CodeAI Vulnerability Disclosure Policy
CodeAI welcomes feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or another security issue in one of our assets, we want to hear from you. This policy explains how to report security issues, what we expect from researchers, and what you can expect from us.

CodeAI's paid bug bounty program is temporarily paused, but our vulnerability disclosure program remains open. Researchers may continue good-faith security testing only on the in-scope targets listed in our Bugcrowd engagement brief. That page remains the authoritative source for targets and testing rules during the pause.
Please do not submit new reports through Bugcrowd while the paid program is paused. Send new security reports directly to security@code.org. Reports received during the pause are not eligible for monetary rewards. Reports submitted through Bugcrowd before the pause took effect will continue to be reviewed under the program terms that applied when they were submitted.
We do not yet have a date for resuming the paid program. We will update this page and the Bugcrowd engagement if and when bounty submissions reopen.
In-scope systems
This policy applies to digital assets owned, operated, or maintained by CodeAI. However, active vulnerability testing may only be performed on targets identified as in scope in the CodeAI Bugcrowd engagement brief. If an asset is not listed as in scope, you may report a suspected vulnerability, but you may not actively test that asset without prior written authorization.
Out-of-scope systems
This policy does not apply to assets or equipment not owned by CodeAI. Vulnerabilities discovered or suspected in systems owned by another organization should be reported to the appropriate owner, vendor, or authority.
Our commitments
When you work with us according to this policy, you can expect us to:
Respond to your report and work with you to understand and validate it;
Strive to keep you informed about the progress of our review;
Work to remediate confirmed vulnerabilities in a timely manner, within our operational constraints; and
Extend Safe Harbor, as explained below, for vulnerability research covered by this policy.
Our expectations
When participating in our vulnerability disclosure program in good faith, we ask that you:
Follow this policy and other relevant agreements. Where this policy conflicts with CodeAI's Terms of Service, this policy controls solely as to the conduct of security testing it authorizes, and only to the extent of the conflict. This policy does not modify, waive, or supersede any other CodeAI terms, including our Privacy Policy, student data privacy commitments, or agreements with schools and districts;
Report discovered vulnerabilities to us promptly;
Avoid violating anyone's privacy, disrupting systems, destroying data, or harming the user experience;
Use only the official reporting channel identified below to discuss vulnerability information with us;
Give us a reasonable amount of time, at least 180 days from the initial report, to resolve the issue before public disclosure;
Test only the in-scope targets listed in the Bugcrowd engagement brief and follow the testing rules published there. Do not test production environments where testing could cause disruption or data loss;
If a vulnerability provides unintended access to data, access only the minimum needed to demonstrate a proof of concept. Stop testing and report the issue immediately if you encounter user data, including personally identifiable information, user project data, or proprietary information;
Interact only with test accounts you own or accounts whose owner has given you explicit permission; and
Do not engage in extortion.
Official reporting channel
While the paid bug bounty program is paused, report security issues by email to security@code.org. Do not submit new reports through Bugcrowd during the pause.
Please include as much of the following information as possible:
The affected target and URL;
A description of the vulnerability and its potential impact;
Clear reproduction steps and a minimal proof of concept;
The date and environment in which you tested; and
Any relevant screenshots, logs, or request and response details.
The more relevant detail you provide, the easier it will be for us to triage and address the issue. Reports received while the paid program is paused are not eligible for monetary rewards.
Safe Harbor
When you conduct vulnerability research according to this policy, we will consider that research to be:
Authorized to the extent it might implicate applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy;
Authorized concerning relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls;
Exempt from restrictions in our Terms of Service that would interfere with conducting security research, and we waive those restrictions on a limited basis; and
Lawful, helpful to the overall security of the Internet, and conducted in good faith.
You are expected to comply with all applicable laws. If a third party initiates legal action against you and you have complied with this policy, we will take steps to make it known that we believe your actions were conducted in compliance with this policy.
If you are uncertain whether your research is consistent with this policy, email security@code.org before going any further.
Safe Harbor applies only to legal claims under CodeAI's control. This policy does not bind independent third parties.
Additional resources
Privacy Policy

Your privacy is important to us. We want to be transparent about the personal data we collect, why we collect it, and what we do with it.
Cookie Policy

Learn how CodeAI uses cookies to enhance site performance and personalize your experience. Plus, manage your cookie settings.
Terms of Service

Review our Terms of Service for using CodeAI’s platform, tools, and curriculum, including legal terms and user responsibilities.