Security & Compliance
Responsible Disclosure
We welcome good-faith security research. This policy explains what is in scope, what is prohibited, how to report, and the protections that apply to researchers who follow it.
Safe harbor
Protection for good-faith research
Safe harbor applies only while you stay within the stated scope, avoid privacy violations and service degradation, and stop testing as soon as a vulnerability is confirmed. Access only the minimum data required to demonstrate the issue, and never retain, share, or publish another party’s data.
Scope
What is in and out of scope
In scope
- Public web properties operated by IEP ALLY APP LLC, including this website
- Publicly reachable application endpoints belonging to systems we operate
- Security misconfiguration, injection, authentication, and authorization flaws
- Sensitive information exposed in a public response or public repository
Prohibited testing
- Denial of service, load generation, or resource-exhaustion testing
- Social engineering, phishing, or physical intrusion attempts against personnel
- Automated scanning that degrades availability for other users
- Testing against customer environments or third-party services we do not operate
- Accessing, modifying, exfiltrating, or retaining another party's data
- Findings limited to missing best-practice headers with no demonstrated impact
Reporting
How to submit a report
Include in your report
- A clear description of the issue and its security impact
- The affected URL, endpoint, or component
- Reproduction steps with the minimum evidence required to demonstrate the issue
- Any supporting output, request, or screenshot
- How you would like to be credited, if at all
Process
What to expect after you report
Acknowledgment
We aim to acknowledge a complete report within five business days of receipt.
Triage
Reports are validated and assigned a severity based on exploitability and exposure.
Remediation
Confirmed issues are assigned an owner and remediated on a risk-prioritized timeline.
Coordinated disclosure
We ask that you allow remediation to complete before public disclosure and coordinate timing with us.
IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.