Skip to main content

Vulnerability disclosure

If you believe you have found a security issue in Qefro cloud, the Admin Console, APIs, widget, SDKs, or documentation that would let an attacker read another tenant’s data, forge invokes, or escalate privilege, report it privately.

Short definition (citation-ready)

Report suspected Qefro security vulnerabilities to [email protected] with steps to reproduce and impact. Do not open a public GitHub issue or discuss unfixed issues on social channels. Qefro does not currently publish a paid bug-bounty program on this page — confirm any bounty with Sales.

How to report

Email [email protected] with subject Security vulnerability.

Include:

  • Product surface (api.qefro.com, widget, Portal, /qefro SDK, Marketplace, docs)
  • A clear description of the issue and impact (especially cross-tenant)
  • Step-by-step reproduction, including whether a second test organization is required
  • Approximate timeline of your testing
  • Your contact details for follow-up

Encrypt the message if you have an established channel with Sales; otherwise use email and do not attach production secrets, customer PII, or live access tokens. Redact.

What is in scope (examples)

  • Cross-tenant or cross-workspace data disclosure
  • Authentication / authorization bypass (RBAC, widget token, HMAC)
  • SSRF that reaches cloud metadata or private networks from Qefro egress
  • Secret leakage in logs, GraphQL errors, or document viewer
  • Marketplace package validation bypass (arbitrary JS, unsigned content)

What is usually out of scope

  • Clickjacking on marketing pages without a demonstrated tenant impact
  • Missing security headers on qefro.com marketing HTML unless they enable account takeover
  • Self-XSS in the widget on a site you already control
  • Reports that require physically stolen unlocked Owner sessions with no additional bug
  • Theoretical issues without a reproduction

After you report

We will acknowledge receipt when we can, investigate, and notify you when a fix is released or if we need more information. We may ask you to keep the issue confidential until customers are protected.

There is no SLA published on this page. Enterprise contracts may include separate security-contact terms.

FAQ

Is there a bug bounty?
This documentation does not advertise a paid bounty. If Sales has offered one under a separate program, follow that program’s rules. Unsolicited testing that violates the terms of use is not authorized.
Can I disclose after 90 days?
Coordinate with us first. If you have not received a response, follow up on the same thread before public disclosure.