WaveMetrics encourages customers, researchers, and other parties to report suspected security vulnerabilities affecting Igor Pro and related products.
Reports should be submitted to: security@wavemetrics.com.
Reports must include:
Vulnerability reports must include a clear, actionable analysis specific to WaveMetrics products, with sufficient detail to reproduce the issue.
Reports lacking genuine understanding, product-specific context, or reproduction steps will be rejected.
WaveMetrics will acknowledge receipt of vulnerability reports within a reasonable time and assign the report for review.
WaveMetrics will evaluate reported issues to determine whether they are security vulnerabilities, assess severity, identify affected versions, and determine remediation options.
Reporters are requested not to publicly disclose vulnerability details until WaveMetrics has had a reasonable opportunity to investigate and, when appropriate, release a fix or mitigation.
When appropriate, WaveMetrics may publish a security advisory identifying affected versions, fixed versions, mitigation steps, and update information.
Security fixes are provided only for versions designated by WaveMetrics as supported versions.
All reported security vulnerabilities and associated decisions shall be tracked in the WaveMetrics issue tracking system and retained as part of WaveMetrics security records.
Forum
Support
Gallery
Learn More
Learn More
Learn More