Security & Vulnerability Disclosure
Last updated: August 31, 2026
Draft prepared for review. This page describes the product as it works today, to the best of our records, but it has not been reviewed by a lawyer and is not legal advice. Do not rely on it as a finished policy until qualified counsel has reviewed it.
Limud handles education records for K-12 students, so we take security reports seriously. If you believe you have found a security vulnerability in Limud, please tell us before disclosing it publicly, so we have a chance to fix it first.
1. How to Report
Email legal@limud.co with:
- a description of the vulnerability and its potential impact;
- steps to reproduce it, including any request/response details, URLs, or screenshots; and
- your contact information, so we can follow up with questions or to confirm a fix.
We aim to acknowledge reports within 2 business days.
2. What We Ask You Not to Do
Please do not, in the course of investigating or reporting an issue:
- access, modify, or delete data belonging to a real (non-test) account other than one you control;
- run automated scanning that could degrade the service for other users, including students and schools currently using the platform;
- publicly disclose a vulnerability before we have had a reasonable opportunity to address it; or
- attempt to access another school or district's data.
3. Good-Faith Research
We will not pursue legal action against a researcher who makes a good-faith effort to comply with this policy, reports a vulnerability responsibly, and avoids privacy violations, service disruption, or data destruction while doing so.
4. What Happens Next
We investigate every report, prioritize fixes based on severity and exploitability, and will let you know once a report is resolved. We do not currently offer a paid bug-bounty program.
5. Contact
Email legal@limud.co to report a vulnerability, or privacy@limud.co for privacy-specific concerns.