Legal
Vulnerability Disclosure Policy
Last updated: August 11, 2026
Clearpoint Business Group, LLC ("Company," "we," "us," or "our") is committed to protecting the security of the CTSO Central platform and the data our customers entrust to us. We value the work of security researchers acting in good faith, and we welcome reports of potential security vulnerabilities in our systems. This Vulnerability Disclosure Policy ("Policy") describes what systems and types of research are covered, how to report vulnerabilities to us, and what you can expect from us in return.
1. Our Commitment
If you make a good faith effort to comply with this Policy during your security research, we will:
- Work with you to understand and validate your report;
- Acknowledge receipt of your report in a timely manner;
- Strive to keep you informed about the progress of remediation;
- Not pursue or support legal action against you for research conducted in accordance with this Policy; and
- Recognize your contribution, if you are the first to report a unique vulnerability and your report triggers a code or configuration change, if you would like to be credited.
2. Scope
This Policy applies only to the following systems and services:
- www.ctsocentral.com
- api.ctsocentral.com
- app.ctsocentral.com
- etesting.ctsocentral.com
- evaluations.ctsocentral.com
- updates.ctsocentral.com
- transcripts.ctsocentral.com
- help.ctsocentral.com
This Policy also applies to the following client applications published by the Company:
- Transmit, the CTSO Central desktop application for scoring and score upload (Windows and macOS), including its distribution and auto-update channel served from updates.ctsocentral.com; and
- STS Secure Browser, the CTSO Central secure testing desktop application (Windows, macOS, ChromeOS, and Linux), including its distribution and auto-update channel served from updates.ctsocentral.com.
Any system or service not expressly listed above is excluded from the scope of this Policy and is not authorized for testing.
3. Out of Scope
The following are expressly out of scope for this Policy. Testing of these systems is not authorized under any circumstances:
- Any subdomain of ctsocentral.com not expressly listed in Section 2;
- Development, staging, and preview environments;
- Any domain or subdomain ending in clearpointbusiness.com;
- Clearpoint Business Group corporate systems and tools, including but not limited to corporate email, internal business applications, employee workstations, collaboration and productivity tools, and network infrastructure;
- Systems, services, or infrastructure operated by third parties, including our vendors and sub-processors (please report vulnerabilities in third-party services directly to the responsible vendor under their own disclosure policy);
- Third-party software, hardware, and firmware bundled with or used by our applications — how our applications integrate with them is in scope; the components themselves are not (report those to their vendor);
- The hosting infrastructure behind our update and download services, including updates.ctsocentral.com — how our applications fetch, verify, and apply updates is in scope; the infrastructure beneath is not; and
- Physical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing.
In addition, the following categories of findings are generally considered out of scope and should not be reported unless you can demonstrate a concrete, exploitable security impact:
- Network denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data;
- Reports from automated scanners without a validated proof of concept;
- Missing security headers, cookie flags, or best-practice configurations without a demonstrated exploit;
- Clickjacking on pages with no sensitive actions;
- Email configuration issues (SPF, DKIM, DMARC) without a demonstrated exploit;
- Software version disclosure or banner identification without a working exploit;
- Rate limiting on non-authentication endpoints;
- Bypassing or evading web application firewall, bot management, or rate-based blocking controls, unless doing so enables a further exploitable vulnerability; and
- Brute-force, credential-stuffing, password-spraying, or account-lockout testing against production accounts.
4. Rules of Engagement
To remain within the authorization granted by this Policy, you must:
- Only test systems expressly listed in Section 2;
- Notify us as soon as possible after you discover a real or potential security issue;
- Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data;
- Only use exploits to the extent necessary to confirm a vulnerability's presence. Do not use an exploit to compromise or exfiltrate data, establish persistent access, or pivot to other systems;
- Use only accounts you own or accounts for which you have the explicit permission of the account holder;
- Never test against live or scheduled exam sessions, proctoring streams, or active competition events. Test secure testing, proctoring, judging, and scoring functionality only with accounts and exam sessions you created yourself;
- If a vulnerability provides unintended access to data: limit the amount of data you access to the minimum required to demonstrate the vulnerability; stop testing immediately and submit a report if you encounter any user data such as personally identifiable information (PII), student education records, financial information, or proprietary information; and do not save, store, transfer, or otherwise retain any such data;
- Not perform denial of service testing, automated high-volume scanning that degrades service, spam, or social engineering (including phishing) against our employees, customers, or users; and
- Not publicly disclose vulnerability details before remediation is complete, as described in Section 7.
The CTSO Central platform serves students, including children under 13, and processes education records and live proctoring audio and video. Exercise particular care during testing. If you encounter any student data, proctoring audio or video, or live exam content, stop immediately and submit a report.
5. How to Report a Vulnerability
Report suspected vulnerabilities by email to security@ctsocentral.com.
To help us triage and remediate quickly, please include:
- A description of the vulnerability and its potential impact;
- The affected hostname, URL, endpoint, or component;
- Step-by-step instructions to reproduce the issue, including any relevant request/response data, screenshots, or proof-of-concept code;
- The date and time of your testing; and
- Your name or handle and contact information, if you wish to receive updates or credit (anonymous reports are accepted).
Please report vulnerabilities in English where possible. Do not include unnecessary personal data, student records, or credentials in your report.
6. What You Can Expect From Us
When you submit a report in accordance with this Policy, we will use commercially reasonable efforts to:
- Acknowledge receipt of your report within three (3) business days;
- Provide an initial assessment of the report's validity and severity within ten (10) business days;
- Keep you reasonably informed of our remediation progress for confirmed vulnerabilities; and
- Notify you when the vulnerability has been remediated.
We prioritize remediation based on the severity of the vulnerability and the risk it presents to our customers and their data.
7. Coordinated Disclosure
We ask that you keep vulnerability details confidential until we have remediated the issue and have authorized disclosure. We aim to remediate confirmed vulnerabilities within ninety (90) days of triage. If you wish to publicly disclose a remediated vulnerability, please coordinate the timing and content of the disclosure with us in advance. We are happy to work with researchers on coordinated publication, including providing credit where desired.
8. Safe Harbor
We consider security research conducted in good faith and in accordance with this Policy to be:
- Authorized with respect to any applicable anti-hacking laws, including the Computer Fraud and Abuse Act (CFAA) (18 U.S.C. § 1030) and analogous state laws, and we will not initiate or support legal action against you for accidental, good faith violations of this Policy;
- Authorized with respect to any applicable anti-circumvention laws, including the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls; and
- Exempted from restrictions in our Terms of Service and Acceptable Use Policy that would otherwise prohibit such research, solely for the limited purpose of the research conducted under this Policy.
If a third party initiates legal action against you for activities conducted in accordance with this Policy, we will make it known that your actions were conducted in compliance with this Policy. If at any time you are uncertain whether your research is consistent with this Policy, please contact security@ctsocentral.com before proceeding.
This safe harbor applies only to legal claims under the control of the Company and does not bind independent third parties. Research that exceeds the scope or violates the rules of this Policy is not authorized.
9. Rewards
This Policy is not a bug bounty program, and we do not currently offer monetary rewards for vulnerability reports. With your permission, we are glad to publicly acknowledge researchers whose reports lead to a confirmed fix.
10. Questions
Questions about this Policy, or reports you are unsure how to classify, may be directed to security@ctsocentral.com. We may revise this Policy from time to time; the version published at this page is the authoritative, current version.