SECURITY

Responsible Disclosure

Last updated: June 2026

At StackCracker, we take security seriously. We welcome reports from security researchers and the community. If you discover a vulnerability, please report it responsibly and we will work with you to address it promptly.

1. Scope

stackcracker.com and all subdomains
StackCracker API endpoints
Authentication and session management
Student lab environments (report escapes from designated lab scope)
Certificate verification system
User data exposure or unauthorized access

2. Out of Scope

Denial of Service (DoS/DDoS) attacks
Social engineering of StackCracker staff
Physical security attacks
Vulnerabilities in third-party services we use (report to them directly)
Issues requiring unlikely user interaction
Rate limiting on non-sensitive endpoints
Missing security headers without demonstrated impact

3. How to Report

Send your report to security@stackcracker.com with the following information:

Description of the vulnerability
Steps to reproduce
Potential impact assessment
Any proof-of-concept code or screenshots
Your suggested remediation (optional)

4. What to Expect

Acknowledgement within 48 hours of your report
Regular updates on our progress
Notification when the vulnerability is fixed
Credit in our Hall of Fame (with your permission)
We aim to resolve critical issues within 7 days

5. Safe Harbor

We consider security research conducted in good faith to be authorised. This means we will not pursue legal action against researchers who:

Report vulnerabilities promptly and do not exploit them
Avoid accessing or modifying other users' data
Do not disrupt our services or degrade user experience
Keep vulnerability details confidential until we have fixed the issue
Act in good faith and within the scope defined above

6. Hall of Fame

We publicly recognise researchers who help us improve our security. If you report a valid vulnerability and consent to being named, we will add you to our Hall of Fame.

7. No Bug Bounty

StackCracker does not currently offer monetary rewards for vulnerability reports. We are a small platform and cannot offer financial compensation at this time. We do offer public recognition and our sincere gratitude for responsible disclosure.

8. Contact

For security reports, contact us at security@stackcracker.com. For general enquiries, use the contact information on our Privacy Policy page.

Found a vulnerability?
Report it responsibly and help us keep StackCracker secure.
security@stackcracker.com