What you may do
If the goal is finding a security vulnerability on in-scope Tefily systems, you may use any technical technique you believe is useful. That includes, without limitation:
- Automated scanning, fuzzing, and brute-force of our own endpoints
- Authentication, authorization, and tenancy bypass attempts
- Injection, SSRF, path traversal, deserialization, and similar tests
- Creating accounts, projects, orgs, apps, and other resources for testing
- Exercising APIs, git hosting, file storage, hosting, DNS, and console flows
- Chaining issues and demonstrating impact on systems we operate