Adaptive Tutor

Coordinated Disclosure

Report a security issue privately

Do not put exploit details, credentials, access tokens, learner information, or an unpatched vulnerability in a public issue, discussion, or pull request.

Private reporting routes

  1. Email admin@adaptivetutor.ai with the subject PRIVATE SECURITY REPORT.
  2. Do not send the report through a public issue, discussion, pull request, or support form.

Include the affected route or version, the minimum synthetic reproduction, impact, required attacker access, and a safe way to contact you.

Automated tools can discover the same contact and policy at /.well-known/security.txt. The record has a review expiry and must not be treated as current after that timestamp.

Safe-testing boundary

Stop after demonstrating the minimum impact. Do not perform denial-of-service testing, automated account enumeration, social engineering, persistence, data destruction, or access to another person's records. This project cannot authorize testing of third-party providers, including Render, IONOS, payment, email, or AI providers.

What to expect

The project aims to acknowledge a credible report within three business days and provide a triage update within seven business days. These are targets, not contractual service levels or a promise of a bug bounty. This page and the same-origin security.txt record are the deployed public reporting guidance; access to the private development repository is not required.