Student Money Mentors Security & Responsible Disclosure

How security researchers and users should report suspected security vulnerabilities affecting Student Money Mentors.

Last updated: August 21, 2026

Student Money Mentors takes the security of its platform and the protection of user information seriously. This Security & Responsible Disclosure Policy explains how security researchers and users should report suspected security vulnerabilities affecting Student Money Mentors.

Student Money Mentors encourages responsible security research that helps identify and resolve vulnerabilities without exposing users, financial information, credentials, or platform systems to unnecessary risk.

This Policy supplements the Student Money Mentors Terms of Service, Privacy Policy, Safety & Reporting Policy, and other applicable policies.

1.Responsible Security Research

If you believe you have identified a security vulnerability in Student Money Mentors, report it privately through the security or contact channel designated by Student Money Mentors.

Security testing should be limited to activity reasonably necessary to demonstrate the suspected vulnerability.

Researchers should:

  • Report vulnerabilities privately.
  • Provide enough information for investigation and reproduction.
  • Avoid accessing unnecessary personal or financial information.
  • Avoid modifying or deleting data.
  • Avoid disrupting the platform.
  • Stop testing when the vulnerability has been reasonably demonstrated.
  • Give Student Money Mentors a reasonable opportunity to investigate and address the issue before public disclosure.

2.Prohibited Security Testing

Users and researchers must not:

  • Access another user’s account without authorization.
  • Obtain passwords, authentication codes, session credentials, or recovery information.
  • Access another user’s financial information unnecessarily.
  • Access private user information beyond what is reasonably necessary to demonstrate a vulnerability.
  • Modify or delete another user’s information.
  • Take over accounts.
  • Circumvent access controls.
  • Deploy malware.
  • Conduct phishing or credential theft.
  • Conduct denial-of-service or disruptive attacks.
  • Spam users or systems.
  • Attack third-party systems through Student Money Mentors.
  • Use vulnerabilities to obtain money or other financial benefit.
  • Publicly expose sensitive vulnerability information before reasonable coordination.

3.Financial Information Requires Special Care

Student Money Mentors may involve financial education, financial information, calculations, recommendations, or other money-related content.

Researchers must take particular care when a vulnerability exposes:

  • Bank-account information.
  • Payment information.
  • Financial-account information.
  • Transaction information.
  • Income information.
  • Student financial information.
  • Budget information.
  • Financial goals.
  • Tax-related information.
  • Authentication credentials.
  • Other sensitive financial data.

If such information becomes accessible during testing, access only the minimum information necessary to establish the vulnerability.

Do not download, retain, publish, sell, or redistribute exposed financial information.

4.Financial and AI Features

Student Money Mentors may provide AI-assisted financial education or analysis features.

Security vulnerabilities may include:

  • Cross-user financial-data exposure.
  • Unauthorized access to uploaded documents.
  • Prompt-injection vulnerabilities.
  • Unauthorized disclosure of AI inputs or outputs.
  • Cross-account data leakage.
  • Circumvention of financial-safety controls.
  • Unauthorized modification of financial information.
  • Manipulation of calculations or recommendations.
  • Exposure of internal prompts or protected system information.

Researchers should demonstrate these issues using the minimum information necessary.

Do not use an AI vulnerability to obtain another user’s financial information.

5.Financial Abuse Through Security Vulnerabilities

Users must not exploit vulnerabilities to:

  • Steal money.
  • Redirect payments.
  • Manipulate transactions.
  • Obtain financial credentials.
  • Create fraudulent financial records.
  • Alter balances or calculations.
  • Manipulate financial recommendations for another user.
  • Impersonate Student Money Mentors.
  • Facilitate scams or financial fraud.

A security vulnerability should be reported, not exploited for financial gain.

6.Authentication and Account Security

Researchers may report vulnerabilities involving:

  • Login systems.
  • Authentication.
  • Password recovery.
  • Session management.
  • Account authorization.
  • Account takeover.
  • Access-control failures.
  • Financial-account protections.

Do not permanently take control of another person’s account.

If temporary access is reasonably necessary to demonstrate an authentication vulnerability, stop once the issue is established and report it privately.

7.Data Exposure

If you discover that Student Money Mentors unintentionally exposes:

  • Personal information.
  • Financial information.
  • Account information.
  • Payment information.
  • Uploaded documents.
  • AI inputs or outputs.
  • Authentication credentials.
  • Student information.
  • Private user data.
  • Internal system information.

do not redistribute the information.

Report the exposure privately and explain what type of information may have been accessible.

8.AI Security

Student Money Mentors may use AI systems to provide educational, analytical, or other assistance.

Researchers should report vulnerabilities that allow AI systems to:

  • Reveal private user information.
  • Cross account boundaries.
  • Expose protected prompts or system information.
  • Bypass access controls.
  • Produce unauthorized financial actions.
  • Manipulate another user’s data.
  • Circumvent safety controls.

AI output should not be treated as permission to access information or systems that the researcher is not otherwise authorized to access.

9.Third-Party Services

Student Money Mentors may rely on third-party providers for services such as:

  • Hosting.
  • Authentication.
  • Payments.
  • AI processing.
  • Analytics.
  • Communications.
  • Security.
  • Other infrastructure.

Do not use a Student Money Mentors vulnerability to attack or compromise a third-party provider.

Where appropriate, Student Money Mentors may coordinate with the affected provider.

10.Public Disclosure

Researchers should not publicly disclose a vulnerability before Student Money Mentors has had a reasonable opportunity to investigate and address it.

Premature disclosure may expose users to:

  • Account compromise.
  • Financial fraud.
  • Credential theft.
  • Data exposure.
  • Unauthorized transactions.
  • Other security risks.

Student Money Mentors may request reasonable additional time when necessary to protect users and complete remediation.

11.What to Include in a Report

A useful report should include, when available:

  • Description of the vulnerability.
  • Affected feature.
  • Steps reasonably necessary to reproduce it.
  • Expected behavior.
  • Actual behavior.
  • Potential impact.
  • Screenshots or technical evidence.
  • Test-account information, if applicable.
  • Whether personal or financial information was exposed.

Do not include unnecessary passwords, authentication codes, financial credentials, or unrelated sensitive information.

12.Vulnerability Severity

Student Money Mentors may consider:

  • Number of users affected.
  • Type and sensitivity of information exposed.
  • Financial impact.
  • Ability to access another user’s account.
  • Ability to bypass authorization.
  • Ability to modify financial information.
  • Ability to initiate or redirect transactions.
  • Likelihood of exploitation.
  • Whether exploitation requires user interaction.

Issues involving financial loss, account takeover, authentication bypass, or significant financial-data exposure may receive elevated priority.

13.Good-Faith Research

Student Money Mentors appreciates good-faith security research intended to improve the platform.

Reporting a vulnerability does not authorize activity that would otherwise violate the Terms of Service or applicable law.

Nothing in this Policy creates a promise of compensation, legal immunity, or a particular response unless Student Money Mentors separately agrees to those terms.

14.No Guarantee of Security

Student Money Mentors uses reasonable security measures, but no online service can guarantee that every vulnerability will be prevented or discovered.

Users and researchers should report suspected vulnerabilities rather than exploiting them or attempting to investigate them independently.

15.Legal Requests and Preservation

Student Money Mentors may preserve or disclose information relating to security incidents when reasonably necessary for:

  • Security investigations.
  • Fraud prevention.
  • Protection of users.
  • Legal compliance.
  • Valid legal process.
  • Emergency circumstances.

Such handling will be subject to applicable law and the Student Money Mentors Privacy Policy.

16.Changes to This Policy

Student Money Mentors may update this Policy as:

  • Security practices develop.
  • Platform features change.
  • Financial risks evolve.
  • New threats emerge.
  • Legal requirements change.
  • Responsible-disclosure procedures mature.

The current version will be made available through Student Money Mentors.

17.Reporting a Vulnerability

If you believe you have discovered a security vulnerability, report it privately through the designated Student Money Mentors security or contact channel.

Do not publicly disclose the vulnerability before Student Money Mentors has had a reasonable opportunity to investigate.

Core Security Rule

Find it → Minimize access → Stop testing → Report privately → Preserve only necessary evidence → Allow reasonable time for remediation.

Do not exploit a vulnerability to obtain money, financial information, credentials, private data, or unauthorized access.

If you have questions about this policy, contact us at about@studentmoneymentors.com.

This document is provided for informational purposes and may be updated from time to time. See the "Last updated" date and "Recent updates" above for the most recent revisions.