ECW encourages responsible reporting of vulnerabilities that may affect executivecyberweek.com, ECW accounts or the Partner Hub.
This policy sets out the minimum rules for security research to be handled in good faith.
1. Scope
The scope covers only domains, applications and APIs officially operated by ECW and accessible to the researcher without bypassing a third party’s security boundary.
Services operated directly by third parties are outside the scope of ECW security research. A vulnerability affecting a third-party service must be reported to the provider concerned, unless it results directly from an integration or configuration under ECW’s control.
2. Permitted activities
Good-faith research may, in particular, include:
- checking an access control on your own account;
- non-destructive testing of a user input;
- analysing public configuration;
- the minimum reproduction necessary to demonstrate a vulnerability.
3. Prohibited activities
The following are not permitted:
- denial of service or saturation;
- social engineering / phishing;
- attempts to access premises;
- destruction / modification of data;
- bulk downloading of data;
- maintaining persistence on a system;
- installing malware;
- public exposure before a reasonable remediation period;
- extortion or threats of publication conditional on payment;
- access beyond the strict minimum necessary to provide evidence;
- testing on third-party accounts or data where the impact can be demonstrated otherwise.
4. If you discover personal data
Immediately stop any further exploration, do not copy additional data, and report the issue with the minimum information necessary.
Do not include real personal data in a public screenshot.
5. How to report
Use /contact, under Security / Responsible Disclosure.
The report should ideally contain:
- affected URL / component;
- vulnerability type;
- reproduction steps;
- impact;
- minimal evidence;
- necessary conditions;
- any recommendation;
- a way to contact you.
For an incident involving personal data, you may also contact dpo@bluepinksecurity.com.
6. ECW’s commitment
For a good-faith report that complies with this policy, ECW endeavours to:
- acknowledge receipt;
- assess the report;
- communicate reasonably about progress;
- remediate or reduce the risk according to its severity;
- refrain from deliberately initiating legal proceedings solely on the basis of the research where it remained within the scope and rules of this policy, subject to applicable law.
This commitment does not protect illegal, malicious or out-of-scope activity.
7. Coordinated publication
No unremediated vulnerability or information enabling its exploitation may be made public without ECW’s prior written consent or before the expiry of the reasonable remediation period agreed upon.
8. Bug bounty
This policy is not a bug bounty programme. No financial reward is payable unless ECW makes an express written commitment before or after the report.
