Security & Vulnerability Disclosure

Last updated: 5 June 2026

StudioLoom is a learning platform used by schools, teachers, and students — some of them children. We take the security of that data seriously, and we welcome reports from security researchers acting in good faith. This page explains how to report a vulnerability, what you can expect from us, and the rules we ask you to follow.

A machine-readable version of our contact details is published at /.well-known/security.txt per RFC 9116.

How to report

Email security@loominary.org — StudioLoom is operated by Loominary, and this is our monitored security inbox. Please report privately; do not open a public GitHub issue, pull request, or social-media post before we’ve had a chance to fix the issue.

To help us triage quickly, include where you can:

  • The affected URL, endpoint, or feature.
  • Clear steps to reproduce, or a short proof-of-concept.
  • The impact you believe it has (what an attacker could do).
  • Any accounts, IPs, or timestamps you used, so we can find it in our logs.

What you can expect from us

  • Acknowledgement within 72 hours of your report reaching us.
  • An initial severity assessment within 7 days, with a sense of next steps.
  • Regular updates through to remediation, and notice when the fix ships.
  • Credit for your finding, with your permission — see Recognition below.

Scope

In scope:

  • studioloom.org and its subdomains.
  • The StudioLoom web application and its API.

Out of scope — please do not test these:

  • Denial-of-service, volumetric, or load/stress testing.
  • Social engineering or phishing of our staff, teachers, or students.
  • Physical attacks against offices, hardware, or people.
  • Third-party services we build on (e.g. Supabase, Vercel, Anthropic, Google/Microsoft sign-in). Report those to the provider; we’re happy to help coordinate.
  • Reports from automated scanners with no demonstrated, exploitable impact, or best-practice suggestions (e.g. a missing header) without a concrete attack.

Protecting student data

StudioLoom holds the work and personal data of minors. If, while researching, you come across student records or any personal data, stop, do not access or download more than the minimum needed to demonstrate the issue, do not retain it, and tell us immediately. Demonstrating that data is reachable is enough — you never need to exfiltrate it to make your point.

Safe harbour

If you make a good-faith effort to follow this policy, we will treat your research as authorised. We will not pursue or support legal action against you for accidental, good-faith violations, and we’ll work with you to understand and resolve the issue quickly. This authorisation is ours to give for systems we operate; it does not bind the third parties listed as out of scope.

What we ask of you

  • Only interact with accounts you own or have explicit permission to use — create test accounts where you can.
  • Don’t access, modify, or delete other people’s data, and take special care around student records.
  • Don’t run tests that degrade, disrupt, or destroy our service or data.
  • Give us a reasonable opportunity to remediate before any public disclosure.

Recognition

We’re grateful to the researchers who help keep StudioLoom safe. Once reports start landing, we’ll acknowledge here — with your permission — the people who have responsibly disclosed valid issues. We don’t currently run a paid bug-bounty program.