Security Policy

Last updated: 29 September 2026

1. Our Commitment

Keeping the data of our students and instructors safe is a priority for Edquis. If you believe you have found a security vulnerability in the platform, we want to hear from you and will work with you to resolve it.

2. Reporting a Vulnerability

Please email info@suftnet.com with the subject line "Security report" and include:

  • A description of the vulnerability and its potential impact.
  • The URL, page, or API endpoint affected.
  • Step-by-step instructions to reproduce the issue.
  • Any proof-of-concept code, screenshots, or logs that help us understand it.

3. What to Expect

  • We aim to acknowledge your report within 5 business days.
  • We will investigate, keep you informed of our progress, and let you know when the issue is fixed.
  • With your permission, we are happy to credit you once the issue has been resolved.

4. Guidelines for Researchers

We will not pursue action against anyone who reports a vulnerability in good faith and follows these guidelines:

  • Only test against accounts you own or have explicit permission to use.
  • Do not access, modify, or delete data belonging to other users.
  • Do not degrade the service — no denial-of-service, spam, or automated high-volume testing.
  • Do not use social engineering, phishing, or physical attacks against our staff or users.
  • Give us reasonable time to fix the issue before disclosing it publicly.

5. Out of Scope

  • Vulnerabilities in third-party services we use, such as Stripe or Cloudinary — please report these to the provider directly.
  • Reports from automated scanners without a demonstrated impact.
  • Missing security headers or best practices that do not lead to an exploitable issue.

6. Contact

For anything else related to security, contact us at info@suftnet.com. Questions about how we handle personal data are covered in our Privacy Policy.