Responsible Vulnerability Disclosure
Guidelines for researchers and users who identify a potential Studyula security issue and want to report it safely and in good faith.
Last updated: 4 September 2026
If you identify a security issue, stop before affecting real user data and report it to support@studyula.com. We aim to review good-faith reports promptly.
1. How to report
Email support@studyula.com with “Security” in the subject. Include the affected URL/feature, a concise description, reproduction steps and, where useful, a non-sensitive screenshot or example. Do not email passwords, access keys or real learner data.
2. Good-faith testing boundaries
Test only your own account, explicitly authorized test data or resources you own. Use the minimum interaction needed to verify the issue and stop if sensitive data becomes visible.
3. Prohibited testing
DoS/DDoS, brute force, social engineering, phishing, spam, malware, physical attacks, downloading/modifying/deleting data, accessing another user’s account or disruptive automation are not permitted.
4. After a report
Studyula verifies the issue, evaluates severity and plans remediation. We ask that security details not be publicly disclosed before a reasonable remediation opportunity.
5. Good-faith approach
We view reports from researchers who follow these rules as a valuable part of improving security. This policy does not authorize violation of law or third-party rights and is not a promise of a paid bug bounty.