Public informationVersion 2026-08-01

Security & Vulnerability Disclosure

Security practices and a safe process for reporting suspected vulnerabilities.

Service
EduTick for EDUTICK SCHOOL
Effective
August 1, 2026

Security approach

EduTick uses dedicated school deployments, role-based access, database row-level security, private object storage, server-side authorization, audit history, bounded sessions, security headers, dependency checks, and malware scanning for new attachments when production scanning is configured.

These are defense-in-depth measures, not a guarantee that the service is risk-free. EduTick does not claim SOC 2, ISO 27001, FedRAMP, PCI DSS, HIPAA, or other certification unless a current, written report explicitly says so.

Report a vulnerability

Send a concise report using the security contact below. Include the affected URL or component, reproduction steps, impact, and a safe proof of concept. Do not include real student data. If no dedicated security email is configured, use the Support page and ask that the report be escalated privately to the security owner.

Good-faith research

  • Test only accounts and data you own or have explicit written permission to use.
  • Do not access, modify, retain, or disclose another person's information.
  • Do not perform denial-of-service, social engineering, spam, automated high-volume scanning, physical attacks, or attacks against third-party providers.
  • Stop and report immediately if you encounter personal information, credentials, or cross-school access.
  • Allow reasonable time to investigate and remediate before disclosure; coordinate public disclosure with the operator and affected school.

What to expect

Receipt will be acknowledged when a monitored security contact is configured. Triage, update, and remediation timing depend on severity, reproducibility, provider involvement, and school coordination. No bounty, payment, safe-harbor promise, or fixed remediation deadline is offered by this public process.

Sensitive reports

Do not submit vulnerability details through a normal helpdesk ticket if that would expose exploit information to unintended school users. Request a private reporting channel. Never send credentials, access tokens, malware, or unredacted student records by email.

Security contact

security@yourdomain.com