← Back to IQBaseline

Security & Vulnerability Disclosure Policy

As a platform built and operated by XRG, a managed IT and cybersecurity services provider, IQBaseline holds itself to the same standard XRG advocates for its clients. If you believe you have found a security vulnerability affecting this website or platform, we want to hear from you, and we commit to working with good-faith researchers in a respectful, non-adversarial way.

1. Our Commitment

2. Scope

In scope for this policy:

Out of scope:

3. Rules of Engagement

4. How to Report

Send a report via our contact form including:

5. What Happens Next

6. Coordinated Disclosure & Recognition

We ask that you give us a reasonable opportunity to investigate and remediate a reported issue before any public disclosure — typically 90 days from acknowledgment, subject to extension for complex issues by mutual agreement. With your permission, we are happy to publicly credit researchers who responsibly report a valid, previously unreported vulnerability.

7. Safe Harbor

Activity conducted in good faith and in accordance with this policy is considered authorized. We will not initiate legal action, and will work to prevent legal action from being taken by others, in connection with research conducted consistently with this policy. This safe harbor applies only to the scope defined in Section 2 and only where the Rules of Engagement in Section 3 are followed.

8. Contact

Security reports and general questions about this policy can be sent via our contact form.