Responsible disclosure

Found a security concern? Tell us without putting data at risk.

We welcome clear, good-faith reports about the public PrivateStride website. Use synthetic data, limit testing, and stop before any action could affect another person or system.

Report channel

Send the finding to a partner.

Email partners@privatestride.com with the subject “SECURITY DISCLOSURE.” Do not attach client files, taxpayer information, credentials, private keys, or data taken from another person.

If ordinary email would expose sensitive proof, send a brief description first and ask us to arrange an appropriate exchange method.

What to include

Enough detail to reproduce it safely.

  • The affected public URL or feature.
  • A concise description of the potential impact.
  • Exact, minimal steps using a test account or synthetic data.
  • Relevant browser, device, request, or response details.
  • Your preferred contact information and disclosure plans.

Testing boundary

Minimize access. Minimize impact.

This page supports responsible reporting. It is not permission to test client deployments, third-party platforms, employee accounts, or systems that PrivateStride does not own.

Good-faith approach

Use the least invasive method.

  • Test only what is necessary to confirm the concern.
  • Use fabricated examples rather than real personal data.
  • Stop immediately if you encounter nonpublic information.
  • Preserve confidentiality while we review the report.
  • Give us a reasonable opportunity to assess and respond.

Out of bounds

Do not create a second problem.

  • No real client data, tax data, or third-party personal data.
  • No phishing, social engineering, or credential guessing.
  • No denial of service, high-volume automation, or disruption.
  • No malware, persistence, data destruction, or exfiltration.
  • No physical testing or testing of vendors without permission.
  • No public disclosure that would increase risk before review.

After a report

We assess the finding and keep the conversation practical.

01

Triage

We review the reported scope, reproduce it when possible, and may ask for safe clarification.

02

Response

We prioritize work based on credible impact, exposure, and the safeguards available while a permanent fix is assessed.

03

Coordination

When appropriate, we coordinate status and responsible disclosure with the reporter. We do not currently offer a public bug-bounty program.

We appreciate research intended to improve security. This process does not authorize unlawful activity or conduct outside the limits above, and it does not waive rights of PrivateStride, its clients, or third parties.

Related information

Security starts with clear boundaries.

Read the site’s privacy notice , its website terms , and the overview of PrivateStride security and compliance .