Vulnerability Disclosure Policy

Effective date: 01 September 2026  ·  Version 1.0  ·  Efore Security Team

1 Purpose

Efore is committed to the security of our products, services, and customers. This policy describes how to report a suspected security vulnerability to us, what you can expect in response, and the terms under which we ask researchers to operate — including how and when vulnerabilities are disclosed publicly.

2 Scope

Please keep any testing within the boundaries below. Anything not explicitly listed as in scope should be treated as out of scope.

✓ In scope

  • Production web applications and APIs under *.efore.com
  • Customer-facing portals and authentication flows
  • Firmware and software shipped with current Efore product lines
  • Cloud infrastructure directly operated by Efore

✕ Out of scope

  • Third-party services, vendors, or integrations we do not control
  • Denial-of-service, spam, or social engineering against staff or customers
  • Physical security testing or attacks requiring physical device access
  • Automated scanning that generates excessive traffic without prior coordination

3 Guidelines & rules of engagement

When conducting research under this policy, we ask that you:

4 Safe harbor

🛡️
Efore will not pursue legal action against researchers who make a good-faith effort to comply with this policy, report findings responsibly, and avoid privacy violations, data destruction, and service interruption. We consider activities conducted consistent with this policy to constitute authorized conduct, and will work with you to understand and resolve any concerns quickly.

5 How to report

Submit your report through our vulnerability report form. Include a clear title, the affected asset or URL, the vulnerability type, your severity estimate, and step-by-step reproduction details. You may report anonymously — a name and email are only needed if you'd like status updates.

If your finding involves sensitive information, you can also reach us directly at security@efore.com.

6 Public disclosure & recognition

7 No compensation or reward

By submitting a report, you agree that it is provided voluntarily, without any expectation or entitlement to compensation, reward, bounty, or any other benefit — financial or otherwise. This is a good-faith vulnerability disclosure program, not a paid bug bounty.

You also acknowledge that Efore is under no obligation to correct any vulnerability or error reported, although we are committed to investigating and, wherever reasonably possible, remediating validated reports within the timeline described above.

8 Contact

For sensitive reports, or if you have any questions about this policy, reach our security team at security@efore.com.

This policy may be updated from time to time; the effective date above reflects the most recent revision.