Responsible Disclosure Policy
TextTrek takes the security of student data seriously. We welcome reports from security researchers who identify potential vulnerabilities in our systems.
Scope
In scope:
texttrek.appand all subdomains- TextTrek API endpoints
- Authentication and session management flows
- Authorization boundaries between student, teacher, and admin roles
- Data exposure or leakage via any channel
Out of scope:
- Denial-of-service (DoS/DDoS) testing — do not attempt
- Social engineering of TextTrek staff, teachers, students, or school personnel
- Physical attacks on any school, district, or hosting facility
- Attacks against third-party services we use (Supabase, Vercel, Anthropic) — report those to the respective vendor
- Automated scanning that degrades service availability
- Findings in third-party libraries where the issue is already publicly disclosed (CVEs)
How to report
Email security@texttrek.app with:
- A description of the vulnerability
- Steps to reproduce (as specific as possible)
- The potential impact as you understand it
- Your preferred contact method for follow-up
Please do not file public GitHub issues for security vulnerabilities.
What we commit to
| Commitment | Timeline |
|---|---|
| Acknowledge your report | 5 business days |
| Initial triage and severity assessment | 10 business days |
| Remediate Critical-severity issues | 14 days |
| Remediate High-severity issues | 30 days |
| Remediate Medium-severity issues | 90 days |
| Notify you when the fix is deployed | Same day as deployment |
Safe harbor
We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid accessing or modifying data belonging to other users
- Report vulnerabilities to us before disclosing them publicly
- Do not exploit a vulnerability beyond what is necessary to confirm its existence
- Do not perform actions that degrade service availability for real users
- Comply with the scope restrictions above
Recognition
We do not currently offer monetary bounties. We are happy to credit you by name (or pseudonym) on a security researchers acknowledgment page and provide a written confirmation of your contribution for professional or academic purposes.
What this policy does NOT cover
- Breach notification: confirmed data breaches are communicated to affected parties under our Data Sharing and Privacy Agreement — a separate obligation from this policy.
- Bug reports: non-security functional bugs should be reported through normal support channels.
Policy version 1.0 — Last updated April 2026. Machine-readable contact: /.well-known/security.txt