Security Contact
Report a Security Issue
To report a suspected vulnerability affecting MHLE, email contact details withheld pending approval with the subject:
[Security Report] — brief description
Please review the Responsible Disclosure Policy before testing or submitting a report.
Helpful Information to Include
- The affected MHLE URL, endpoint, application area, or integration.
- A concise description of the issue and its potential impact.
- Reproduction steps using an account and data you are authorized to access.
- Screenshots, timestamps, request identifiers, or sanitized logs.
- Whether the issue appears to expose student, customer, authentication, payment, or other sensitive information.
- A safe way to contact you for follow-up.
Do not email passwords, session tokens, API keys, private encryption keys, complete student records, payment-card data, or bulk personal information. State that you possess sensitive evidence and wait for secure-transfer instructions.
Security Emergencies
If you believe there is active exploitation, unauthorized access, or imminent risk to users, put URGENT in the subject line. Do not continue testing after confirming the issue, and do not access or retain data beyond what is necessary to report it.
MHLE's published Responsible Disclosure Policy describes acknowledgement and remediation targets. Actual timelines depend on severity, reproducibility, affected vendors, and the need to protect users while a fix is developed.
Privacy and Data Rights
Use contact details withheld pending approval for:
- Access, correction, export, or deletion questions.
- Parent or guardian privacy requests.
- Questions about AI processing or training use of content.
- Privacy Policy or Student Data Transparency Notice questions.
For institution-managed education records, users should also contact the institution's privacy or FERPA official.
Institutional Assurance
Use contact details withheld pending approval for:
- Security questionnaires and HECVAT requests.
- DPA, subprocessor, retention, or audit-evidence questions.
- Current SOC 2 readiness or independent-testing status.
- Requests for non-public security documentation under appropriate confidentiality terms.
Use contact details withheld pending approval for contract execution and legal notices that are not handled by the DMCA intake form.
What Not to Send Through Public Contact Channels
Public email should not be used for:
- Production credentials or database exports.
- Unredacted student records.
- Complete vulnerability scan results containing exploitable details.
- Health, financial, government-identifier, or other highly sensitive datasets.
- Copyright takedown notices; use the Trust Center DMCA form.
MHLE may request identity or authority verification before disclosing account, security, or institutional information.
Review Note
This directory remains Draft until every inbox is tested, assigned an owner and backup,
and approved for publication. The Trust Center currently contains mixed mhle.com and
mhle.app addresses; those addresses must be reconciled before this document is marked
Current.