Skip to main content

Responsible Disclosure Policy

TextTrek takes the security of student data seriously. We welcome reports from security researchers who identify potential vulnerabilities in our systems.

Scope

In scope:

  • texttrek.app and all subdomains
  • TextTrek API endpoints
  • Authentication and session management flows
  • Authorization boundaries between student, teacher, and admin roles
  • Data exposure or leakage via any channel

Out of scope:

  • Denial-of-service (DoS/DDoS) testing — do not attempt
  • Social engineering of TextTrek staff, teachers, students, or school personnel
  • Physical attacks on any school, district, or hosting facility
  • Attacks against third-party services we use (Supabase, Vercel, Anthropic) — report those to the respective vendor
  • Automated scanning that degrades service availability
  • Findings in third-party libraries where the issue is already publicly disclosed (CVEs)

How to report

Email security@texttrek.app with:

  1. A description of the vulnerability
  2. Steps to reproduce (as specific as possible)
  3. The potential impact as you understand it
  4. Your preferred contact method for follow-up

Please do not file public GitHub issues for security vulnerabilities.

What we commit to

CommitmentTimeline
Acknowledge your report5 business days
Initial triage and severity assessment10 business days
Remediate Critical-severity issues14 days
Remediate High-severity issues30 days
Remediate Medium-severity issues90 days
Notify you when the fix is deployedSame day as deployment

Safe harbor

We will not pursue legal action against researchers who:

  • Make a good-faith effort to avoid accessing or modifying data belonging to other users
  • Report vulnerabilities to us before disclosing them publicly
  • Do not exploit a vulnerability beyond what is necessary to confirm its existence
  • Do not perform actions that degrade service availability for real users
  • Comply with the scope restrictions above

Recognition

We do not currently offer monetary bounties. We are happy to credit you by name (or pseudonym) on a security researchers acknowledgment page and provide a written confirmation of your contribution for professional or academic purposes.

What this policy does NOT cover

  • Breach notification: confirmed data breaches are communicated to affected parties under our Data Sharing and Privacy Agreement — a separate obligation from this policy.
  • Bug reports: non-security functional bugs should be reported through normal support channels.

Policy version 1.0 — Last updated April 2026. Machine-readable contact: /.well-known/security.txt