How security researchers and users should report suspected security vulnerabilities affecting Student Money Mentors.
Last updated: August 21, 2026
Student Money Mentors takes the security of its platform and the protection of user information seriously. This Security & Responsible Disclosure Policy explains how security researchers and users should report suspected security vulnerabilities affecting Student Money Mentors.
Student Money Mentors encourages responsible security research that helps identify and resolve vulnerabilities without exposing users, financial information, credentials, or platform systems to unnecessary risk.
This Policy supplements the Student Money Mentors Terms of Service, Privacy Policy, Safety & Reporting Policy, and other applicable policies.
If you believe you have identified a security vulnerability in Student Money Mentors, report it privately through the security or contact channel designated by Student Money Mentors.
Security testing should be limited to activity reasonably necessary to demonstrate the suspected vulnerability.
Researchers should:
Users and researchers must not:
Student Money Mentors may involve financial education, financial information, calculations, recommendations, or other money-related content.
Researchers must take particular care when a vulnerability exposes:
If such information becomes accessible during testing, access only the minimum information necessary to establish the vulnerability.
Do not download, retain, publish, sell, or redistribute exposed financial information.
Student Money Mentors may provide AI-assisted financial education or analysis features.
Security vulnerabilities may include:
Researchers should demonstrate these issues using the minimum information necessary.
Do not use an AI vulnerability to obtain another user’s financial information.
Users must not exploit vulnerabilities to:
A security vulnerability should be reported, not exploited for financial gain.
Researchers may report vulnerabilities involving:
Do not permanently take control of another person’s account.
If temporary access is reasonably necessary to demonstrate an authentication vulnerability, stop once the issue is established and report it privately.
If you discover that Student Money Mentors unintentionally exposes:
do not redistribute the information.
Report the exposure privately and explain what type of information may have been accessible.
Student Money Mentors may use AI systems to provide educational, analytical, or other assistance.
Researchers should report vulnerabilities that allow AI systems to:
AI output should not be treated as permission to access information or systems that the researcher is not otherwise authorized to access.
Student Money Mentors may rely on third-party providers for services such as:
Do not use a Student Money Mentors vulnerability to attack or compromise a third-party provider.
Where appropriate, Student Money Mentors may coordinate with the affected provider.
Researchers should not publicly disclose a vulnerability before Student Money Mentors has had a reasonable opportunity to investigate and address it.
Premature disclosure may expose users to:
Student Money Mentors may request reasonable additional time when necessary to protect users and complete remediation.
A useful report should include, when available:
Do not include unnecessary passwords, authentication codes, financial credentials, or unrelated sensitive information.
Student Money Mentors may consider:
Issues involving financial loss, account takeover, authentication bypass, or significant financial-data exposure may receive elevated priority.
Student Money Mentors appreciates good-faith security research intended to improve the platform.
Reporting a vulnerability does not authorize activity that would otherwise violate the Terms of Service or applicable law.
Nothing in this Policy creates a promise of compensation, legal immunity, or a particular response unless Student Money Mentors separately agrees to those terms.
Student Money Mentors uses reasonable security measures, but no online service can guarantee that every vulnerability will be prevented or discovered.
Users and researchers should report suspected vulnerabilities rather than exploiting them or attempting to investigate them independently.
Student Money Mentors may preserve or disclose information relating to security incidents when reasonably necessary for:
Such handling will be subject to applicable law and the Student Money Mentors Privacy Policy.
Student Money Mentors may update this Policy as:
The current version will be made available through Student Money Mentors.
If you believe you have discovered a security vulnerability, report it privately through the designated Student Money Mentors security or contact channel.
Do not publicly disclose the vulnerability before Student Money Mentors has had a reasonable opportunity to investigate.
Find it → Minimize access → Stop testing → Report privately → Preserve only necessary evidence → Allow reasonable time for remediation.
Do not exploit a vulnerability to obtain money, financial information, credentials, private data, or unauthorized access.