SECURITY
How to report a vulnerability, and what we promise in return
EduCollective is a free, open platform used by schools and by people who work with children. We would much rather hear about a problem from you than read about it later. If you have found something, please tell us.
How to report
Email info@educollective.org with "Security" in the subject. Please include what you found, where, and enough detail for us to reproduce it. Screenshots or a short recording help. You can write in German or English.
Our machine-readable contact details are at /.well-known/security.txt.
What we promise
- We will acknowledge your report within 5 working days.
- We will tell you what we think, and keep you updated while we fix it.
- We will credit you by name when the fix ships, if you would like that. You are equally welcome to stay anonymous.
- We will not ask you to sign anything, and we will not ask you to stay silent forever. If we need longer than 90 days, we will explain why.
Safe harbour
If you follow this policy in good faith, we will not take legal action against you, and we will not report you to the authorities for your research. We will say so publicly if anyone else claims otherwise. We consider work done under this policy to be authorised.
This is our own commitment. It cannot bind a third party, so it does not cover testing anything that is not ours: our hosting, database and email providers are named in our Privacy Policy, and their own rules apply to them.
Please do not
- Access, change or download other people’s personal data. If you can reach it, stop there and tell us. A single screenshot proving access is enough; we do not need the data.
- Run denial-of-service or load tests, or anything that degrades the service for others.
- Use social engineering, phishing, or physical attempts against our team or our providers.
- Publish the issue before we have had a reasonable chance to fix it.
- Test with a real school’s or a real person’s account. Make your own.
What we are most interested in
- Anything that exposes one account’s data to another, especially anything touching a school or a classroom account.
- Authentication and session problems, or ways to act as somebody else.
- Ways to bypass our row-level security in the database.
- Stored cross-site scripting, or anything that runs in another person’s browser.
- Ways to send mail that appears to come from us.
Reports generated only by an automated scanner, with no demonstrated impact, are usually not useful to us. Missing hardening headers on their own, rate limits you reached by trying, and issues that need a device the victim already controls are generally out of scope.
No bounty, and why
We do not pay for reports. EduCollective is free to use, carries no advertising and is run by a non-profit, so there is no budget to pay from and we would rather be honest than string you along. What we can offer is a fast, human reply, real credit, and a fix.
Not a security problem?
To report harmful, illegal or infringing content rather than a technical flaw, use the Report function on any profile, group, activity or review, or see section 23 of our Terms of Use. For questions about your personal data, see our Privacy Policy.