Coordinated security

Responsible Vulnerability Disclosure

StudyLabPro supports responsible disclosure of security vulnerabilities.

Security reports concerning StudyLabPro systems should be sent to security@studylabpro.com.

Scope

This policy applies only to systems, software and infrastructure owned or operated by StudyLabPro. It does not authorize testing of third-party systems, services, accounts, networks or data.

If there is doubt about whether a target is in scope, contact StudyLabPro before testing. Absence from this policy must not be treated as authorization.

What to include in a report

Provide enough technical information to help reproduce, understand and remediate the issue.

  • the affected StudyLabPro system or software
  • a clear vulnerability description
  • minimal and reproducible steps
  • the potential impact
  • supporting evidence that does not expose unnecessary personal or sensitive data
  • suggested remediation, if available
  • a preferred contact method for follow-up

Research expectations

Use only the minimum testing necessary to confirm a suspected vulnerability and avoid harm to people, data and services.

Stop testing and report promptly if you encounter personal data, confidential information or evidence of active compromise. Do not download, retain, alter or disclose data beyond the minimum evidence needed for the report.

Prohibited testing

This policy does not authorize destructive, disruptive or privacy-invasive activity.

  • denial-of-service or resource-exhaustion testing
  • destruction, alteration or exfiltration of data
  • malware deployment or persistence
  • credential theft, brute force or credential stuffing
  • phishing, social engineering or impersonation
  • unauthorized lateral movement
  • physical attacks
  • testing third-party systems without their explicit authorization

Disclosure principles

Give StudyLabPro a reasonable opportunity to investigate and remediate a reported issue before public disclosure. Coordinate disclosure timing where appropriate and protect sensitive details while a fix is being prepared.

If StudyLabPro research identifies a vulnerability in third-party software or infrastructure during lawful and authorized work, we aim to notify the responsible maintainer or organization with sufficient reproduction and remediation information. Public disclosure may be delayed to allow reasonable time for a fix.

Good-faith research

StudyLabPro recognizes and appreciates good-faith security research that stays within the stated scope, minimizes harm and follows this policy.

This statement does not authorize activity prohibited by law or by a third party, does not create immunity from legal consequences, and does not promise a reward or bounty.

Contact

Send reports to security@studylabpro.com with the affected system in the subject line. A PGP key is not currently published, so do not assume an encryption endpoint exists.

Researching the systems that come next.