Security Policy
Last updated: 29 September 2026
1. Our Commitment
Keeping the data of our students and instructors safe is a priority for Edquis. If you believe you have found a security vulnerability in the platform, we want to hear from you and will work with you to resolve it.
2. Reporting a Vulnerability
Please email info@suftnet.com with the subject line "Security report" and include:
- A description of the vulnerability and its potential impact.
- The URL, page, or API endpoint affected.
- Step-by-step instructions to reproduce the issue.
- Any proof-of-concept code, screenshots, or logs that help us understand it.
3. What to Expect
- We aim to acknowledge your report within 5 business days.
- We will investigate, keep you informed of our progress, and let you know when the issue is fixed.
- With your permission, we are happy to credit you once the issue has been resolved.
4. Guidelines for Researchers
We will not pursue action against anyone who reports a vulnerability in good faith and follows these guidelines:
- Only test against accounts you own or have explicit permission to use.
- Do not access, modify, or delete data belonging to other users.
- Do not degrade the service — no denial-of-service, spam, or automated high-volume testing.
- Do not use social engineering, phishing, or physical attacks against our staff or users.
- Give us reasonable time to fix the issue before disclosing it publicly.
5. Out of Scope
- Vulnerabilities in third-party services we use, such as Stripe or Cloudinary — please report these to the provider directly.
- Reports from automated scanners without a demonstrated impact.
- Missing security headers or best practices that do not lead to an exploitable issue.
6. Contact
For anything else related to security, contact us at info@suftnet.com. Questions about how we handle personal data are covered in our Privacy Policy.