Report
Email reproduction steps, impact, and affected endpoints.
Security program
Security researchers and customers help us protect growth-stage teams. Report vulnerabilities responsibly — we investigate quickly, remediate with care, and coordinate public disclosure.
How it works
Email reproduction steps, impact, and affected endpoints.
We validate severity, scope, and duplicate status.
Engineering fixes ship with coordinated communication.
Status updates until resolved; credit offered when appropriate.
In scope
ask.degree production and keyteller.com staging hosts we operate.
Growth Readiness Assessment apps and APIs — classic and Option 2 flows.
Authentication, authorization, session, and assessment data exposure flaws.
Misconfigurations that could expose customer or participant information.
Out of scope
Submit a report
The more reproducible your submission, the faster we can validate and fix. Send everything to our dedicated security inbox.
Security inbox
security@ask.degree
Include in your message
Response expectations
Within 2 business days
We confirm receipt and assign triage.
During investigation
We share severity assessment and remediation progress.
Before public disclosure
We align on timing so customers stay protected.
After fix
Credit in advisories when you request it and policy allows.
We appreciate good-faith research that helps us improve. Follow these guardrails so we can focus on fixing issues — not investigating harm.
AskDegree does not run a paid bug bounty today. We prioritize fixes that protect customers and assessment participants.
Send reproduction details to our security team. For non-security inquiries, use the contact page.
See also Privacy Policy