Skip to main content
Trust: Vulnerability disclosure

Report a security issue

If you think you've found a security problem, we want to hear about it.

Last updated
2026-09-25

How to report

Email [email protected] with “Security report” in the subject. Tell us what you found, the steps to reproduce it, and what an attacker could do with it. Please don’t post it publicly until we have fixed it.

What we promise

  • We reply within 3 business days to say we have your report.
  • We keep you posted while we fix it and tell you when it is fixed.
  • We credit you, if you want, once the fix is out.
  • We will not pursue legal action against research done in good faith under this policy.

We don’t run a paid bug bounty.

In scope

www.questivaconsultants.com and its API, the eBook reader, and our LTI 1.3 integration.

Please don’t

  • Access, change or delete anyone else’s data. Use accounts you own.
  • Run denial-of-service or load tests, or send spam.
  • Try phishing or social engineering on our staff, authors or customers.
  • Test the payment form of Authorize.net, which is theirs, not ours.

Reviewing us for a school?

Our security overview covers hosting, encryption, sign-in and data retention.