Security Center
Vulnerability Disclosure Policy
WaveMetrics encourages customers, researchers, and other parties to report suspected security vulnerabilities affecting Igor Pro and related products.
Reporting a Vulnerability
Reports should be submitted to: security@wavemetrics.com.
Reports must include:
- a description of the issue
- affected version(s)
- reproduction steps
- any supporting evidence
Vulnerability reports must include a clear, actionable analysis specific to WaveMetrics products, with sufficient detail to reproduce the issue.
Reports lacking genuine understanding, product-specific context, or reproduction steps will be rejected.
Acknowledgement
WaveMetrics will acknowledge receipt of vulnerability reports within a reasonable time and assign the report for review.
Evaluation Process
WaveMetrics will evaluate reported issues to determine whether they are security vulnerabilities, assess severity, identify affected versions, and determine remediation options.
Responsible Disclosure
Reporters are requested not to publicly disclose vulnerability details until WaveMetrics has had a reasonable opportunity to investigate and, when appropriate, release a fix or mitigation.
Escalation Procedures
- Level 1: Initial triage by support or designated security contact.
- Level 2: Engineering review for confirmed or suspected security vulnerabilities.
- Level 3: Management review for high-severity issues, actively exploited vulnerabilities, or incidents with significant customer impact.
- Level 4: CRA reporting review for potentially reportable vulnerabilities or severe security incidents.
Security Advisories
When appropriate, WaveMetrics may publish a security advisory identifying affected versions, fixed versions, mitigation steps, and update information.
Supported Versions
Security fixes are provided only for versions designated by WaveMetrics as supported versions.
| Igor Pro 10 | Current supported release. Support will continue until the release of Igor Pro 11. |
| Igor Pro 9 | End of Support: October 2025 |
Record Keeping
All reported security vulnerabilities and associated decisions shall be tracked in the WaveMetrics issue tracking system and retained as part of WaveMetrics security records.
Forum
Support
Gallery
Igor Pro 10
Learn More
Igor XOP Toolkit
Learn More
Igor NIDAQ Tools MX
Learn More