Skip to content
Executive Cybersecurity Week

Responsible disclosure of vulnerabilities

ECW encourages responsible reporting of vulnerabilities that may affect executivecyberweek.com, ECW accounts or the Partner Hub.

This policy sets out the minimum rules for security research to be handled in good faith.

1. Scope

The scope covers only domains, applications and APIs officially operated by ECW and accessible to the researcher without bypassing a third party’s security boundary.

Services operated directly by third parties are outside the scope of ECW security research. A vulnerability affecting a third-party service must be reported to the provider concerned, unless it results directly from an integration or configuration under ECW’s control.

2. Permitted activities

Good-faith research may, in particular, include:

  • checking an access control on your own account;
  • non-destructive testing of a user input;
  • analysing public configuration;
  • the minimum reproduction necessary to demonstrate a vulnerability.

3. Prohibited activities

The following are not permitted:

  • denial of service or saturation;
  • social engineering / phishing;
  • attempts to access premises;
  • destruction / modification of data;
  • bulk downloading of data;
  • maintaining persistence on a system;
  • installing malware;
  • public exposure before a reasonable remediation period;
  • extortion or threats of publication conditional on payment;
  • access beyond the strict minimum necessary to provide evidence;
  • testing on third-party accounts or data where the impact can be demonstrated otherwise.

4. If you discover personal data

Immediately stop any further exploration, do not copy additional data, and report the issue with the minimum information necessary.

Do not include real personal data in a public screenshot.

5. How to report

Use /contact, under Security / Responsible Disclosure.

The report should ideally contain:

  • affected URL / component;
  • vulnerability type;
  • reproduction steps;
  • impact;
  • minimal evidence;
  • necessary conditions;
  • any recommendation;
  • a way to contact you.

For an incident involving personal data, you may also contact dpo@bluepinksecurity.com.

6. ECW’s commitment

For a good-faith report that complies with this policy, ECW endeavours to:

  • acknowledge receipt;
  • assess the report;
  • communicate reasonably about progress;
  • remediate or reduce the risk according to its severity;
  • refrain from deliberately initiating legal proceedings solely on the basis of the research where it remained within the scope and rules of this policy, subject to applicable law.

This commitment does not protect illegal, malicious or out-of-scope activity.

7. Coordinated publication

No unremediated vulnerability or information enabling its exploitation may be made public without ECW’s prior written consent or before the expiry of the reasonable remediation period agreed upon.

8. Bug bounty

This policy is not a bug bounty programme. No financial reward is payable unless ECW makes an express written commitment before or after the report.

Your voice conversation

ECW Assistant

A question, an idea, a journey to choose?

Speak with ECW Assistant, just like a phone call.

Microphone & privacy

Your microphone is required.

Conversations are processed and may be retained by ECW for your request: avoid sensitive or card information.

Or go directly to your journey

Executive Cybersecurity Week

Before you enter

Cookie policy