Report a security weakness without putting anyone at risk.
This page gives safe current reporting guidance and a candidate process for future accounts. It is not a bug-bounty offer or an approved legal safe harbour.
A qualified security and legal review must settle testing permission, response handling, disclosure timing and any safe-harbour wording. No payment, reward or immunity is promised. This text is not an approved account, subscription, privacy, cancellation, acceptable-use, copyright, complaints, safety or security policy, is not legal advice and is not accepted anywhere in the current service. Parent accounts, paid pupil profiles, checkout, real uploads and pupil-facing AI remain closed. See the legal and trust status for the documents that apply to today's public preview.
Candidate version candidate-0.1 · prepared 7 September 2026 · no effective date
Report safely
The security address is delivery-tested, but monitored human handling is not yet verified, so the public email route remains closed. Do not send it personal information or secrets. A minimal written report can be posted to ECOMMERCE ONLINE LTD, 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX, marked “Security”. Postal contact is not an emergency route.
For immediate danger to a person, call 999. For a privacy complaint rather than a technical weakness, use the privacy notice. For a child-safety concern, use safeguarding help.
What to include
- the affected public address or feature;
- a concise description of the weakness and expected security impact;
- safe, minimal reproduction steps using only an account and data you control;
- the browser, device or request conditions if relevant; and
- a safe way to reply.
Replace tokens, credentials, email addresses, names and pupil material with redacted or synthetic examples. Do not send a database copy, password, API key, full session cookie, payment-card data or an image of real schoolwork through ordinary email.
Do not
- access, change, download or retain another person's account or information;
- test with a real child, real pupil profile or real schoolwork;
- use phishing, credential stuffing, malware, denial of service, spam or physical attacks;
- defeat rate or cost limits at scale, disrupt availability or degrade another visitor's experience;
- contact a pupil, school, provider worker or unrelated third party;
- demand money, threaten disclosure or publish exploit details before a safe resolution; or
- assume this draft grants legal permission or immunity for conduct that would otherwise be unlawful.
Proposed handling
- Restrict the report to authorised security responders and acknowledge it using a reference.
- Preserve the minimum evidence, remove exposed secrets and protect any unexpectedly received personal information.
- Triage impact without asking the reporter to retrieve more real data.
- Contain, correct and verify the weakness, including provider notification where required.
- Explain the outcome and coordinate any public disclosure only after affected people and systems are protected.
No response-time promise is published because a named monitored owner and continuity cover have not been verified. The final page must publish only a target the company can staff and must connect to a tested incident, breach-assessment and notification process.
Scope today
The current scope is the public content, manual Reset and fictional scan demonstration at www.how2revise.com. Accounts, paid profiles, checkout, real uploads and pupil-facing AI are closed, so no researcher should try to activate or simulate them in production. Provider dashboards, staff accounts, other ECOMMERCE ONLINE LTD products and third-party websites are outside this page.
No bounty or public-disclosure promise
How2Revise has not established a paid vulnerability programme. This candidate promises no reward, reimbursement, legal immunity, credit or publication timetable. A final coordinated- disclosure policy may recognise good-faith help only after qualified review and operational ownership are complete.
Machine-readable route
The site also publishes /.well-known/security.txt. It exposes a mailbox only when branded mailboxes are enabled; otherwise it points to this safe public route. The record is not evidence that a staffed response target or bounty exists.
Approval still required
Independent security review, named incident ownership, protected evidence transfer, breach response, provider escalation, record retention and legal safe-harbour wording remain unresolved. This candidate has no effective date.