Vulnerability Disclosure Program

Found a security issue? Report it directly to us.

Efore values the security research community. If you've discovered a vulnerability in one of our products or services, please report it through the form below so our security team can investigate and remediate it — before it's disclosed publicly.

Before you report

  • Test only against in-scope assets
  • Avoid privacy violations, data destruction, or service disruption
  • Allow a reasonable remediation period prior to public disclosure
  • Include clear steps to reproduce and impact
  • One vulnerability per report, please

Program scope

Please keep testing within the boundaries below. Anything not explicitly listed as in scope should be treated as out of scope.

In scope

  • Production web applications and APIs under *.efore.com
  • Customer-facing portals and authentication flows
  • Firmware and software shipped with current Efore product lines
  • Cloud infrastructure directly operated by Efore

Out of scope

  • Third-party services, vendors, or integrations we do not control
  • Denial-of-service, spam, or social engineering against staff or customers
  • Physical security testing or attacks requiring physical device access
  • Automated scanning that generates excessive traffic without prior coordination
🛡️
Safe harbor. Efore will not pursue legal action against researchers who make a good-faith effort to comply with this policy, report findings responsibly, and avoid privacy violations, data destruction, and service interruption. We consider activities conducted consistent with this policy to constitute "authorized" conduct.

Coordinated disclosure policy

Here's what happens after you submit a report, and when public disclosure comes into play.

1

Report received

You submit a report through the form below or via encrypted email.

2

Acknowledgement

Our security team confirms receipt within 1 business day.

3

Triage & fix

We validate, prioritize, and work on a remediation — typically within 90 days.

4

Public disclosure

Once the issue is resolved, we agree on a coordinated disclosure date together and publicly credit your work.

📄

Vulnerability Disclosure Policy

The full policy document covers scope, safe harbor terms, our disclosure timeline, and researcher recognition in detail.