Imperial Eminence Cyberguard Corporation ("IECC") operates this Vulnerability Disclosure Policy ("VDP") to encourage responsible disclosure of security vulnerabilities in The Ivory Index Software and IECC systems. IECC is committed to working with security researchers in good faith to identify and resolve vulnerabilities promptly.
To qualify for safe harbour under this Policy, researchers must:
| Step | IECC Commitment |
|---|---|
| Initial acknowledgement | Within 24 hours of report receipt |
| Triage and severity assessment | Within 5 business days |
| Status update | Every 14 days until resolved |
| Critical (CVSS 9.0+) remediation | 7 days from confirmation |
| High (CVSS 7.0–8.9) remediation | 30 days from confirmation |
| Coordinated disclosure | By mutual agreement; default 90 days from confirmation |
IECC recognises the contributions of security researchers who responsibly disclose vulnerabilities. With the researcher's consent, IECC will: (i) publicly credit the researcher in the relevant security advisory or release notes; and (ii) maintain a Hall of Acknowledgement on the IECC website (upon launch). IECC does not currently operate a bug bounty programme with monetary rewards; this may be introduced in future.
All vulnerability reports must be submitted to: legal@imperialecc.com. Use subject line: [VDP] Vulnerability Report — [Brief Description]. PGP encryption is available upon request for sensitive findings. Do not submit vulnerability reports via public issue trackers, social media, or third-party platforms.