Legal

Security & vulnerability disclosure

Effective 2026-07-30 · Version 2026-07-30 · Operator: Better Brain Lab LLC

Security approach

CourseKit uses defence in depth across tenant isolation, authentication, provider credentials, private assets, application changes, audit evidence, and operations. Controls are reviewed against the risks of a multi-tenant learning and commerce platform.

IdentityRequired staff MFA, role-based access, tenant-aware policies, secure password reset, and revocable sessions.
DataPrivate storage, signed downloads, encrypted integration credentials, scoped access, and verified deletion workflows.
ApplicationAutomated security, tenancy, integration, and live-flow tests; reviewed changes; secret-safe configuration.
OperationsHealth checks, alerts, backup and restore controls, provider visibility, audit trails, and documented incident response.

Report a vulnerability

Send a clear report to security@coursekit.cloud. Include the affected URL or component, steps to reproduce, impact, and any safe proof. Do not include unnecessary personal data or secrets.

When testing, please:

  • use only accounts, schools, sites, and data you own or have explicit permission to test;
  • avoid denial of service, automated high-volume scanning, spam, social engineering, and physical attacks;
  • do not access, modify, retain, or disclose another person’s data;
  • stop and report immediately if you encounter customer data or a secret; and
  • allow reasonable time for investigation and remediation before public disclosure.

We will acknowledge a good-faith report, investigate it, keep you reasonably informed, and not pursue legal action for research that follows this policy and applicable law. This is not permission to test third-party providers such as Stripe, Webflow, Zoom, Bunny.net, Cloudflare, Resend, or PostHog.

Security incidents

If you believe an active account compromise, data exposure, or service incident is occurring, email security@coursekit.cloud with “URGENT INCIDENT” in the subject. For harmful customer content or misuse, use abuse@coursekit.cloud.