Epitome welcomes reports from security researchers and customers who find a vulnerability in our platforms or corporate systems. This page explains how to report one, what we ask of you, and what you can expect from us. It is also published in machine-readable form at /.well-known/security.txt Available now.
How to report
E-mail security@epitome.global with enough detail for us to reproduce the issue: the affected URL or component, the steps you took, what you observed, and the impact you believe it has. Screenshots or a short proof of concept help. If the report contains sensitive data, say so in the subject line and we will arrange a secure channel before you send it.
Scope
In scope: the public web properties and applications that Epitome operates, including epitome.global and its subdomains, the Epitome platform and tenant deployments, and YourCareer.fit.
Out of scope: denial-of-service or volumetric testing, social engineering or phishing of Epitome staff or customers, physical attacks, testing of third-party services we integrate with but do not operate, and reports that only show a missing best-practice header without a demonstrated impact. Automated scanning that degrades the service is not acceptable.
What we ask of you
- Act in good faith: do not access, change or delete data that is not yours, and stop as soon as you have enough evidence to demonstrate the issue.
- Do not use a vulnerability to pivot to other systems, exfiltrate data, or disrupt service.
- Give us reasonable time to fix the issue before you disclose it publicly. We ask for 90 days from acknowledgement, or longer by agreement for issues that need coordinated fixes.
- Keep any data you may have encountered confidential and delete it once the report is closed.
What you can expect from us
- Acknowledgement of your report within 3 business days Available now.
- An initial assessment of severity and an expected remediation timeline within 10 business days.
- Remediation targets by severity: critical within 7 days, high within 30 days, medium within 90 days, low at the next scheduled release.
- We will not take legal action against researchers who follow this policy, and we will not report them to law enforcement for good-faith research.
- A note of thanks, with your name or handle if you wish, in the acknowledgements below once the issue is resolved.
Rewards
Epitome does not currently run a paid bug-bounty programme In progress. Reports are handled under this responsible-disclosure policy and we credit researchers publicly. If a paid programme is introduced it will be announced on this page.
Acknowledgements
We thank the following people for responsibly reporting security issues to Epitome. No reports have been received under this policy yet.
Related
Security overview and incident response: Security Overview. Data-protection questions: dpo@epitome.global.