Coordinated Disclosure
Report a security issue privately
Do not put exploit details, credentials, access tokens, learner information, or an unpatched vulnerability in a public issue, discussion, or pull request.
Private reporting routes
- Email admin@adaptivetutor.ai with the subject PRIVATE SECURITY REPORT.
- Do not send the report through a public issue, discussion, pull request, or support form.
Include the affected route or version, the minimum synthetic reproduction, impact, required attacker access, and a safe way to contact you.
Automated tools can discover the same contact and policy at /.well-known/security.txt. The record has a review expiry and must not be treated as current after that timestamp.
Safe-testing boundary
Stop after demonstrating the minimum impact. Do not perform denial-of-service testing, automated account enumeration, social engineering, persistence, data destruction, or access to another person's records. This project cannot authorize testing of third-party providers, including Render, IONOS, payment, email, or AI providers.
What to expect
The project aims to acknowledge a credible report within three business days and provide a triage update within seven business days. These are targets, not contractual service levels or a promise of a bug bounty. This page and the same-origin security.txt record are the deployed public reporting guidance; access to the private development repository is not required.