Found a security issue? Report it directly to us.
Efore values the security research community. If you've discovered a vulnerability in one of our products or services, please report it through the form below so our security team can investigate and remediate it — before it's disclosed publicly.
Before you report
- ✓ Test only against in-scope assets
- ✓ Avoid privacy violations, data destruction, or service disruption
- ✓ Allow a reasonable remediation period prior to public disclosure
- ✓ Include clear steps to reproduce and impact
- ✓ One vulnerability per report, please
Program scope
Please keep testing within the boundaries below. Anything not explicitly listed as in scope should be treated as out of scope.
✓ In scope
- Production web applications and APIs under
*.efore.com - Customer-facing portals and authentication flows
- Firmware and software shipped with current Efore product lines
- Cloud infrastructure directly operated by Efore
✕ Out of scope
- Third-party services, vendors, or integrations we do not control
- Denial-of-service, spam, or social engineering against staff or customers
- Physical security testing or attacks requiring physical device access
- Automated scanning that generates excessive traffic without prior coordination
Coordinated disclosure policy
Here's what happens after you submit a report, and when public disclosure comes into play.
Report received
You submit a report through the form below or via encrypted email.
Acknowledgement
Our security team confirms receipt within 1 business day.
Triage & fix
We validate, prioritize, and work on a remediation — typically within 90 days.
Public disclosure
Once the issue is resolved, we agree on a coordinated disclosure date together and publicly credit your work.
Vulnerability Disclosure Policy
The full policy document covers scope, safe harbor terms, our disclosure timeline, and researcher recognition in detail.