Security & Responsible Disclosure
Security is our discipline, not our marketing. This page describes our practices and how to report vulnerabilities.
Our practices
- Every software release is signed, with SHA-256 checksums published alongside downloads.
- Privileged administrative actions on our platform are audit-logged.
- Changes to authentication or release infrastructure require two-person review.
Reporting a vulnerability
If you believe you have found a security issue in any EduSentinel AI property or product, use the form below. It reaches the same inbox as security@edusentinel.ai, which you are equally welcome to email directly — the form simply asks for the details we need to triage a report quickly.
You may report anonymously. Please do not include live credentials or third-party personal data in your report.
Our commitment to researchers
- Acknowledgement of your report within 72 hours.
- A remediation target and status updates while we fix the issue.
- Coordinated disclosure within 90 days of report.
- No legal action against good-faith research that avoids privacy violations, data destruction, and service disruption.
Machine-readable contact details are published at /.well-known/security.txt.