Security is an ongoing process, not a one-time milestone. Responsible vulnerability disclosure helps strengthen our platform by enabling security researchers to report potential issues through a coordinated and transparent process.
eResource Scheduler, developed by Enbraun Technologies Private Limited, is supported by SOC 2 Type II and ISO 27001 certifications, regular third-party penetration testing, and continuous security practices. We encourage responsible disclosure and are committed to investigating and remediating valid security findings promptly.
Scope
In scope:
- The eResource Scheduler web application (app.eresourcescheduler.cloud and related subdomains)
- The eResource Scheduler API
- Official iOS and Android mobile applications
- Marketing and support properties (eresourcescheduler.com, support.eresourcescheduler.cloud) for issues that expose customer or account data
Out of scope:
- Third-party services we integrate with but do not control (Stripe, Zendesk, SendGrid, Zoho, and similar sub-processors)
- Denial-of-service testing, spam, or social engineering aimed at our employees or customers
- Automated scanning that generates high-volume traffic without prior coordination with our security team
- Issues that require physical access to a user's device
- Reports based purely on missing security headers or best-practice suggestions with no demonstrated impact
If you are not sure whether something is in scope, ask us before you dig further. We would rather answer a question than have you waste your time.
A Note on Our Terms of Service
Our standard Terms of Service restrict activity like probing our systems or attempting unauthorized access, for good reason. That restriction is not meant for you if you are acting in good faith under this program.
Safe harbor: If you make a genuine effort to follow this policy, stay within scope, and avoid privacy violations, data destruction, or service disruption, we will not pursue legal action against you for that research. We consider this activity authorized under our Terms of Service for the purposes of this program only.
This safe harbor does not extend to testing that falls outside the scope above, or to any activity that violates applicable law.
How To Report
Send your report to support@enbraun.com.
Include as much of the following as you can:
- A clear description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce it
- The URL, endpoint, or app version affected
- Any proof-of-concept code, screenshots, or logs that support your finding
Please do not include real customer data in your report. If a vulnerability exposes such data, describe what you saw without copying or storing it.
What Happens After You Report
- Acknowledgment within 3 business days. We will confirm we received your report and give you a point of contact.
- Triage and severity assessment within 10 business days. We evaluate impact using a CVSS-based framework and confirm whether the finding is valid.
- Remediation timeline based on severity. Critical and high-severity issues are prioritized for the fastest possible fix. We will keep you updated on progress at reasonable intervals.
- Resolution confirmation. Once fixed, we will let you know and, where appropriate, ask you to verify the fix.
We ask that you give us 90 days from acknowledgment before any public disclosure, unless we agree to a different timeline together. Coordinated disclosure protects your work and our customers at the same time.
Reporting Responsibly
- Give us reasonable time to investigate and fix an issue before disclosing it publicly
- Avoid accessing, modifying, or deleting data that is not yours
- Test only against accounts you control, or use a trial account created for this purpose
- Do not use findings to pivot into other systems, escalate access beyond what is needed to confirm the issue, or pursue further exploitation
- One issue per report, so we can track and respond accurately
Recognition
This is currently a disclosure-only program, not a paid bug bounty. We are glad to credit researchers by name (with permission) on this page for validated, meaningful findings. If that changes, this page will be updated first.
Got Questions?
For anything not covered here, reach out to support@enbraun.com. For privacy-specific questions, our Privacy Policy has the details on how we handle data, including our 72-hour breach notification commitment under GDPR.
Thank you for helping keep eResource Scheduler secure. Reports like yours are the reason our customers can trust us with their schedules, their teams, and their data.