Security research · Protect customers and report responsibly
Send security reports to security@enteleexchange.com. Use support@enteleexchange.com for general account or product support. Do not include passwords, private keys, seed phrases, authentication codes or unnecessary personal data.

What to report

We welcome good-faith reports concerning authentication, session handling, authorization, data exposure, security headers, cross-site scripting, request forgery, injection, account takeover, sensitive-information disclosure, domain or certificate configuration and other weaknesses that could materially affect EnteleEXCHANGE customers or infrastructure.

Before testing

Use only accounts and data you are authorized to control. Keep testing limited, reversible and proportionate. Stop immediately if you encounter personal data, confidential information, credentials, customer records, unexpected access or any indication that continued testing could affect another person or system.

Prohibited activity

Do not perform denial-of-service testing, traffic flooding, destructive testing, social engineering, phishing, credential stuffing, password spraying, malware deployment, physical attacks, employee impersonation, third-party infrastructure testing, automated account creation at scale, transaction attempts, asset transfers or public disclosure before coordinated remediation.

Report contents

Include the affected URL or component, a clear description, reproducible steps, expected and observed behavior, impact, timestamps, browser or client details and minimal screenshots or logs. Remove secrets and unrelated personal information before sending evidence.

Our response

We will acknowledge receipt when the reporting channel is monitored, triage the issue, request clarification when necessary and coordinate remediation and disclosure based on severity and customer risk. Response targets are not yet contractual service levels and may change as the security operation matures.

Safe-harbor intent

We will not pursue action against researchers who act in good faith, comply with this policy, avoid privacy violations and service disruption, report promptly and allow reasonable time for remediation. This statement does not authorize access to third-party systems or activity prohibited by applicable law.

No bounty promise

EnteleEXCHANGE does not currently operate a paid bug-bounty program. Submission of a report does not create a right to payment, employment, public acknowledgment or any other reward.

Acknowledgments

A public researcher acknowledgment program has not yet launched. Any future acknowledgment will require the reporter's consent and confirmation that disclosure will not create customer or security risk.

Security careers

No dedicated security-careers channel is currently published. General company opportunities, if opened, will be announced through verified TVK Group or EnteleEXCHANGE channels.

Emergency concerns

For an active incident affecting availability, first check System Status. For suspected account compromise, change the account password, review account activity and use the Support Center guidance or email EnteleEXCHANGE Security.