Scholera Developers
Incident Reporting & Response
How to report a suspected security incident and what to expect from Scholera’s response process.
Report a suspected incident promptly.
Include what you observed, affected systems or accounts, relevant timestamps, and safe contact details. Do not include passwords, tokens, exploit code that affects active users, or unnecessary student information.
Triage
Scholera records the report, confirms receipt, assesses credibility and potential impact, and assigns an incident owner. Immediate containment actions take priority when users or data may be at risk.
Containment and investigation
The response team limits further exposure, preserves relevant evidence, determines affected systems and information, and coordinates with institutional contacts when appropriate.
Eradication and recovery
Scholera removes the cause, validates remediations, restores normal operation carefully, and monitors for recurrence. Recovery decisions consider both service availability and the integrity of learning data.
Communication
Updates are provided according to the nature of the event, contractual commitments, applicable requirements, and available facts. We avoid speculation while an investigation is active.
Post-incident review
After stabilization, Scholera documents the timeline, contributing conditions, actions taken, and follow-up improvements. Relevant controls, procedures, and training are updated.
