[ POLICY ]

DISCLOSURE POLICY

Overview

The NTL AP Vulnerability Disclosure Program (VDP) provides a structured, official channel for security researchers to responsibly report vulnerabilities affecting approved digital assets operated by Next Tech Lab AP.

Safe Harbor

If you identify a security issue in good faith and comply with these guidelines, NTL AP will not pursue legal action against you. We ask that you:

  • Do not access, modify, or exfiltrate personal data beyond what is necessary to demonstrate the vulnerability.
  • Do not perform denial-of-service attacks or disruptive testing.
  • Do not publicly disclose the vulnerability without coordinating with us first.

Rules of Engagement

  • Only test against assets listed in the Scope page.
  • Use your own test accounts. Do not use or impact real student data.
  • Provide clear, reproducible reproduction steps in your report.
  • Allow reasonable time (90 days) for triage and remediation before public disclosure.

Response Timeline

  • Initial Response: 5 business days
  • Triage: 14 business days
  • Resolution target: 90 days (critical: 30 days)