Security · Responsible disclosure
Security Policy
Effective 26 July 2026 · Reviewed annually.
Reporting a vulnerability
If you have discovered a security issue affecting ibs-edu.org or any of its subdomains, please email us directly:
- Primary: security@ibs-edu.org
- Backup: ict@ibs-edu.org
Please provide enough detail for us to reproduce the issue: steps taken, request bodies where applicable, and any screenshots. Attaching PoC code (harmless, non-destructive) is welcome.
Scope
In scope:
- The public site
ibs-edu.organdwww.ibs-edu.org - The SchoolOS portal at
/schoolos - The Cloudflare Functions under
/ai/*,/portal/*, and/portal-files/* - The Templates & Downloads pages
Out of scope:
- Third-party integrations (Cloudflare, Microsoft 365, Anthropic Claude) — please report those to the vendor directly
- Denial-of-service, brute-force, or spam attacks
- Findings that require phishing school staff or physical access to school premises
Our commitments
- We will acknowledge your report within 3 working days.
- We will keep you updated on progress until the issue is resolved.
- We will not pursue legal action for good-faith research that follows this policy.
- We will publicly credit you in the site changelog if you wish (and if the fix ships).
What we ask
- Give us reasonable time to investigate and remediate before any public disclosure.
- Do not access, modify, or delete data belonging to others.
- Do not degrade the service or attempt to bypass rate limits at scale.
- Respect the privacy of students, staff, parents, and prospective families.
No monetary rewards
I.B.S Educational Complex is a Christian basic school in Asankrangwa, Ghana. We are a small institution and cannot offer a paid bug bounty. What we can offer is our sincere thanks, a public credit in the release notes, and a good-faith response.
Canonical location of this document: https://ibs-edu.org/security-policy.html
Machine-readable version: /.well-known/security.txt