CourseKit uses defence in depth across tenant isolation, authentication, provider credentials, private assets, application changes, audit evidence, and operations. Controls are reviewed against the risks of a multi-tenant learning and commerce platform.
Send a clear report to security@coursekit.cloud. Include the affected URL or component, steps to reproduce, impact, and any safe proof. Do not include unnecessary personal data or secrets.
When testing, please:
We will acknowledge a good-faith report, investigate it, keep you reasonably informed, and not pursue legal action for research that follows this policy and applicable law. This is not permission to test third-party providers such as Stripe, Webflow, Zoom, Bunny.net, Cloudflare, Resend, or PostHog.
If you believe an active account compromise, data exposure, or service incident is occurring, email security@coursekit.cloud with “URGENT INCIDENT” in the subject. For harmful customer content or misuse, use abuse@coursekit.cloud.