Skip to content
Resources

Vulnerability Disclosure Policy

How to report a security problem in Trace, what we will do, and what we ask of you.

Last updated: 2026-09-22

Contact: [email protected]

Trace serves students, many of them minors. If you find a security or privacy problem in Trace, we want to hear about it, and we will treat you as a partner rather than a threat as long as you follow the rules below.

1. How to report#

Email [email protected] with the subject line Security report. Include:

  • what you found and where (URL, endpoint, or feature);
  • steps to reproduce it;
  • what impact you believe it has;
  • how we can reach you for follow-up.

The same contact is published at https://trace.school/.well-known/security.txt. If a report contains student data you saw by accident, say so and do not include the data itself.

2. What we will do#

StepCommitment
Acknowledge your reportWithin 2 business days
Triage and assign a severityWithin 5 business days
Keep you informedAt least every 10 business days until the issue is closed
FixCritical issues within 7 days, high within 30, medium within 90, in line with our internal security policy
CreditWith your permission, we will name you when the fix ships

If a report shows any sign that an issue has already been exploited, we open an incident and follow our incident response plan, which includes notifying affected schools within the windows in our Data Processing Agreement.

We do not run a bug bounty and do not pay for reports.

3. What we ask of you#

  • Test only against accounts you own or have been given for the purpose. Do not access, change, or download another person's data. If you reach data that is not yours, stop, record the minimum needed to describe the problem, and report it.
  • Do not run denial-of-service tests, spam, phishing, or physical or social-engineering attacks.
  • Do not exploit a finding beyond what is needed to show it exists.
  • Give us a reasonable time to fix the issue before you publish anything about it. We will agree a date with you. Our default is 90 days from acknowledgement, or sooner once a fix is live.
  • Delete any data you obtained during testing once the issue is closed.

4. Safe harbor#

If you make a good-faith effort to follow this policy, we consider your research authorized. We will not pursue or support legal action against you for it, and if a third party starts action against you for research that followed this policy, we will make it known that you acted within it. This does not cover testing that breaks the rules in section 3.

5. Scope#

In scope: trace.school, its API, and the Trace SDK gateway.

Out of scope: the services of our subprocessors (WorkOS, Stripe, OpenRouter, and the others listed in our subprocessor list). Report a problem in one of those to that company. If you think it affects Trace specifically, tell us too.

6. Changes#

We may update this policy. The date at the top is the version that applies. A report made under an earlier version is handled under that version.