Skip to content

SECURITY

How to report a vulnerability

EduCollective is a free, open platform used by schools and by people who work with children. We would much rather hear about a problem from you than read about it later. If you have found something, please tell us.

How to report

Email info@educollective.org with "Security" in the subject. Please include what you found, where, and enough detail for us to reproduce it. Screenshots or a short recording help. You can write in German or English.
Our machine-readable contact details are at /.well-known/security.txt.

Safe harbour

If you follow this policy in good faith, we will not take legal action against you, and we will not report you to the authorities for your research. We consider work done under this policy to be authorised, and we will not ask you to sign anything.
This is our own commitment. It cannot bind a third party, so it does not cover testing anything that is not ours: our hosting, database and email providers are named in our Privacy Policy, and their own rules apply to them.

Please do not

  • Access, change or download other people’s personal data. If you can reach it, stop there and tell us. A single screenshot proving access is enough; we do not need the data.
  • Run denial-of-service or load tests, or anything that degrades the service for others.
  • Use social engineering, phishing, or physical attempts against our team or our providers.
  • Publish the issue before we have had a reasonable chance to fix it.
  • Test with a real school’s or a real person’s account. Make your own.

What we are most interested in

  • Anything that exposes one account’s data to another, especially anything touching a school or a classroom account.
  • Authentication and session problems, or ways to act as somebody else.
  • Ways to bypass our row-level security in the database.
  • Stored cross-site scripting, or anything that runs in another person’s browser.
  • Ways to send mail that appears to come from us.
Reports generated only by an automated scanner, with no demonstrated impact, are usually not useful to us. Missing hardening headers on their own, rate limits you reached by trying, and issues that need a device the victim already controls are generally out of scope.

No bounty

We do not pay for reports. EduCollective is free to use, carries no advertising and is run by a non-profit, so there is no budget to pay from and we would rather be honest than string you along.

Our Value Compass

These six rules hold for everyone on EduCollective, and they hold while you are testing too. You will find the same Value Compass on our home page.
  • Be Kind, Be Safe
    No harassment, violence, threats, or abuse; nothing that harms or exploits young people.
  • Equality
    No person or group stands above another; supremacist or discriminatory content is not permitted.
  • Grounded
    Knowledge rests on fact and reason; opinion must be clearly labeled as such.
  • Secular
    Promoting the existence of god is not permitted; religion may be studied as a human phenomenon.
  • Be Real
    One genuine account per person or group; no impersonation, fake identities, bots, or off-topic entries.
  • Offer, Don’t Push
    Share your work, don’t market it; no spam, cold campaigns, or affiliate links.

Not a security problem?

To report harmful, illegal or infringing content rather than a technical flaw, use the Report function on any profile, group, activity or review, or see section 23 of our Terms of Use. For questions about your personal data, see our Privacy Policy.