Reporting a vulnerability
If you have found something, we want to hear about it.
Where to send it
security@neurolearnai.uk. We aim to acknowledge within 5 working days. Include what you found, how to reproduce it, and what an attacker could do with it.
Safe harbour
If you act in good faith, stay within the scope below, avoid privacy violations and service degradation, and give us reasonable time before publishing, we will not pursue or support legal action against you.
In scope
- neurolearnai.uk and its API routes.
- Certificate forgery, tampering with the register, or bypassing verification.
- Cross-site scripting, injection, or anything letting one visitor affect another.
Out of scope
- Volumetric denial of service. Please do not.
- Reports from automated scanners with no demonstrated impact.
- Missing security headers with no exploitable consequence.
- Anything already listed below.
Already known — no need to report
Assessments are graded in the browser, and the key used to derive certificate IDs is present in the client bundle, so a determined person can construct a certificate ID without taking an assessment. This is documented on how verification works and is being fixed by moving issuance server-side. A working demonstration is still welcome; a report that this is theoretically possible is not news to us.
What we will do
- Acknowledge your report.
- Tell you whether we agree it is a vulnerability, and why if not.
- Fix it, and tell you when it is fixed.
- Credit you publicly if you want to be credited.
There is no bug bounty. This is a free service with no revenue.