Security Policy
Effective date: August 12, 2026
Responsible Disclosure
We take the security of Paxaver and the data entrusted to us by schools, parents, and students seriously. If you believe you have discovered a security vulnerability in our platform, we encourage you to report it to us responsibly.
Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate it. We commit to acknowledging receipt of your report within 2 business days and to providing a substantive update within 10 business days.
How to Report
Email your report to security@paxaver.com. To help us reproduce and address the issue quickly, please include:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce the issue, including any relevant URLs, parameters, or payloads.
- The date and time you discovered the issue.
- Your name and contact information (optional, but helpful for follow-up).
A machine-readable description of our security contact is available at /.well-known/security.txt (RFC 9116).
Scope
This policy applies to the Paxaver platform, including:
- paxaver.com, paxaver.ca, and paxaver.dev web applications
- Our public API endpoints
- Our MCP (Model Context Protocol) server
The following are out of scope: vulnerabilities in third-party services we use (e.g., Stripe, Cloudflare) that have their own security programs, and issues that require physical access to our infrastructure or social engineering of our staff.
Safe Harbor
We will not pursue legal action against individuals who report security vulnerabilities in good faith and in accordance with this policy, provided they do not access or modify data other than their own, do not degrade the availability of our services, and do not publicly disclose the vulnerability before we have completed remediation.
Security Measures
Paxaver is hosted on the Cloudflare global network. We employ the following security measures:
- Encryption in transit (TLS) for all connections
- Strict Content-Security-Policy, HSTS, and other security headers
- Role-based access control with least-privilege defaults
- Two-factor authentication for administrative accounts
- Regular security reviews and dependency auditing
- Payment card data processed by Stripe (never stored on our servers)
Acknowledgments
We are grateful to the security researchers who help us keep Paxaver safe. With your permission, we will acknowledge your contribution here after the vulnerability has been remediated.
Trademarks
Paxaver and the Paxaver logo are trademarks of Smartoire Inc. Cloudflare is a trademark of Cloudflare, Inc. Stripe and Stripe Connect are trademarks of Stripe, Inc. All other product names, logos, and brands are property of their respective owners. Use of these names does not imply endorsement.