SECURITY AND RESPONSIBLE DISCLOSURE POLICY
Effective date: 18 June 2026
AcademyLauncher takes reasonable measures to protect the confidentiality, integrity and availability of its systems. No internet service is completely secure. This Policy describes user responsibilities and how security researchers may report suspected vulnerabilities.
ACCOUNT SECURITY
Users must keep credentials confidential, use unique strong passwords, enable available multi-factor authentication, maintain secure devices and promptly remove access for former staff. Account owners are responsible for permissions granted to administrators, instructors, contractors and integrations. Notify us promptly of suspected unauthorized access.
OUR PRACTICES
Depending on the service and risk, safeguards may include access controls, authentication, encryption in transit, logging, backups, monitoring, vulnerability management, provider reviews, incident response and personnel confidentiality. We continually evaluate safeguards but do not warrant that every attack or loss can be prevented.
CUSTOMER RESPONSIBILITIES
Creators must configure access appropriately, protect API keys and payment credentials, keep integrations current, avoid collecting unnecessary sensitive information and maintain independent copies of essential business content. Do not share passwords through tickets or email.
RESPONSIBLE SECURITY RESEARCH
We welcome good-faith reports that avoid harm. Researchers must:
Use only accounts and data they own or are authorized to test;
Avoid privacy violations, social engineering, phishing, denial of service, malware, spam and physical attacks;
Avoid accessing, changing, downloading or deleting other users' data;
Stop testing and notify us if sensitive data is encountered;
Use the minimum activity necessary to demonstrate the issue; and
Allow reasonable time for remediation before public disclosure.
Testing third-party services, Creator custom domains or infrastructure not controlled by AcademyLauncher is outside scope unless expressly authorized.
REPORTING
Send reports to security@academylauncher.com. Include the affected URL or feature, steps to reproduce, impact, supporting evidence and a safe contact method. Do not include real user data beyond what is strictly necessary. Encrypt sensitive reports where a secure method has been arranged.
OUR RESPONSE
We may acknowledge, triage, request details, reproduce and remediate a valid report. Response and remediation times depend on severity and complexity. Submission does not create a right to payment. Any bounty or recognition must be agreed in writing; we do not currently promise a bounty through this Policy.
SAFE-HARBOR INTENT
Where research follows this Policy in good faith, AcademyLauncher does not intend to pursue claims solely for the authorized research. This statement does not bind third parties or excuse unlawful conduct and is not permission to violate privacy or access data.
INCIDENT NOTICES
If a confirmed incident triggers a legal or contractual notification duty, AcademyLauncher will provide notices as required. Users should keep account contact information current.
EMERGENCIES
For an active compromise, include “URGENT SECURITY” in the subject. Support and general account issues should go to support@academylauncher.com.