Responsible Disclosure Policy

Last updated: August 24, 2026

We build software that holds student data for school districts, so we would much rather hear about a security flaw from you than read about it later. If you have found a vulnerability in Manage1to1, this page tells you how to report it and what we commit to in return.

Security research conducted in good faith under this policy is authorized. We will not pursue or recommend legal action against anyone who makes a good-faith effort to follow it.

Report a vulnerability

Email security@manage1to1.com. If you do not receive an acknowledgement within five business days, follow up at support@manage1to1.com and we will chase it down. This policy is also published in machine-readable form as a security.txt file.

Reporting

What to send us.

A good report is one we can reproduce. Please include as much of the following as you can:

  • A description of the vulnerability and why you believe it matters
  • The affected URL, endpoint, or component
  • Step-by-step instructions to reproduce it, including any accounts or roles required
  • A proof of concept, along with any screenshots, request captures, or logs
  • Your assessment of the potential impact
  • How you would like to be credited, or whether you prefer to stay anonymous

Please send reports in English, and please report each distinct issue separately so we can track and fix them independently.

Our commitments

What you get from us in return.

  • We acknowledge quickly

    We confirm receipt of your report within five business days, so you know a human has it and it did not land in a void.

  • We keep you updated

    We provide an initial assessment within ten business days and keep you informed as we work toward a fix.

  • We will not pursue legal action

    If you make a good-faith effort to follow this policy, we will not pursue or recommend legal action against you, and we will make it known that your actions were authorized if a third party raises the question.

  • We credit you

    We are glad to publicly credit you for a valid report once the issue is resolved, or to keep your report anonymous. Your call, not ours.

We do not currently operate a paid bug bounty program, so we cannot offer monetary rewards. We would rather say that plainly than let you spend a weekend on our application expecting a payout.

Ground rules

What we ask of you.

Our safe-harbor commitment applies as long as you follow these. They exist mostly to protect the students whose records live in this system.

  • Give us a reasonable time to remediate before disclosing publicly. Our standard coordination window is 90 days from acknowledgement, and we are happy to discuss the timeline with you if a finding warrants a different one.
  • Use only accounts you own or have explicit permission to test. Do not access, modify, or retain another district’s data, another user’s data, or any student record.
  • If you encounter student data or other personal information, stop, do not save a copy, and tell us immediately in your report.
  • Limit testing to the minimum necessary to demonstrate the issue. Do not pivot deeper into our systems once you have a proof of concept.
  • Do not degrade service for districts in production, and do not run destructive tests such as deleting or corrupting records.
  • Comply with applicable law, including student-privacy law. Nothing in this policy authorizes activity that would violate it.

Scope

What is in scope.

In scope

  • The Manage1to1 web application and its administrative interfaces
  • The Manage1to1 API and its authentication mechanisms
  • The Self-Service Portal and the Parent Portal
  • manage1to1.com and its public subdomains that we operate

Out of scope

  • Third-party services we integrate with but do not control, including MDM vendors, student information systems, identity providers, and payment processors. Report those to the vendor that operates them.
  • Findings that require physical access to a district device, a compromised endpoint, or a privileged account you already control
  • Social engineering of our staff, our customers, or their students, and any form of phishing
  • Denial of service, volumetric or stress testing, and anything that degrades availability for districts in production
  • Missing security headers, cookie flags, or TLS configuration findings with no demonstrated exploit path
  • Automated scanner output submitted without a working proof of concept

If you are not sure whether something is in scope, ask us at security@manage1to1.com before you test it. We would rather answer a question than receive an apology.

This policy covers security vulnerabilities. If you are a district reporting a suspected breach of your own data, or you need our incident-response commitments, see our Data Security and Privacy Plan, which includes our 72-hour breach notification commitment. Our broader posture is documented on the Security and Compliance page, and this policy fulfills goal five of our CISA Secure by Design Pledge progress report.