Security
Report a problem privately
If you think you have found a security or privacy weakness, give us enough detail to reproduce it without including secrets or accessing anyone else's information.
What to send
- The affected page or feature and the date you noticed the problem.
- Clear reproduction steps and the impact you believe is possible.
- Small, redacted screenshots or logs when they help explain the issue.
Trust and privacy documents
Read the privacy policy for what we collect and how long we keep it. Organisations reviewing a processing arrangement can download the current DPA. Review it with your own legal or privacy lead; downloading it does not mean your organisation has signed it. For general questions, use the contact route.
Keep the test safe
Do not disrupt the service, use social engineering, run broad automated attacks, download data that is not yours or keep testing after you have shown the issue. Never send passwords, session tokens or unredacted learner data by email.
Claims we do not make
This page is a reporting route, not a claim of certification, a bug-bounty programme or permission to test other people's accounts.