Vulnerability disclosure
If you believe you have found a security issue in Qefro cloud, the Admin Console, APIs, widget, SDKs, or documentation that would let an attacker read another tenant’s data, forge invokes, or escalate privilege, report it privately.
Short definition (citation-ready)
Report suspected Qefro security vulnerabilities to [email protected] with steps to reproduce and impact. Do not open a public GitHub issue or discuss unfixed issues on social channels. Qefro does not currently publish a paid bug-bounty program on this page — confirm any bounty with Sales.
How to report
Email [email protected] with subject Security vulnerability.
Include:
- Product surface (
api.qefro.com, widget, Portal,/qefroSDK, Marketplace, docs) - A clear description of the issue and impact (especially cross-tenant)
- Step-by-step reproduction, including whether a second test organization is required
- Approximate timeline of your testing
- Your contact details for follow-up
Encrypt the message if you have an established channel with Sales; otherwise use email and do not attach production secrets, customer PII, or live access tokens. Redact.
What is in scope (examples)
- Cross-tenant or cross-workspace data disclosure
- Authentication / authorization bypass (RBAC, widget token, HMAC)
- SSRF that reaches cloud metadata or private networks from Qefro egress
- Secret leakage in logs, GraphQL errors, or document viewer
- Marketplace package validation bypass (arbitrary JS, unsigned content)
What is usually out of scope
- Clickjacking on marketing pages without a demonstrated tenant impact
- Missing security headers on
qefro.commarketing HTML unless they enable account takeover - Self-XSS in the widget on a site you already control
- Reports that require physically stolen unlocked Owner sessions with no additional bug
- Theoretical issues without a reproduction
After you report
We will acknowledge receipt when we can, investigate, and notify you when a fix is released or if we need more information. We may ask you to keep the issue confidential until customers are protected.
There is no SLA published on this page. Enterprise contracts may include separate security-contact terms.