1. Introduction

At Lecturio, the security of our customers’ data is our top priority. We appreciate the work of security researchers and believe that a responsible disclosure process is the best way to keep our ecosystem safe.

2. Safe Harbor

If you conduct your research in good faith and comply with this policy, we will not initiate or support any legal action against you. We consider your research “authorized” as long as it adheres to the guidelines below.

3. Rules of Engagement

To remain eligible for recognition (and to stay within Safe Harbor), you must:

  • Use Official Channels: All findings must be submitted to security@lecturio.com.
  • No “Carpet-Bombing”: Do not contact our CEO, CTO, board members, or Customer Success teams. Contacting individual employees regarding a security finding is a violation of this policy and may result in a permanent ban from our disclosure program.
  • No Disruption: Do not perform Denial of Service (DoS) attacks, social engineering (phishing) of our employees, or physical security testing.
  • Privacy First: If you encounter customer data, stop immediately and report the finding. Do not view, alter, or exfiltrate any data that does not belong to you.

4. Scope

The following assets are In-Scope:

  • *.lecturio.com (Main web application)
  • Our official iOS and Android applications

The following are Out-of-Scope:

  • Third-party integrations (e.g., Zendesk, Slack, AWS console).
  • Marketing landing pages hosted on subdomains.

5. Non-Qualifying Vulnerabilities (The “No-Fly” List)

To reduce low-quality reports, the following are strictly excluded:

  • Missing SPF/DKIM/DMARC records.
  • Missing security headers (e.g., CSP, HSTS) that do not lead to a direct exploit.
  • Clickjacking on pages without sensitive actions.
  • “Best practice” suggestions without a working Proof of Concept (PoC).
  • Software version disclosure or banner grabbing.

6. Our Commitment

If you follow this policy, we commit to:

  • Acknowledging receipt of your report within 3 business days.
  • Providing an estimated timeframe for a fix.
  • Notifying you when the vulnerability is remediated.

7. Recognition and Rewards

We may offer a discretionary financial reward (bounty) for high-quality reports. To be eligible for a reward, the following conditions must be met:

  • Impact: The finding must demonstrate a significant risk to the data privacy of our customers (e.g., unauthorized access, alteration, deletion, or leakage of sensitive information).
  • System Integrity: The finding demonstrates a flaw that could severely impact system performance or availability without the researcher having performed a prohibited Denial of Service (DoS) attack.
  • Quality of Report: The submission must include a clear, written Proof of Concept (PoC) and be validated by our internal team.
  • Bounty Terms:
    • Rewards are capped at a maximum of €50 EUR per report, with the final amount determined by our team based on the severity and complexity of the finding.
    • First-to-Report: Only the first researcher to report a specific, previously unknown vulnerability is eligible for a reward.
    • Payment Method: Rewards are typically issued via PayPal. You are responsible for any taxes or transaction fees.
    • Compliance: You must remain in compliance with this policy and the “Safe Harbor” terms throughout the process.

Important: Rewards are contingent on the researcher keeping the finding confidential until a fix has been deployed and we have given explicit permission to disclose.