We take the security of iCustomer software and customer data seriously. This policy applies to all repositories in the iCustomer organisation unless a repository overrides it with its own SECURITY.md.
Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Instead, use one of the private channels below:
- Preferred: GitHub private vulnerability reporting — open the repository's Security tab and choose Report a vulnerability.
- Email: security@icustomer.ai.
Please include enough detail to reproduce the issue: affected repository and version, a description of the impact, and step-by-step reproduction where possible.
- We acknowledge new reports within three business days.
- We provide an initial assessment and expected timeline within ten business days.
- We keep you informed as we work towards a fix and coordinate disclosure with you.
We provide security fixes for the currently deployed release of each actively maintained service. Older or unreleased versions are addressed on a best-effort basis.
This policy covers code and services owned by the iCustomer organisation. It does not cover third-party dependencies or services, which should be reported to their respective maintainers.