Report a Security Issue
Found a weakness in our platform? Tell us privately and we will fix it. This page sets out what to send, how we respond, and the protections we offer researchers.
Table of Contents
What We Want to Hear About
Anything that could expose student data or let someone act as another user: authentication or session flaws, access-control gaps between student, instructor and admin roles, injection of any kind, exposed credentials or API keys, insecure file uploads, or payment-flow weaknesses. Our web platform and the accounts behind it are in scope.
Usually Out of Scope
Reports generated solely by an automated scanner with no demonstrated impact; missing security headers or cookie flags on their own; rate-limiting or brute-force findings without a working demonstration; social engineering of our staff or students; denial-of-service testing; and issues in third-party services we merely link to. Tell us anyway if you think something here has real impact — we would rather hear it.
How to Report
Email us with "Security" in the subject line, and include:
- What the issue is, and what an attacker could do with it.
- Clear steps to reproduce it — the exact URLs, parameters and any test account you used.
- Screenshots or a short recording, if that makes it clearer.
- How you would like to be credited, if you would like to be.
Please send the report privately and give us a chance to fix the issue before discussing it publicly.
Testing Responsibly
Use only your own accounts and test data. Do not access, modify or download anyone else's personal information, do not degrade the service for students, and stop as soon as you have shown the issue exists. If you come across someone else's data by accident, stop, do not save a copy, and tell us what happened.
What We Will Do
We acknowledge reports within three working days and give you an assessment of severity and a rough timeline within ten. We will keep you updated as we work on a fix, and tell you when it ships. We do not run a paid bounty programme, but we are glad to credit researchers who report responsibly.
Safe Harbour
If you follow the guidance on this page — testing only against your own data, avoiding disruption, and reporting privately — we will treat your research as authorised and will not pursue legal action over it. If a third party brings action against you for such research, we will make it clear that your work was authorised.
Contact Information
Questions about this page, or a report to file? Reach us here:
Last updated: 2026· Mechatronics Institute of Robotics Engineering — Reg No: PV00362322




