Skip to content

Security & Compliance

Responsible Disclosure

We welcome good-faith security research. This policy explains what is in scope, what is prohibited, how to report, and the protections that apply to researchers who follow it.

Safe harbor

Protection for good-faith research

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorized, will work with you to understand and resolve the issue quickly, and will not pursue or support legal action related to it. If a third party initiates action against you for research conducted within this policy, we will make that authorization known.

Safe harbor applies only while you stay within the stated scope, avoid privacy violations and service degradation, and stop testing as soon as a vulnerability is confirmed. Access only the minimum data required to demonstrate the issue, and never retain, share, or publish another party’s data.

Scope

What is in and out of scope

In scope

  • Public web properties operated by IEP ALLY APP LLC, including this website
  • Publicly reachable application endpoints belonging to systems we operate
  • Security misconfiguration, injection, authentication, and authorization flaws
  • Sensitive information exposed in a public response or public repository

Prohibited testing

  • Denial of service, load generation, or resource-exhaustion testing
  • Social engineering, phishing, or physical intrusion attempts against personnel
  • Automated scanning that degrades availability for other users
  • Testing against customer environments or third-party services we do not operate
  • Accessing, modifying, exfiltrating, or retaining another party's data
  • Findings limited to missing best-practice headers with no demonstrated impact

Reporting

How to submit a report

Submit reports through our secure contact workflow. Do not include exploit payloads that could cause harm if executed, and do not attach another party's data.

Include in your report

  • A clear description of the issue and its security impact
  • The affected URL, endpoint, or component
  • Reproduction steps with the minimum evidence required to demonstrate the issue
  • Any supporting output, request, or screenshot
  • How you would like to be credited, if at all

Process

What to expect after you report

  • Acknowledgment

    We aim to acknowledge a complete report within five business days of receipt.

  • Triage

    Reports are validated and assigned a severity based on exploitability and exposure.

  • Remediation

    Confirmed issues are assigned an owner and remediated on a risk-prioritized timeline.

  • Coordinated disclosure

    We ask that you allow remediation to complete before public disclosure and coordinate timing with us.

IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.