Vulnerability Disclosure Policy
Last updated: September 23, 2026
Our commitment to security research
We welcome help from the security research community, and we’ve built this policy to make it easy to report a vulnerability, and clear what happens after you do.
This policy describes what’s in scope, how to report an issue, what you can expect from us in return, and the protections we offer researchers who report in good faith.
For more on how we protect data and infrastructure day to day, see our Security Overview. For our broader data practices, see our Privacy Policy.
Scope
What’s in scope
- learningcommons.org and its subdomains, including our documentation site
- The Learning Commons Platform, our self-serve portal for Build Partners
- The Knowledge Graph API and REST endpoints
- Our Model Context Protocol (MCP) server integrations
- Evaluators and its SDK
- Curriculum Sync and its learning management system integrations
- Our public repositories at github.com/learning-commons-org
What’s out of scope
- Denial-of-service or load testing of any kind
- High-volume automated scanning that hasn’t been coordinated with us in advance
- Social engineering or phishing directed at our staff or partners
- Physical attacks against our facilities or hardware
- Vulnerabilities in infrastructure we don’t control, including our cloud provider, third-party learning management systems, or the AI products built on top of our tools (for example, an issue inside a third-party AI assistant that uses our Knowledge Graph should be reported to that provider directly)
- Reports based purely on automated scanner output, without a working proof of concept
- Best-practice suggestions or theoretical issues without demonstrated impact we welcome this feedback, but it won’t be tracked as a formal vulnerability report
If you’re not sure whether something is in scope, report it anyway — we’d rather hear about it and rule it out than miss something.
How to report
Email us at security@learningcommons.org with:
- A description of the vulnerability and its potential impact
- Steps to reproduce it, or a proof of concept
- The affected URL, endpoint, repository, or component
- Any tools you used, so we can reproduce your results
Please don’t open a public GitHub issue for a security vulnerability — email keeps the details private while we work on a fix.
Recognition
We’re grateful to the researchers who help keep Learning Commons safe. With your permission, we’re happy to credit you publicly once an issue is resolved. Learning Commons doesn’t currently offer monetary rewards through this program.
Questions
If anything in this policy is unclear, or you’d like to report a vulnerability, reach us at security@learningcommons.org.