Home / Bug Bounty
Bug Bounty
Help us keep school data safe. If you find a security issue in Spark-Ed, we want to hear about it.
Last updated: 29 September 2026
1. In scope
- The Spark-Ed website at spark-ed.app.
- The Spark-Ed web application and mobile apps.
- Spark-Ed APIs.
2. Out of scope
- Social engineering, phishing or physical attacks against our staff, schools or offices.
- Denial-of-service or volumetric testing, and spam.
- Third-party services and providers we integrate with.
- Reports from automated scanners without a demonstrated impact.
- Missing security best practices with no practical exploit.
3. Rules
- Test only with accounts you own or have permission to use.
- Do not access, change, copy or delete data that belongs to other schools, staff, students or parents. If you reach such data by accident, stop and report it.
- Do not disrupt the service or degrade it for other users.
- Keep the details private until we have confirmed a fix. Do not publish or share them before then.
4. How to report
Email [email protected] with the subject “Security report”. Please include a clear description, the steps to reproduce, the impact you see, and any proof of concept. Tell us how to contact you.
5. What to expect
- We acknowledge your report and assess it.
- We keep you updated while we investigate and fix the issue.
- With your permission, we credit you once the issue is resolved.
6. Rewards
Rewards, where offered, are at our discretion and depend on the severity and impact of the finding. We do not publish fixed reward amounts.
7. Good-faith research
We treat research that follows this policy as authorized and will not take action against you for it.