Curious Maths Policies
Security Policy
This policy explains how Curious Maths protects accounts and how security issues can be reported responsibly.
Last updated: June 14, 2026
Plain English Summary
This summary is for quick understanding. The detailed sections below explain the full policy.
- We use account protection, access checks, secure server routes, monitoring, and security controls.
- Sensitive actions are checked server-side before access is granted.
- Please report suspected vulnerabilities privately by email.
- Do not test in a way that harms learners, data, infrastructure, or service availability.
Account And Access Security
Curious Maths uses modern account authentication, secure session handling, and server-side authorization checks. Protected areas verify account status, role, access level, and payment status before allowing sensitive actions.
Operational Controls
The app uses controls such as rate limiting, request validation, payment verification, private file access, audit logging, and secure HTTP headers. Production credentials and secrets should be stored only in secure deployment environments.
Responsible Disclosure
If you believe you found a vulnerability, email us with the affected URL, steps to reproduce, potential impact, and any safe proof of concept. Please avoid accessing another user's data, disrupting service, or publicly disclosing the issue before we have had a reasonable chance to investigate.
Out Of Scope
Social engineering, spam, denial-of-service, physical attacks, automated scanning that degrades service, and attacks against third-party providers outside our control are not authorized.
Contact
Report security concerns to admin@curiousmaths.com.