Vulnerability Disclosure

Last updated: 10 November 2025
We take security seriously. If you believe you’ve found a vulnerability affecting lawlitbiztutoring.com or our services, we’d like to know so we can fix it quickly.

How to report
Email info@lawlitbiztutoring.com) with:

  • A clear description of the issue and where you found it
  • Steps to reproduce (screenshots or proof-of-concept welcome)
  • Your contact details for follow-up

We aim to acknowledge your report within 3 business days and keep you informed of progress. We appreciate responsible, private disclosure and won’t take legal action for good-faith research aligned with this policy.

Scope

  • lawlitbiztutoring.com and subpages
  • Our booking/contact forms and publicly accessible endpoints

Out of scope

  • Social engineering, spam, or phishing against our staff or clients
  • Denial of service (DoS/DDoS), rate-limit or brute-force tests
  • Physical security, third-party platforms outside our control
  • Disclosure of non-exploitative best-practice issues without security impact (e.g., click-path UX)

Research rules

  • Don’t access, modify, or exfiltrate data that isn’t yours
  • Don’t degrade service for users
  • Don’t view more data than necessary to demonstrate the issue
  • Use test accounts where possible and comply with laws

Safe harbour
If you follow this policy and act in good faith, we won’t pursue legal action. This safe harbour doesn’t apply to actions that are illegal or harmful, or to third-party systems outside our control.

Recognition
With your permission, we can list your name on our Security Acknowledgements page once the issue is resolved. We don’t offer bounties at this time.

Data protection
Please avoid including personal information in your report. If you encounter personal data, stop testing and report immediately.