How to report a vulnerability

  • Email [email protected] with Security in the subject line.
  • Include the product and version, what you found, steps to reproduce, and the impact you believe it has.
  • Do not include real student data. Use sample data to demonstrate the problem.
  • Do not report security issues in public forums or public issue trackers.

We aim to acknowledge security reports within one business day. Machine-readable contact details are published at /.well-known/security.txt.

How we classify issues

SeverityExamplesFix target
CriticalAccess to student or institutional data without valid credentials; running code on the server; bypassing authenticationFix released within 7 calendar days of confirmation
HighA signed-in user reaching data or actions beyond their role; exposure of stored secretsFix released within 30 days of confirmation
Medium and lowIssues that need unusual conditions or have limited impactFixed in a regular release

These are targets, not guarantees. Contractual commitments are in the Data Processing Agreement.

What happens after a report

  1. AcknowledgeWe confirm we received the report and may ask follow-up questions.
  2. Reproduce and assessWe confirm the issue on a test installation and assign a severity.
  3. Fix and verifyWe build the fix, add an automated test for it where possible, and have it checked by a separate reviewer.
  4. Release and notifyWe release an updated installer and tell affected customers what changed, what they should do, and any interim mitigation.
  5. DiscloseWe describe the fix in the public changelog once customers have had reasonable time to update. By default we coordinate public disclosure within 90 days of the report.

Customer notification

  • Vulnerabilities: we notify customers directly when a release fixes a security issue that affects them.
  • Incidents on our side: we notify affected customers within 72 hours of confirming unauthorized access involving our code, systems, or personnel.
  • Incidents on your side: your institution detects and responds to incidents on its own servers and networks. Please tell us within 72 hours if an incident involves the application, so we can help and check whether other customers are affected.

Guidance for your IT team

An incident response runbook for institution IT staff (containment, evidence preservation, audit log review, and recovery) is included with Atlas K-12 installations and provided to AtlasOA customers. The audit log and backups are your main tools during an investigation. The runbook shipped with current Atlas K-12 installers predates the September 2026 release; where it differs from the Trust Center (data folder location, audit log export, session end on deactivation), the Trust Center is current.

Responsible disclosure expectations

  • Test only on installations you are authorized to test, such as your own evaluation copy.
  • Do not access, change, or keep data that is not yours, and stop and report as soon as you see real personal data.
  • Give us reasonable time to fix the issue before publishing details.

We will credit researchers in the changelog if they wish.

Do not take our word for it. Test it yourself. Install AtlasOA or Atlas K-12 on a machine your institution controls, use sample or non-production data, and let your own people decide.