Security Reporting
If you believe you've found a security vulnerability in think4ei.com or the Think4Ei platform, we want to hear from you directly, before it's disclosed publicly.
How to report
Email support@think4ei.com with the subject line "SECURITY". Please include:
- The URL or system affected.
- Steps to reproduce the issue.
- What you observed vs. what you expected.
- Your assessment of impact, if you have one.
security@ mailbox or a formal bug-bounty program — reports go to our
general support inbox with priority handling on anything marked "SECURITY." We're naming that gap honestly rather
than pointing you at a contact channel that doesn't really exist yet.
Our commitment
- We will acknowledge a good-faith security report within 3 business days.
- We will work to understand and validate the report, and keep you reasonably informed of progress toward a fix.
- We will not pursue legal action against a security researcher who makes a good-faith effort to comply with this policy, even if that research technically violates a restriction in our Terms of Use, provided the research was conducted within the scope below and reported to us rather than exploited or disclosed publicly first.
Scope
In scope: think4ei.com and production subdomains of think4ei.com that you can reach as an ordinary visitor or customer, without needing credentials that weren't given to you.
Out of scope: social engineering or phishing against Think4Ei staff or customers; physical security of our offices or infrastructure providers; denial-of-service testing; vulnerabilities in third-party services we use (report those to the vendor directly — see our Subprocessors list); and any testing against a specific customer's tenant data without that customer's separate authorization.
Responsible disclosure
Please give us a reasonable opportunity to investigate and remediate an issue — generally 90 days from your report — before any public disclosure. We're happy to coordinate on disclosure timing and, where appropriate, credit your finding once it's fixed.
What not to do
Please don't access, modify, or delete data that isn't yours; don't attempt to pivot from one finding into broader exploitation beyond what's needed to demonstrate the issue; and don't publicly disclose a vulnerability before we've had a chance to address it under the timeline above.