General practices
IRIS takes security very seriously. Our general security practices include:
- We use automatic security vulnerability detection tools to alert us when our dependencies have known security issues, such as GitHub Advanced Security.
- We regularly perform internal and external vulnerability scans and application penetration tests to monitor the status of our security efforts.
- We prefer third-party tools with strong privacy and security postures that align with our goals.
- All developers are granted access to systems according to the principle of least privilege.