Customer Assurance Draft public

Security Contact

Version 0.9 Last updated August 24, 2026
Draft review copy. This document has not been approved for publication. Its claims, effective date, and contact details remain subject to owner review.

Report a Security Issue

To report a suspected vulnerability affecting MHLE, email contact details withheld pending approval with the subject:

[Security Report] — brief description

Please review the Responsible Disclosure Policy before testing or submitting a report.

Helpful Information to Include

  • The affected MHLE URL, endpoint, application area, or integration.
  • A concise description of the issue and its potential impact.
  • Reproduction steps using an account and data you are authorized to access.
  • Screenshots, timestamps, request identifiers, or sanitized logs.
  • Whether the issue appears to expose student, customer, authentication, payment, or other sensitive information.
  • A safe way to contact you for follow-up.

Do not email passwords, session tokens, API keys, private encryption keys, complete student records, payment-card data, or bulk personal information. State that you possess sensitive evidence and wait for secure-transfer instructions.

Security Emergencies

If you believe there is active exploitation, unauthorized access, or imminent risk to users, put URGENT in the subject line. Do not continue testing after confirming the issue, and do not access or retain data beyond what is necessary to report it.

MHLE's published Responsible Disclosure Policy describes acknowledgement and remediation targets. Actual timelines depend on severity, reproducibility, affected vendors, and the need to protect users while a fix is developed.

Privacy and Data Rights

Use contact details withheld pending approval for:

  • Access, correction, export, or deletion questions.
  • Parent or guardian privacy requests.
  • Questions about AI processing or training use of content.
  • Privacy Policy or Student Data Transparency Notice questions.

For institution-managed education records, users should also contact the institution's privacy or FERPA official.

Institutional Assurance

Use contact details withheld pending approval for:

  • Security questionnaires and HECVAT requests.
  • DPA, subprocessor, retention, or audit-evidence questions.
  • Current SOC 2 readiness or independent-testing status.
  • Requests for non-public security documentation under appropriate confidentiality terms.

Use contact details withheld pending approval for contract execution and legal notices that are not handled by the DMCA intake form.

What Not to Send Through Public Contact Channels

Public email should not be used for:

  • Production credentials or database exports.
  • Unredacted student records.
  • Complete vulnerability scan results containing exploitable details.
  • Health, financial, government-identifier, or other highly sensitive datasets.
  • Copyright takedown notices; use the Trust Center DMCA form.

MHLE may request identity or authority verification before disclosing account, security, or institutional information.

Review Note

This directory remains Draft until every inbox is tested, assigned an owner and backup, and approved for publication. The Trust Center currently contains mixed mhle.com and mhle.app addresses; those addresses must be reconciled before this document is marked Current.

Back to Trust Center