Reporting a vulnerability
We take the security of student, parent, teacher and school data seriously. If you believe you have found a security vulnerability in The English Hub, please report it to us privately at [email protected] with enough detail to reproduce the issue. A machine-readable contact is also published at /.well-known/security.txt (RFC 9116).
What to include
- The affected URL, endpoint or component.
- Steps to reproduce, and the impact you believe it has.
- Any proof-of-concept that does not access, modify or exfiltrate real user data.
- Your contact details so we can follow up.
Our commitments
- We aim to acknowledge a valid report within one working day.
- We will keep you updated on remediation and let you know when the issue is resolved.
- We will not take legal action against researchers who act in good faith and within this policy (safe harbour).
Good-faith research — please do
- Test only against accounts and data you own or have explicit permission to use.
- Stop as soon as you have demonstrated a vulnerability, and report it promptly.
- Give us reasonable time to remediate before any public disclosure.
Please do not
- Access, modify, delete or exfiltrate data belonging to other users — particularly any data relating to children.
- Run denial-of-service tests, spam, or social-engineer our staff or users.
- Publicly disclose an unresolved issue, or test physical or third-party systems.
Scope
In scope: the The English Hub web application and API on theenglishhub.app. Out of scope: third-party providers we rely on (their own disclosure programmes apply), and findings that require a compromised device or a man-in-the-middle position.
This is a coordinated-disclosure policy. A formal bug-bounty programme may follow once our triage and response process is proven. Upskill Energy Limited, Companies House 16511479.