Security & Responsible Disclosure

Security is our discipline, not our marketing. This page describes our practices and how to report vulnerabilities.

Our practices

  • Every software release is signed, with SHA-256 checksums published alongside downloads.
  • Privileged administrative actions on our platform are audit-logged.
  • Changes to authentication or release infrastructure require two-person review.

Reporting a vulnerability

If you believe you have found a security issue in any EduSentinel AI property or product, use the form below. It reaches the same inbox as security@edusentinel.ai, which you are equally welcome to email directly — the form simply asks for the details we need to triage a report quickly.

You may report anonymously. Please do not include live credentials or third-party personal data in your report.

Reporting anonymously is fine — the name and email fields are optional. Without an address we cannot acknowledge the report or tell you when it is fixed.

Our commitment to researchers

  • Acknowledgement of your report within 72 hours.
  • A remediation target and status updates while we fix the issue.
  • Coordinated disclosure within 90 days of report.
  • No legal action against good-faith research that avoids privacy violations, data destruction, and service disruption.

Machine-readable contact details are published at /.well-known/security.txt.