
Responsible disclosure
If you find a vulnerability in our website or in IRIS, tell us first, and we will work with you to fix it.
How to report
Email the contact address with the subject “Vulnerability report”. Include the affected system or URL, a description, steps to reproduce and how we can reach you.
Our commitment
We acknowledge reports within a few working days, keep you informed, and credit you when the issue is fixed if you wish.
Please do not
Access or modify data that is not yours, degrade the availability of our systems, use social engineering, or disclose the issue publicly before it is fixed.