Security

Effective Date: September 4th, 2026

Introduction

Interactive Group develops and supports real-time software solutions for mission-critical communications environments. We take the security of our products, services, and website seriously, and we welcome responsible reports of suspected vulnerabilities. This page explains how to report a security vulnerability to Interactive Group, what information to include, and how we handle reports once they are received.

Reporting a Vulnerability

To report a suspected security vulnerability, email:

security@interactivegroup.biz

Please include enough detail for us to understand and reproduce the issue where possible. Useful information includes:

the affected product, service, website, or component;
the affected version, URL, Docker image tag, or deployment context if known;
a clear description of the suspected vulnerability;
steps to reproduce the issue;
any screenshots, logs, proof-of-concept details, or scanner output that support the report;
your contact details and preferred contact method;
whether you believe the issue is being actively exploited or affects a customer production environment.

If your report relates to a customer deployment, do not include customer secrets, passwords, private keys, personal information, or confidential operational data unless Interactive Group has provided a secure transfer method.

Urgent Customer Incidents

This mailbox is for vulnerability reporting. If you are an Interactive Group customer or partner experiencing an urgent operational or security incident, also use your agreed support or escalation route so the issue can be handled under the relevant support arrangements.

Coordinated Disclosure

We ask reporters to give Interactive Group a reasonable opportunity to investigate and remediate reported vulnerabilities before making details public. We will acknowledge credible reports, assess impact, and coordinate next steps with the reporter where appropriate.

Interactive Group may need to coordinate with affected customers, partners, suppliers, hosting providers, or regulatory stakeholders before a vulnerability can be publicly disclosed.

Authorised Testing

Reporting a vulnerability does not authorise access to Interactive Group systems, customer systems, customer data, or third-party services. Do not:

access, modify, delete, or exfiltrate data that is not your own;
attempt denial-of-service testing;
use social engineering, phishing, physical intrusion, or credential attacks;
test customer environments without written authorisation from the customer;
disrupt Interactive Group services, customer services, or third-party services.

Supported Products and Versions

Interactive Group will assess vulnerability reports for currently supported products, services, and release versions. Where a report relates to software supplied through a partner or reseller, Interactive Group may coordinate remediation and release activity with that partner.

How We Handle Reports

Interactive Group will review submitted vulnerability reports, create an internal vulnerability record where the report is credible, assess severity and affected versions, and determine the appropriate remediation or advisory response.

Where a vulnerability affects a supported release, Interactive Group will determine whether the response requires a configuration change, customer advisory, workaround, software patch, dependency update, container update, or release of a corrected version.

Privacy and Confidentiality

Interactive Group will use the information provided in a vulnerability report to investigate, remediate, and communicate about the reported issue. We will handle personal information in accordance with our Privacy Policy.

Do not submit sensitive personal information, customer confidential information, credentials, private keys, or production data unless Interactive Group has confirmed an appropriate secure transfer method.

Policy Updates

Interactive Group may update this security page periodically to reflect changes in our products, support arrangements, vulnerability handling process, or legal and regulatory obligations. Updated versions will be published on this page.