Security

Vulnerability disclosure

MathPath is built and run by a small team that takes security seriously. If you have found a vulnerability, we want to hear from you, and we will work with you in good faith to confirm and fix it.

Last reviewed: 6 July 2026

Scope

This policy covers the production application and its API served from our primary domain, including the learner, teacher, and organization surfaces.

  • The web application and its authenticated and public pages.
  • The public and organization API endpoints.
  • Authentication, session, and access-control behavior.

Out of scope

  • Third-party services we rely on (report those to the vendor directly).
  • Denial-of-service, volumetric, or automated-scanner traffic.
  • Social engineering, phishing, or physical attacks against staff.
  • Findings that require an already rooted or compromised device, or a stolen credential.

Safe harbor

We will not pursue legal action against researchers who act in good faith, stay within the scope above, avoid privacy violations and service disruption, and give us a reasonable chance to fix an issue before disclosing it publicly. Access only the minimum data needed to demonstrate a finding, and never modify or delete data that is not yours.

How to report

Send a report to security@learnhub.com.

  • Clear steps to reproduce, including any request or payload used.
  • The impact you believe the issue has.
  • A proof of concept, kept to the smallest demonstration that proves the point.
  • Your contact details so we can follow up and credit you.

Machine-readable contact details live at /.well-known/security.txt

What to expect

We are a small team and support runs during business hours (Pacific time, Monday to Friday). We do not offer around-the-clock response, but we do commit to the following:

  • Acknowledgement of your report within 3 business days.
  • An initial triage and severity assessment within 5 business days.
  • A remediation plan sized to severity: critical issues addressed as fast as we can, lower-severity issues folded into normal release work.
  • An update when the issue is resolved, and credit if you would like it.

No bug bounty yet

We do not run a paid bug-bounty program today. We are grateful for responsible disclosure and will happily credit you, with your permission, once an issue is fixed. If our contracts and resources grow to warrant a paid program, we will announce it here.