CI&T se adhiere al pacto global de la ONU - Women Empowerment principles May 24, 2022 CI&T firmó un compromiso público con Women's Empowerment Principles (WEPs) para la equidad de género y el empoderamiento de las mujeres. Leer más
CI&T es reconocida en el premio Learning Innovator of the Year May 06, 2024 CI&T recibe el premio Degreed Awards Visionaries en tercer lugar en la categoría Learning Innovator of the Year Award concedido por Degreed, empresa proveedora de la plataforma de CI&T University. Leer más
Grupos de acción en CI&T: Conozca a los líderes y algunos logros hasta ahora May 24, 2022 Nunca hemos tenido tantas personas negras, LGBTQIA+, mujeres y personas con discapacidades en CI&T como hoy, y este trabajo es en gran parte el resultado de articular a nuestra gente a través de grupos de acción enfocados en la diversidad corporativa. Leer más
Faster, Faster: The Dawn of Lean Digital May 24, 2022 El libro "Faster, Faster" ilustra la evolución del pensamiento lean, agile y scrum para crear Lean Digital y luego Lean Digital con una gestión moderna. Leer más
Responsible Vulnerability Disclosure Our approach to securitySecurity is a shared responsibility. We genuinely appreciate the work of security researchers, ethical hackers, and members of the cybersecurity community who help make technology safer.While we do not operate a bug bounty or reward program, we welcome responsible, good-faith vulnerability reports that help us identify and mitigate potential risks. This policy explains how to report security issues safely and what you can expect from us in return.ScopeThis policy applies only to systems, applications, services, and infrastructure owned or directly operated by us.The following are out of scope:- Systems or environments owned by customers, partners, vendors, or third parties- Social engineering, phishing, or interactions with employees or users- Denial-of-service, brute-force attacks, or stress testing- Physical security testing- Findings with no practical security impact or purely informational issuesHow to report a vulnerabilityIf you believe you have identified a security vulnerability, please report it to: securitytalk@ciandt.comTo help us investigate efficiently, please include:- A clear description of the issue- The affected system, URL, endpoint, or component- Steps to reproduce the issue using a non-destructive proof of concept- The potential security impact- Suggested remediation, if available- Your preferred contact informationReports that lack sufficient detail may not be reviewed.Responsible research guidelinesWe ask that all research conducted under this policy:- Is performed in good faith and in compliance with applicable laws- Is limited to the minimum testing required to confirm the vulnerability- Does not access, modify, copy, or exfiltrate data belonging to users or systems- Stops immediately if sensitive data is encountered and is reported without delay- Avoids service disruption, performance degradation, or persistence- Does not involve lateral movement or privilege escalation beyond proof of existenceCoordinated disclosurePlease allow us a reasonable amount of time to investigate and remediate the issue before any public disclosure. Coordinated disclosure helps protect users and systems while ensuring fixes are properly validated.What you can expect from usWhen a valid report is received, we will:- Acknowledge receipt within a reasonable timeframe- Assess the report and prioritize remediation based on risk and impact- Communicate with you as needed during the investigation- Notify you once the issue has been addressedReports submitted in accordance with this policy and in good faith will not result in legal action by our organization.Bug Bounty and Compensation PolicyCI&T does not currently have a formal bug bounty program. However, we recognize and appreciate the ethical work performed by security researchers who responsibly identify and report potential security vulnerabilities. Historically, we have received and addressed vulnerability reports even in the absence of any established reward program.We invite you to share the details of the potential vulnerability with us so that we can properly analyze it. Based on our assessment and the quality and impact of the findings, we may evaluate, at our sole discretion, the possibility of providing a goodwill reward in recognition of your effort and good faith.Submitting a report does not create any contractual, financial, or legal obligation between you and our organization.Policy updatesThis policy may be updated periodically. The latest version published on our website is always the authoritative version. Contact us