Contact: mailto:support@redeemos.com Preferred-Languages: en Canonical: https://www.redeemos.com/.well-known/security.txt Policy: https://www.redeemos.com/security-policy Expires: 2027-06-29T00:00:00.000Z # Security Reporting Policy # # RedeemOS takes the security of our platform and our customers' data # seriously. If you discover a security vulnerability, we encourage # responsible disclosure. # # HOW TO REPORT # Email: support@redeemos.com # Subject line: [SECURITY] Brief description of vulnerability # # Please include: # - Description of the vulnerability # - Steps to reproduce # - Potential impact assessment # - Your contact information (optional) # # WHAT WE COMMIT TO # - Acknowledge your report within 48 business hours # - Investigate and validate the reported issue # - Work to resolve confirmed vulnerabilities promptly # - Keep you informed of our progress # - Credit you in our acknowledgements (if desired) # # SCOPE # In-scope: www.redeemos.com, API endpoints, authentication systems # Out-of-scope: Third-party services, social engineering attacks # # SUPPORTED VERSIONS # We support and patch only the current production version. # # SECURITY OVERVIEW # - Multi-tenant isolation: each school has a dedicated database # - Role-based access control with granular permissions # - SSL/TLS encryption for all data in transit # - Automatic daily encrypted cloud backups # - Activity audit logs for all user actions # - Secure authentication via Better Auth # - Rate limiting on authentication endpoints # - Content Security Policy headers enforced # - HSTS with 2-year max-age and preload # # We do NOT offer bug bounties at this time. # Thank you for helping keep RedeemOS and its schools safe.