Legal
Security and vulnerability disclosure
How the platform is secured, and how to report a vulnerability to us.
Reporting
How to tell us about a vulnerability
Write to security@aurethiaeducation.com with enough detail to reproduce the issue. A request path, a payload and what you saw is usually enough. Please do not open a public issue first.
A human replies within 2 working days. That is a commitment about a reply, not about a fix: the fix time depends on what you found, and we will tell you which it is in the reply.
Scope
What we would like you to look at
Anything that lets one institute read another institute data. The repository layer injects a tenant filter on every read and every write, so a way past it is the most serious class of bug in this product.
Anything that returns a question image, a mark scheme or an export to an account without a valid entitlement.
Anything that exposes a student record, a mark, a comment or a fee to a person who should not see it. Students never see fees at all, by design.
Authentication and session handling, including anything that makes a signed URL outlive its expiry or reach a second account.
Out of scope
What we already know
Rate limiting is held in one process memory today and is not shared between instances. It is stated in the code and it is on the list.
The style source in the content security policy permits inline styles, because the design system sets CSS custom properties through the style attribute.
Reports produced only by an automated scanner, with no demonstrated impact.
The safe harbour paragraph is not written yet.
A disclosure policy normally promises not to pursue a researcher acting in good faith. That promise is a legal undertaking rather than an engineering one, so it is being reviewed before it is published here. Until it appears, a report is still welcome and still answered.
What we do not do
Two things worth stating plainly
No readable passwords
Passwords are hashed with argon2id and nobody can read one, including the super admin. This was asked for twice and refused twice, because these users are children and a readable password is every one of their credentials one breach away from disclosure.
No public objects
Nothing in the storage bucket is publicly readable. Every image and every export is a short lived signed URL issued after the entitlement has been checked, so a leaked link stops working rather than becoming a permanent hole.
For the drafter
What this document has to answer
Each line is a question the build team could not answer and a lawyer will need answered. They are listed rather than guessed at.
The safe harbour paragraph, which promises not to pursue a good faith researcher, is the one part of this page that is a legal undertaking and it must be reviewed before it is published.
The breach notification commitment and its clock, which is a regulatory deadline rather than a preference.
Ownership
Who writes it
The engineering team, with the safe harbour wording reviewed by counsel.
Versioning
How you can tell what you agreed to
This is version 0.3, in force from 1 Aug 2026. Nobody accepts one document on its own, so what is recorded against an account is the whole set in force at that moment, stamped with every document's version. The set today is acceptable-use 0.1, privacy 0.1, refunds 0.1, security 0.3, terms 0.1.
If you have an account, your settings screen shows which version you accepted and when, and asks again when the set moves on. Nothing is ever rewritten in place: a new acceptance is a new record, because the old one is the evidence of what was true then.
Elsewhere