← Back to home
Security disclosure policy
Last updated 12 May 2026 · Linked from /.well-known/security.txt (RFC 9116)
How to report a vulnerability
Email security@eduvianai.com with a clear description, reproduction steps, the URL(s) affected, and your assessment of the impact. We aim to acknowledge every report within 3 business days.
What we ask
- Give us 90 days from initial report to remediate before public disclosure. We will keep you updated on progress and credit you when the fix lands (with your permission).
- Stick to the in-scope assets below. Do not attempt to access, modify, or destroy data belonging to other users.
- Avoid heavy load testing, scraping, or anything that would degrade service for legitimate users. If your test needs more than a handful of requests to confirm, email first.
- Do not run social-engineering attacks against our team, partners, or contractors.
In scope
https://www.eduvianai.comand any*.eduvianai.comsubdomain we operate- Authentication flows (OTP register / login, admin TOTP MFA, session cookies)
- API routes under
/api/*including AI tool endpoints and admin routes - The verification + extraction pipelines that build
src/data/programs.ts
Out of scope
- Third-party services we use: Supabase Cloud, Vercel, Anthropic API, Resend, Upstash, Sentry. Please report vulnerabilities in those platforms directly to the respective vendor.
- Reports based solely on the output of automated scanners (e.g., missing security headers on pages that don't need them, weak TLS ciphers on Vercel-managed certificates) unless you can demonstrate an exploitable impact.
- Self-XSS or attacks requiring physical access to a user's unlocked device.
- Findings already documented in our internal audit register that we are actively remediating.
What you can expect from us
- Acknowledgement within 3 business days.
- An initial severity assessment + remediation plan within 10 business days for confirmed reports.
- Status updates at least every 14 days while a fix is in flight.
- Public credit (researcher name / handle linked from the deploy note) once the fix ships, if you want it.
- No legal action against good-faith researchers who follow this policy.
Bug bounty
We do not currently run a paid bug bounty programme. We are still in beta. We do maintain a researcher acknowledgement list and will add a structured programme as we move out of beta — drop us a line if you'd like to be the first contact for the launch round.
Encrypted disclosure
We do not publish a PGP key yet. If you need to send a sensitive attachment, email us first and we will share a one-time secure link.