Security at TutorLab
Found something we should fix?
Tell the founder directly. A clear, private report helps us protect tutors, parents and students without putting anyone else's data at risk.
Responsible disclosure
TutorLab does not currently offer a bug bounty or financial reward. Useful reports may be credited publicly only with the reporter's permission.
In scope
- — TutorLab-owned production pages and APIs on tutorlab.uk.
- — Accounts, records and payment test data you own or have explicit permission to use.
- — The minimum steps needed to demonstrate the issue safely, followed by an immediate stop.
Out of scope
- — Accessing, changing, retaining or sharing another person's data.
- — Denial of service, load testing, credential stuffing, phishing or social engineering.
- — Real payments, persistence, bulk enumeration, automated scanning or testing third-party services.
- — Public disclosure before TutorLab has had a reasonable opportunity to investigate and respond.
What happens next
The form returns a case reference immediately. Harry aims to acknowledge genuine security reports within two business days, with urgent active harm triaged sooner. This is a response target, not a guaranteed remediation deadline.
Send a private report
One issue per report. For an ordinary product bug, use the support page.
Good-faith reports are welcome, but this page does not authorise testing prohibited by TutorLab's Acceptable Use Policy and cannot bind third parties or public authorities. If the form itself is unsafe or unavailable, email harry@trytutorlab.uk.