TierSphere
Vulnerability disclosure
TierSphere holds records about students, including minors. If you have found a way to reach data you should not be able to reach, we want to hear from you.
Good-faith research
We will not pursue or support legal action against anyone who reports a vulnerability to us in good faith and within the guidance on this page.
How to report
Email help@tiersphere.com with enough detail for us to reproduce the issue: the URL or endpoint, the steps you took, and what you were able to see or do.
In scope
The TierSphere web application and its public pages.
Please do not
- Access, download, modify or retain anyone else's data. If you reach data that is not yours, stop and tell us what you reached — we do not need a copy.
- Test against real customer data, or against accounts you do not own.
- Run denial-of-service, load or stress tests.
- Use social engineering, phishing, or physical access attempts against our people or our customers.
- Disclose the issue publicly before we have had a chance to fix it.
What to expect
A person will read your report and reply. We do not publish a response-time commitment, because we would rather not make a promise we have not yet built the process to keep. We will tell you what we find and when it is fixed.
This is a disclosure path, not a bug bounty. We do not offer payment for reports.