Skip to main content
All CollectionsUsing IT GlueSecurity
Responsible Security Reporting and Disclosure
Responsible Security Reporting and Disclosure
A
Written by Aiden Morris
Updated over a week ago

One of our core values is Trust:
​

Champion complete vigilance for the privacy and security of information. Show respect through accountability; responsibility assumed; and ownership taken. Transparently. Willingly. Effectively.
​

As such, at IT Glue we take every security incident extremely seriously, and we have internal processes and security compliance standards that guide how we review reports or remediate possible vulnerabilities.
​

To maintain utmost confidentiality and protect partner data and security, we will take additional steps to move all security-related discussions offline, reducing any public visibility until we have properly assessed the situation.
​

Our Responsible Security Reporting and Disclosure policy invites the disclosure of security vulnerabilities responsibly and ethically. If you're a user, partner, or security researcher, and you think you've found a possible vulnerability with IT Glue, please follow the steps below:

  1. Potential security bugs and vulnerabilities should be reported to us by email(security@itglue.com).

  2. Give us an opportunity to respond before making any public disclosure or comments about the vulnerability.

  3. Do not share, access, or modify any data without the account owner's permission.

  4. Act in good faith, and do not maliciously degrade the performance of our services (including denial of service).

Following these basic guidelines, we will all be better equipped to help keep data safe. Thank you in advance for your consideration of, and abidance with this policy.

Did this answer your question?