1 Purpose
Efore is committed to the security of our products, services, and customers. This policy describes how to report a suspected security vulnerability to us, what you can expect in response, and the terms under which we ask researchers to operate — including how and when vulnerabilities are disclosed publicly.
2 Scope
Please keep any testing within the boundaries below. Anything not explicitly listed as in scope should be treated as out of scope.
✓ In scope
- Production web applications and APIs under
*.efore.com - Customer-facing portals and authentication flows
- Firmware and software shipped with current Efore product lines
- Cloud infrastructure directly operated by Efore
✕ Out of scope
- Third-party services, vendors, or integrations we do not control
- Denial-of-service, spam, or social engineering against staff or customers
- Physical security testing or attacks requiring physical device access
- Automated scanning that generates excessive traffic without prior coordination
3 Guidelines & rules of engagement
When conducting research under this policy, we ask that you:
- Only test against assets explicitly listed as in scope.
- Avoid actions that could degrade, disrupt, or destroy Efore systems or data, including denial-of-service testing.
- Never access, modify, or exfiltrate data that isn't your own; stop and report immediately if you encounter customer or employee data.
- Do not use automated scanners that generate high-volume traffic without contacting us first.
- Submit one vulnerability per report, with enough detail for us to reproduce it.
- Give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly.
4 Safe harbor
5 How to report
Submit your report through our vulnerability report form. Include a clear title, the affected asset or URL, the vulnerability type, your severity estimate, and step-by-step reproduction details. You may report anonymously — a name and email are only needed if you'd like status updates.
If your finding involves sensitive information, you can also reach us directly at security@efore.com.
6 Public disclosure & recognition
- We support coordinated public disclosure: once a reported vulnerability is remediated, we work with the reporter to agree on a mutually acceptable disclosure date.
- We ask researchers not to publicly disclose details of a vulnerability before a fix is available and a joint disclosure date has been agreed, to protect users in the meantime.
- With your permission, we're happy to credit you publicly for a confirmed, resolved report.
- You may request to remain anonymous or withhold credit at any point in the process — it's entirely your choice.
- This is a good-faith vulnerability disclosure program and not a paid bug bounty; recognition is offered as public credit rather than monetary reward.
7 No compensation or reward
By submitting a report, you agree that it is provided voluntarily, without any expectation or entitlement to compensation, reward, bounty, or any other benefit — financial or otherwise. This is a good-faith vulnerability disclosure program, not a paid bug bounty.
You also acknowledge that Efore is under no obligation to correct any vulnerability or error reported, although we are committed to investigating and, wherever reasonably possible, remediating validated reports within the timeline described above.
8 Contact
For sensitive reports, or if you have any questions about this policy, reach our security team at security@efore.com.
This policy may be updated from time to time; the effective date above reflects the most recent revision.