SECURITY

Last updated August 18, 2026

Security at GradePath is built in, not bolted on. This page describes our practices and how to report a vulnerability.

1. What we protect and how

Encryption

Access controls

Application security

Infrastructure


2. Reporting a vulnerability

If you have identified a security vulnerability in GradePath, please report it to us. We appreciate coordinated disclosure.
Contact: [email protected], subject line "Security Report"
Preferred format: Include a clear description of the vulnerability, steps to reproduce, the potential impact, and any proof-of-concept code or screenshots. Do not include actual user data.

3. Safe harbor

We will not pursue legal action against researchers who:

4. What is out of scope


5. Response handling

We review security reports based on the available evidence, severity, scope, and potential user impact. This page does not promise a fixed acknowledgement, assessment, or remediation time.

6. Bug bounty

GradePath does not currently operate a paid bug bounty program. We recognize the work of responsible researchers through public acknowledgement. As the product grows, we intend to launch a bounty program. If you would like to be notified when it opens, include that in your report.

7. Incident notification

In the event of a confirmed security incident affecting user data, we will provide notices as required by applicable law.

8. security.txt

Machine-readable security contact information is available at /.well-known/security.txt per RFC 9116.