3 business days
Hall of Fame
iaudit.global/security/hall-of-fame
Policy URL
iaudit.global/security/vulnerability-disclosure-policy

Machine-readable security contact: /.well-known/security.txt

Report a security vulnerability to iAudit Global

Start free trial