General practices

IRIS takes security very seriously. Our general security practices include:

  • We use automatic security vulnerability detection tools to alert us when our dependencies have known security issues, such as GitHub Advanced Security. 
  • We regularly perform internal and external vulnerability scans and application penetration tests to monitor the status of our security efforts.
  • We prefer third-party tools with strong privacy and security postures that align with our goals.
  • All developers are granted access to systems according to the principle of least privilege.