Responsible disclosure policy
Last updated: August 20, 2026.
SuperSchool welcomes good-faith security research that helps us protect educators, schools, and classroom data. This policy explains how to report a potential vulnerability and the conduct we consider authorized.
Scope
This policy covers systems and services operated by SuperSchool Inc., including:
superschool.usand its subdomains;- SuperSchool web applications and APIs; and
- authentication, authorization, and data-access controls used by the service.
Third-party services, social-engineering attacks, denial-of-service testing, and physical security are outside scope.
How to report
Email developers@superschool.us with:
- a clear description of the issue and its potential impact;
- the affected URL, endpoint, or feature;
- reproducible steps or a minimal proof of concept;
- the date and time of testing; and
- a safe way to contact you.
Please do not include classroom content, personal information, credentials, or more sensitive data than is necessary to explain the issue. If sensitive material is required, ask us to arrange a secure transfer method first.
Research rules
To keep research within this policy:
- use accounts and data you own or have explicit permission to test;
- stop testing and report the issue if you encounter another person's data;
- do not retain, copy, download, alter, or disclose data that is not yours;
- avoid privacy violations, disruption, degradation, spam, and denial of service;
- do not use social engineering, phishing, credential stuffing, or physical attacks;
- do not introduce malware or establish persistent access;
- make only the minimum requests needed to demonstrate the issue; and
- allow us a reasonable opportunity to investigate and remediate before public disclosure.
Our commitment
If you follow this policy and act in good faith, SuperSchool will consider your research authorized and will not initiate legal action against you for that research. If a third party initiates legal action, we will make reasonable efforts to explain that your activity complied with this policy.
This authorization does not bind third parties, excuse violations of law, or authorize access to data or systems beyond the scope above.
We aim to acknowledge a report within three business days, keep you informed as we investigate, and coordinate any public disclosure. Remediation time depends on severity and complexity.
SuperSchool does not currently operate a paid bug-bounty program. We may recognize helpful reports with the researcher's permission.
Safe harbor limits
This policy does not authorize extortion, threats, public disclosure before a reasonable remediation period, or any activity that causes harm. We may change or end the program, but changes will not retroactively remove safe harbor from research that complied with the policy in effect at the time.
Security reports: developers@superschool.us