Vulnerability Disclosure Policy
Pearl Education welcomes reports from security researchers and the public about potential vulnerabilities in our Products and services. This policy reflects Pearl’s Responsible Disclosure Policy v1.1. We are committed to coordinated, responsible disclosure and to working in good faith with anyone who helps keep Pearl and our school communities safe.
Scope
This policy covers Pearl’s production Products and the canonical domain poweredbypearl.com. Legacy domains that are being migrated or redirected are not in scope; Pearl can confirm specific in-scope subdomains on request.
How to Report
Send your report to seccom@poweredbypearl.com (MSA §3.1; Responsible Disclosure Policy v1.1). Please use a descriptive subject line and do not include actual Student Data or other personal data in your report.
What to Include
To help us triage quickly, please include a clear description of the issue and its potential impact; the affected URL, endpoint, or component; step-by-step reproduction details or a proof-of-concept; and any relevant logs or screenshots. Please do not include actual Student Data or other personal data in your report.
Good-Faith Safe Harbor
Pearl will not pursue or support legal action against researchers for security research and disclosure conducted in good faith and in compliance with this policy. To the extent your good-faith testing complies with this policy, Pearl authorizes it and will treat it as exempt from the acceptable-use restrictions on probing or scanning Pearl systems in MSA §3.3(c). This safe harbor does not cover accessing, modifying, or exfiltrating data beyond the minimum necessary to demonstrate a vulnerability, degrading service, or violating applicable law.
Rules of Engagement
Act in good faith to avoid privacy violations, data destruction, and service disruption. Do not access, store, or share Customer Content or Student Data. Do not run automated scans that degrade service. Give Pearl reasonable time to remediate before any public disclosure, and coordinate timing with us.
Our Response
Pearl will acknowledge valid reports, triage and validate the issue, keep the reporter reasonably informed, and work to remediate confirmed vulnerabilities on a risk-prioritized basis.
Recognition
Pearl does not currently operate a paid bug-bounty program. We appreciate researchers who report responsibly and, with your permission, will credit you once an issue is resolved.
