Third Party Index

Snapshot 35868

Document
Security advisories
URL
https://www.iru.com/security/responsible-disclosure-policy
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
108415 bytes
SHA-256 (raw)
12e00711002303af077314945c74268f4de174833e75a1d19bf4929a02368358
SHA-256 (normalized text)
bc64173c07f88357912e8e87dde4557baa3b741fd417ae1eb1998f2227d87beb

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to content
Introducing Iru MCP
Iru logo
Login Book a demo
Products
Identity
Passwordless access that adapts to every context
Workforce Identity
Endpoint
Manage every device with one lightweight agent
Endpoint Management
Endpoint Detection & Response
Vulnerability Management
Compliance
Stay audit-ready with continuous evidence collection
Compliance Automation
Trust Center
Iru AI
Automating compliance, insights, and actions from a single interface.
Solutions
Solutions by device
Mac
Android
Windows
iPhone & iPad
Apple TV
Vision Pro
Solutions by use case
Zero-touch deployment
Automated Patching
Configuration-as-code
Build with MCP
Iru for MSPs
Resources
See Iru in action Get a guided walkthrough of how Iru simplifies data management, connects your systems, and helps your team move faster.
Learn & Connect
Iru Blog Updates, research, and how-tos
Events Live and on-demand events
Podcast: Patch Me If You Can For builders in IT and security
Endpoint Learning Hub Guides, resources, best practices
Why Iru?
Customer Stories
Compare Iru
Wall of Love
Support
Support Docs
API Documentation
Iru Academy
Product Updates
Security
Company
Introducing Iru Our new united platform
Company
About Iru
Careers
Contact
Last Modified: December 17, 2025
We believe community researchers play an integral role in maintaining Iru as a secure service and helping to protect our customers and their data. Our aim is to do what's best for our users, customers, partners, and the general health of the Internet.
We appreciate all security submissions from the research community and strive to respond in an expedient manner. We will investigate legitimate reports and do our best to quickly fix any identified issues. Our investigation panel consists of members from the Iru Security Team.
Please submit your report to our team as soon as you believe you have found a security vulnerability. All submissions must meet the terms of this Vulnerability Disclosure Policy (“policy”).
Iru’s Vulnerability Research and Disclosure Principles
We believe in strengthening defense by democratizing access to attacker tooling and knowledge. One of Iru’s unique strengths is our deep knowledge of how attackers work. Releasing public exploit code and novel research is core to our mission to close the security achievement gap.
Public disclosure of vulnerabilities is a critical component of a healthy cybersecurity ecosystem. Iru practices and advocates for timely public disclosure of vulnerabilities across both third-party products and our own systems and solutions. This includes vulnerabilities we independently discover in systems and software. Through transparent, open, and timely vulnerability disclosures, Iru helps the entire internet protect and defend those assets and services critical to modern civilization.
In today’s threat landscape, organizations need timely information about risk in order to make educated choices about protecting their networks — especially during active attacks. Our vulnerability disclosure policy includes explicit provisions for speeding up public disclosure in cases where exploitation has been observed in the wild. Vendors often (understandably) act to protect their own businesses and reputations when there are security issues in their products that introduce risk into their downstream customers’ environments. When we know about exploitation in the wild, or when we believe that threat actors may be covertly weaponizing non-public vulnerabilities, our priority is to make customers and the community aware of that risk so they may take action to protect their organizations.
Reporting a Potential Security Vulnerability
For the security of our users and service, we ask that you do not share details of the suspected vulnerability publicly or with any third party.
Please report the details of any suspected or detected vulnerabilities with Iru by completing the submission form on this page, or by emailing [email protected], including the following information:
Provide clear and reproducible steps that demonstrate the vulnerability exists
Avoid privacy violations, destruction of data, and interruption or degradation of our services.
Do not modify or access data that does not belong to you.
Coordinated Vulnerability Disclosure (CVD) Policy
In keeping with standard industry practices around Coordinated Vulnerability Disclosure (CVD) (such as CERT/CC's, Google's, ZDI's) Iru will typically prepare and publish advisories detailing newly discovered vulnerabilities approximately 90 days after our initial attempts at private disclosure, barring extenuating circumstances (including those outlined below which may warrant different disclosure guidelines). These advisories will be made publicly available via Iru’s blog and social media. Depending on the details of the findings, there may also be media engagement.
While coordinated vulnerability disclosure can differ from bug to bug depending on a wide range of circumstances, Iru’s primary concern is getting vulnerabilities fixed and making affected parties aware of the risks associated with vulnerabilities. In keeping with the principles outlined above, Iru has identified several common types of vulnerabilities, each of which warrants slightly different disclosure guidelines.
Please note, technical vulnerabilities often involve undefined behavior and unexpected interactions. Therefore, Iru may modify the timeline for disclosure at our sole discretion due to unique or unpredictable elements of that specific vulnerability.
Authorization
If you make a good faith effort to comply with this document during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and Iru will not recommend or pursue legal action related to your research.
Guidelines
Under this policy, “research” means activities in which you:
Notify us as soon as possible after you discover a real or potential privacy or security vulnerability.
Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems
Once you’ve established that a vulnerability exists, or encounter any sensitive data (including personally identifiable information, financial information, proprietary or trade secret information of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else.
Prohibited Actions
While we encourage you to discover and report to us any vulnerabilities you find in a responsible manner, the following conduct is prohibited:
Performing actions that may negatively affect Iru or its users (e.g., Spam, Brute Force, Denial of Service, etc).
Accessing, or attempting to access, data or information that does not belong to you.
Delete, alter, share, retain, or destroy data or information that does not belong to you.
Social engineering of any Iru Personnel.
Violating any laws or breaching any agreements in order to discover vulnerabilities.
Our Commitment to Researchers
If you responsibly report a vulnerability in accordance with this policy, we will:
Within three (3) business days, we will promptly respond to and acknowledge the receipt of your report
To the best of our ability, we will confirm the existence of the reported vulnerability to you and be as transparent as possible about what steps we are taking
Provide an estimated timeframe for addressing the vulnerability
Notify you when the vulnerability has been remediated.
All Vulnerabilities (The Default Policy)
Iru will confidentially disclose discovered vulnerabilities to the organization that is in the best position to address that vulnerability with a resolution. That organization is the "responsible organization."
If the responsible organization is not a CVE Partner, Iru will reserve a CVE ID.
In the interest of full transparency and to allow your organization sufficient time to address this issue, please be aware that Iru follows the industry standard of a 90+30 disclosure deadline policy.
A vendor has 90 days after Iru notifies them about a security vulnerability to make a patch available to users. If they make a patch available within 90 days, Iru will publicly disclose details of the vulnerability 30 days after the patch has been made available to users.
If a vendor cannot patch an issue within the initial 90 days, Iru will make the details of the vulnerability public at the end of the 90 days.
If the responsible organization is showing consistent good-faith effort to develop and ship an update, but cannot complete this work within 90 days, a 30-day extension may be granted at Iru’s sole discretion under the Default Policy (or for any of the enumerated exceptions below).
Grace Period
If a vendor cannot make a patch available in 90 days but will make a patch available within an additional 14 days (i.e., within 104 days since the vulnerability was disclosed to the vendor), Iru may grant a grace period to the vendor upon request. In that case, Iru will publicly disclose details of the vulnerability 120 days after the vulnerability was initially disclosed to the public.
Mutually-agreed early disclosure
In any of the above cases, Iru and the relevant vendor can mutually agree to release details of a vulnerability earlier than the date indicated by policy.
Other Information
If you have any other concerns about the way Iru or its employees operate or know of any violations, please contact [email protected].
Stay up to date
Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.