DocentBase Trust & Responsible Disclosure
Responsible Vulnerability Disclosure
& Bug Bounty Program.
We believe security is a collaborative effort. We invite independent researchers and ethical hackers to discover and disclose vulnerabilities under our Safe Harbor policy.
< 4h Triage SLA for Criticals
Hall of Fame & Monetary Bounties
Safe Harbor Guaranteed
The following production domains are eligible for bounty assessment and Hall of Fame credit:
| Target Asset | Type | Eligible Vulnerabilities |
|---|---|---|
| *.docentbase.com | Web Application | Authentication bypass, IDOR, SQLi, Remote Code Execution, Privilege Escalation |
| admin.docentbase.com | Teacher & Admin Cockpit | Multi-tenant data isolation, RBAC role escalation, unauthorized student data export |
| student.docentbase.com | Student & Parent Portal | Join code brute-forcing, fee verification bypass, unauthorized scorecard disclosure |
Interactive Vulnerability Report Builder
Auto-Generated PoC PreviewMarkdown
# [SECURITY REPORT] Vulnerability Report Summary **Target Asset:** admin.docentbase.com **Category:** IDOR **Severity:** P2 - High **Reporter:** Security Researcher (researcher@example.com) **Hall of Fame Credit:** Yes (Handle: Anonymous) **Date:** 2026-08-17 --- ### 1. Vulnerability Description & Steps to Reproduce 1. Step one to reproduce... 2. Step two... ### 2. Impact & Suggested Remediation Describe unauthorized data access, privilege escalation, or session hijacking impact. --- *Submitted via DocentBase Responsible Disclosure Portal (docentbase.com/security).*
Encrypted PGP Key: 0xDOCENT88
SECURITY CONTRIBUTIONS
Security Researcher Hall of Fame
Tariqul Hasan
@tariq_sec
P1 Auth Token Triage
Aug 2026
Saifur Rahman
@saifur_bounty
P2 IDOR Fee Ledger
Jul 2026
Anonymous Researcher
N/A
P3 Rate Limiting PoC
Jun 2026
