Scholera Developers

Incident Reporting & Response

How to report a suspected security incident and what to expect from Scholera’s response process.

Report a suspected incident promptly.

Include what you observed, affected systems or accounts, relevant timestamps, and safe contact details. Do not include passwords, tokens, exploit code that affects active users, or unnecessary student information.

Do not submit passwords, API keys, authentication tokens, exploit code affecting active users, or unnecessary student information.

Protected by reCAPTCHA. Google Privacy Policy and Terms apply.

Triage

Scholera records the report, confirms receipt, assesses credibility and potential impact, and assigns an incident owner. Immediate containment actions take priority when users or data may be at risk.

Containment and investigation

The response team limits further exposure, preserves relevant evidence, determines affected systems and information, and coordinates with institutional contacts when appropriate.

Eradication and recovery

Scholera removes the cause, validates remediations, restores normal operation carefully, and monitors for recurrence. Recovery decisions consider both service availability and the integrity of learning data.

Communication

Updates are provided according to the nature of the event, contractual commitments, applicable requirements, and available facts. We avoid speculation while an investigation is active.

Post-incident review

After stabilization, Scholera documents the timeline, contributing conditions, actions taken, and follow-up improvements. Relevant controls, procedures, and training are updated.