Customer Assurance
Draft
public
Security Contact
Version 0.9
Last updated August 31, 2026
Draft review copy.
This document has not been approved for publication. Its claims, effective date, and contact details remain subject to owner review.
## Report a Security Issue To report a suspected vulnerability affecting MHLE, email **contact details withheld pending approval** with the subject: **[Security Report] — brief description** Please review the [Responsible Disclosure Policy](/trust/security-disclosure) before testing or submitting a report. ## Helpful Information to Include - The affected MHLE URL, endpoint, application area, or integration. - A concise description of the issue and its potential impact. - Reproduction steps using an account and data you are authorized to access. - Screenshots, timestamps, request identifiers, or sanitized logs. - Whether the issue appears to expose student, customer, authentication, payment, or other sensitive information. - A safe way to contact you for follow-up. Do **not** email passwords, session tokens, API keys, private encryption keys, complete student records, payment-card data, or bulk personal information. State that you possess sensitive evidence and wait for secure-transfer instructions. ## Security Emergencies If you believe there is active exploitation, unauthorized access, or imminent risk to users, put **URGENT** in the subject line. Do not continue testing after confirming the issue, and do not access or retain data beyond what is necessary to report it. MHLE's published Responsible Disclosure Policy describes acknowledgement and remediation targets. Actual timelines depend on severity, reproducibility, affected vendors, and the need to protect users while a fix is developed. ## Privacy and Data Rights Use **contact details withheld pending approval** for: - Access, correction, export, or deletion questions. - Parent or guardian privacy requests. - Questions about AI processing or training use of content. - Privacy Policy or Student Data Transparency Notice questions. For institution-managed education records, users should also contact the institution's privacy or FERPA official. ## Institutional Assurance Use **contact details withheld pending approval** for: - Security questionnaires and HECVAT requests. - DPA, subprocessor, retention, or audit-evidence questions. - Current SOC 2 readiness or independent-testing status. - Requests for non-public security documentation under appropriate confidentiality terms. Use **contact details withheld pending approval** for contract execution and legal notices that are not handled by the [DMCA intake form](/trust/dmca). ## What Not to Send Through Public Contact Channels Public email should not be used for: - Production credentials or database exports. - Unredacted student records. - Complete vulnerability scan results containing exploitable details. - Health, financial, government-identifier, or other highly sensitive datasets. - Copyright takedown notices; use the Trust Center DMCA form. MHLE may request identity or authority verification before disclosing account, security, or institutional information. ## Review Note This directory remains **Draft** until every inbox is tested, assigned an owner and backup, and approved for publication. The Trust Center currently contains mixed `mhle.com` and `mhle.app` addresses; those addresses must be reconciled before this document is marked Current.