← ClassOvation

Reporting a security problem

We would much rather hear from you than not. This page says where to send it and what we promise in return.

Where to send it

Email security@classovation.com. If that bounces for any reason, use support@classovation.com — both reach the same person.

Please include enough for us to reproduce it: the URL or endpoint, the steps, and what you saw. A short proof-of-concept is welcome; a full exploit chain is not necessary.

We aim to acknowledge a report within 3 business days. ClassOvation is run by a very small team, so please allow reasonable time for a fix before disclosing publicly. We will tell you when it is fixed, and we are glad to credit you if you would like that. There is no paid bug bounty. We would still like the report.

Please do not access other people's data

This is the one request we would make above all others. Studio records contain the names, dates of birth, addresses and medical notes of children.

If you find a way to reach data that is not yours, please stop at the point where you have proved it — a single record identifier, or a screenshot with the content redacted, is plenty. Do not enumerate, download, keep or share it. Tell us and we will reproduce it ourselves. If you need an account to test with, ask and we will set one up.

Scope

In scope: classovation.com, api.classovation.com, and the ClassOvation mobile apps for iOS and Android.

Out of scope: the third-party services we build on (Stripe, Fly.io, Resend — report those to the vendor, though we would appreciate a heads-up); denial of service, volumetric or load testing against production; social engineering of our staff, studios or families; anything physical; automated scanner output with no demonstrated impact; and missing hardening headers with no exploitable consequence, unless you can show one.

Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue legal action against you or ask anyone else to. We consider such research authorised, and we will say so publicly if it is ever needed.

If you are unsure whether something is in scope, or whether a test goes too far, ask first. We would rather answer a question than receive an apology.

What we do not claim

We hold no security certification — there is no SOC 2 audit, and we do not assert one. What we do have, we describe plainly on our reliability page.