Transparent Security

Responsible disclosure

At YuJa Inc., we understand that safeguarding educational, corporate, and public-sector data requires constant vigilance and continuous evolution. We are trusted by leading academic and government institutions worldwide to power their digital infrastructures, and we consider the protection of user privacy and system integrity to be our highest priority.

We firmly believe that the external security research community plays a vital, symbiotic role in maintaining the highest standards of global cybersecurity. This Vulnerability Disclosure Policy outlines our collaborative approach to working with security researchers. We welcome and highly value good-faith reports of potential security vulnerabilities in our platforms, APIs, and mobile applications.

If you discover a potential security vulnerability, please report it to security@yuja.com using the format provided below. We appreciate your efforts in helping us keep our platforms secure.

Safe harbor authorization

When conducting vulnerability research according to this policy, we consider this research to be authorized. We will work with you to understand and resolve the issue quickly, and YuJa will not initiate or recommend legal action related to your research.

Should legal action be initiated by a third-party against you for activities that were conducted in accordance with this policy, we will make this authorization known. However, please understand that this policy does not and cannot legally bind any third-parties, nor does it authorize testing on third-party infrastructure. You remain responsible for complying with all applicable laws.

Guidelines for good-faith security research

To maintain Safe Harbor protection, researchers must adhere strictly to the following rules of engagement during all testing phases:

Do no harm and maintain availability

Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and the destruction or corruption of data. Denial of Service (DoS) testing is strictly prohibited under all circumstances.

Protect confidentiality and PII

Under no circumstances should you access, download, modify, or delete data belonging to YuJa’s clients, students, or institutional partners. If you inadvertently encounter Personally Identifiable Information (PII), personal health information, or data governed by FERPA, GDPR, or HIPAA during your testing, you must immediately halt testing, securely purge any local copies of the data, and report the vulnerability to our team at once.

Limit exploitation

Only utilize exploits to the extent strictly necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command-line access, pivot to other internal systems, or maintain a backdoor.

Coordinated vulnerability disclosure (CVD)

You must not publicly disclose the vulnerability or share details with any third-party without explicit, written permission from the YuJa Inc. security team. You must provide us with a reasonable, agreed-upon timeframe to develop, test, and deploy a remediation patch before any public release of information.

Scope definitions and boundaries

To ensure testing remains productive and safe, YuJa explicitly defines the boundaries of authorized research.

Core web domains (in-scope)

*.yuja.com encompassing all main web properties, authenticated dashboards, and web applications.

Product platforms (in-scope)

YuJa Panorama, YuJa Lumina, YuJa EqualGround, YuJa Verity, and YuJa CivicGuard platforms.

Mobile applications (in-scope)

YuJa enterprise mobile applications deployed on iOS and Android operating systems.

Integration endpoints (in-scope)

YuJa public APIs and Learning Tools Interoperability (LTI 1.3 Advantage) integration endpoints hosted by YuJa.

Volumetric attacks (out-of-scope)

Any form of Denial of Service (DoS), Distributed Denial of Service (DDoS), or resource exhaustion attacks.

Social engineering (out-of-scope)

Phishing, vishing, or smishing attacks directed at YuJa employees, contractors, or client institutions.

Physical security (out-of-scope)

Physical penetration testing of YuJa corporate offices, employee devices, or third-party data centers.

Third-party infrastructure (out-of-scope)

Testing of third-party vendors, cloud providers (e.g., AWS, Google Cloud), or external platform APIs (e.g., Zoom, YouTube) that integrate with YuJa, unless the vulnerability resides strictly within YuJa’s proprietary code implementation.

Reporting mechanics, requirements, and service level agreements

If you believe you have discovered a vulnerability that falls within the scope of this policy, please report it immediately to our dedicated security routing team by emailing the appropriate contact channel.

Contact method: security@yuja.com

Report requirements

To assist our engineering team in verifying and resolving the issue rapidly, please ensure your submission includes:

  • A comprehensive description of the vulnerability, including its location (URL or specific endpoint) and the potential impact on system confidentiality, integrity, or availability.
  • Detailed, step-by-step technical instructions required to reliably reproduce the vulnerability.
  • Proof-of-Concept (PoC) code, scripts, or non-destructive screenshots. (Note: Scripts or exploit code should be embedded into non-executable file types or standard archives such as zip or gzip).
  • The exact date and time the vulnerability was initially discovered.

Our commitment and timelines (SLAs)

Upon receipt of a vulnerability report, we commit to the following operational timelines:

  • Acknowledgment: We will formally acknowledge receipt of your report within three (3) business days.
  • Triage and Assessment: We will provide an initial technical assessment and triage status within ten (10) business days.
  • Remediation: We will keep you reasonably informed of the remediation progress and aim to resolve critical vulnerabilities as swiftly as possible, prioritizing issues based on severity and potential impact.

Join the 1,000+ Organizations Deploying High-Impact Solutions

A collection of logos representing various organizations and institutions that use YuJa’s platform.