Security disclosure
Last updated: 26 September 2026
Draft — this document has not yet been reviewed by a lawyer and may change before launch.
1. Our commitment
We would much rather hear about a security weakness from a careful researcher than find it any other way. If you believe you have found one in SchoolTrendz, please tell us the way described on this page, and we will treat your report seriously, investigate promptly, and keep you updated.
2. Scope
This policy covers:
- schooltrendz.com — this marketing website
- app.schooltrendz.com — the SchoolTrendz portal (the school ERP itself)
3. Out of scope
The following are outside the scope of this policy, and we ask researchers not to attempt them against SchoolTrendz or our schools:
- Denial-of-service (DoS) testing, or anything that could degrade the service for schools
- Social engineering of our staff, contractors, or any school, teacher, parent or student
- Physical attempts to access our premises or equipment
- Automated, high-volume scanning that could affect the availability of the platform
4. How to report
Please use our contact page and choose the topic "Something else", describing that it's a security report. Once a dedicated security e-mail address is published, we will list it here instead.
Please do not post details of a suspected vulnerability publicly before we have had a reasonable chance to look into it and respond.
5. What to include
A report is far more useful — and much faster for us to act on — when it includes:
- A clear description of the issue and why you believe it's a security weakness
- Steps to reproduce it, ideally with a proof of concept that doesn't touch real school data
- The URL, screen or API endpoint involved, and roughly when you tested it
- Anything you think might help us judge its severity or impact
- A way to reach you for follow-up questions
6. What to expect from us
We will acknowledge a genuine report, investigate it, and keep you reasonably informed of progress. We may ask follow-up questions, and once a fix is in place we're happy to let you know and, if you'd like, credit you for the find (unless you'd rather stay anonymous).
7. Safe harbour for good-faith research
If you make a good-faith effort to follow this policy — staying within scope, avoiding the out-of-scope activities above, not accessing or changing data beyond what's needed to demonstrate the issue, and reporting to us before disclosing publicly — we will not pursue legal action against you for that research, and we will treat it as authorised testing under this policy.
8. No bug bounty at present
We do not currently run a paid bug-bounty programme. We do, however, genuinely value responsible reports and will say so publicly when we can, with your permission.
9. Thank you
Thank you for taking the time to help keep school data safe. If you're not sure whether something is in scope, or you're not sure this is even a security issue, please write to us anyway — we would rather hear from you than not.