Responsible Vulnerability Disclosure 

Our approach to security

Security is a shared responsibility. We genuinely appreciate the work of security researchers, ethical hackers, and members of the cybersecurity community who help make technology safer.

While we do not operate a bug bounty or reward program, we welcome responsible, good-faith vulnerability reports that help us identify and mitigate potential risks. This policy explains how to report security issues safely and what you can expect from us in return.

Scope

This policy applies only to systems, applications, services, and infrastructure owned or directly operated by us.

The following are out of scope:
- Systems or environments owned by customers, partners, vendors, or third parties
- Social engineering, phishing, or interactions with employees or users
- Denial-of-service, brute-force attacks, or stress testing
- Physical security testing
- Findings with no practical security impact or purely informational issues

How to report a vulnerability

If you believe you have identified a security vulnerability, please report it to: securitytalk@ciandt.com

To help us investigate efficiently, please include:
- A clear description of the issue
- The affected system, URL, endpoint, or component
- Steps to reproduce the issue using a non-destructive proof of concept
- The potential security impact
- Suggested remediation, if available
- Your preferred contact information

Reports that lack sufficient detail may not be reviewed.

Responsible research guidelines

We ask that all research conducted under this policy:
- Is performed in good faith and in compliance with applicable laws
- Is limited to the minimum testing required to confirm the vulnerability
- Does not access, modify, copy, or exfiltrate data belonging to users or systems
- Stops immediately if sensitive data is encountered and is reported without delay
- Avoids service disruption, performance degradation, or persistence
- Does not involve lateral movement or privilege escalation beyond proof of existence

Coordinated disclosure

Please allow us a reasonable amount of time to investigate and remediate the issue before any public disclosure. Coordinated disclosure helps protect users and systems while ensuring fixes are properly validated.

What you can expect from us

When a valid report is received, we will:
- Acknowledge receipt within a reasonable timeframe
- Assess the report and prioritize remediation based on risk and impact
- Communicate with you as needed during the investigation
- Notify you once the issue has been addressed

Reports submitted in accordance with this policy and in good faith will not result in legal action by our organization.

Bug Bounty and Compensation Policy

CI&T does not currently have a formal bug bounty program. However, we recognize and appreciate the ethical work performed by security researchers who responsibly identify and report potential security vulnerabilities. Historically, we have received and addressed vulnerability reports even in the absence of any established reward program.

We invite you to share the details of the potential vulnerability with us so that we can properly analyze it. Based on our assessment and the quality and impact of the findings, we may evaluate, at our sole discretion, the possibility of providing a goodwill reward in recognition of your effort and good faith.

Submitting a report does not create any contractual, financial, or legal obligation between you and our organization.

Policy updates

This policy may be updated periodically. The latest version published on our website is always the authoritative version.

Contact us