Skip to main content

TierSphere

Vulnerability disclosure

TierSphere holds records about students, including minors. If you have found a way to reach data you should not be able to reach, we want to hear from you.

Good-faith research

We will not pursue or support legal action against anyone who reports a vulnerability to us in good faith and within the guidance on this page.

How to report

Email help@tiersphere.com with enough detail for us to reproduce the issue: the URL or endpoint, the steps you took, and what you were able to see or do.

In scope

The TierSphere web application and its public pages.

Please do not

  • Access, download, modify or retain anyone else's data. If you reach data that is not yours, stop and tell us what you reached — we do not need a copy.
  • Test against real customer data, or against accounts you do not own.
  • Run denial-of-service, load or stress tests.
  • Use social engineering, phishing, or physical access attempts against our people or our customers.
  • Disclose the issue publicly before we have had a chance to fix it.

What to expect

A person will read your report and reply. We do not publish a response-time commitment, because we would rather not make a promise we have not yet built the process to keep. We will tell you what we find and when it is fixed.

This is a disclosure path, not a bug bounty. We do not offer payment for reports.