Security Center

Vulnerability Disclosure Policy


WaveMetrics encourages customers, researchers, and other parties to report suspected security vulnerabilities affecting Igor Pro and related products.

Reporting a Vulnerability

Reports should be submitted to: security@wavemetrics.com.

Reports must include:

  • a description of the issue
  • affected version(s)
  • reproduction steps
  • any supporting evidence

Vulnerability reports must include a clear, actionable analysis specific to WaveMetrics products, with sufficient detail to reproduce the issue.

Reports lacking genuine understanding, product-specific context, or reproduction steps will be rejected.

Acknowledgement

WaveMetrics will acknowledge receipt of vulnerability reports within a reasonable time and assign the report for review.

Evaluation Process

WaveMetrics will evaluate reported issues to determine whether they are security vulnerabilities, assess severity, identify affected versions, and determine remediation options.

Responsible Disclosure

Reporters are requested not to publicly disclose vulnerability details until WaveMetrics has had a reasonable opportunity to investigate and, when appropriate, release a fix or mitigation.

Escalation Procedures

  • Level 1: Initial triage by support or designated security contact.
  • Level 2: Engineering review for confirmed or suspected security vulnerabilities.
  • Level 3: Management review for high-severity issues, actively exploited vulnerabilities, or incidents with significant customer impact.
  • Level 4: CRA reporting review for potentially reportable vulnerabilities or severe security incidents.

Security Advisories

When appropriate, WaveMetrics may publish a security advisory identifying affected versions, fixed versions, mitigation steps, and update information.

Supported Versions

Security fixes are provided only for versions designated by WaveMetrics as supported versions.

Igor Pro 10Current supported release. Support will continue until the release of Igor Pro 11.
Igor Pro 9End of Support: October 2025

Record Keeping

All reported security vulnerabilities and associated decisions shall be tracked in the WaveMetrics issue tracking system and retained as part of WaveMetrics security records.

Forum

Support

Gallery

Igor Pro 10

Learn More

Igor XOP Toolkit

Learn More

Igor NIDAQ Tools MX

Learn More