← Return to KirthiVerse

Security and responsible disclosure

KirthiVerse welcomes responsible reports that help protect learners, families, teachers and the platform.

What to report

Authentication or authorisation defects, data exposure, cross-site scripting, insecure direct-object access, harmful content bypasses, dependency vulnerabilities and other reproducible security weaknesses.

How to report

Use the contact page. Include affected URL, clear reproduction steps, expected and actual behaviour, impact, and non-sensitive evidence. Do not include passwords, private keys or unnecessary personal data.

Safe testing rules

Do not access another person’s information, disrupt service, perform denial-of-service testing, use social engineering, publish an unresolved vulnerability, or retain data obtained during testing.

Current release boundary

The current learner experience is local-first. Progress is stored in the browser. Cloud identity and school tenancy remain future controlled releases and must pass separate security gates before launch.

Canonical disclosure file: /.well-known/security.txt