Skip to content

Security and Responsible Disclosure Policy

How Mentoring @ Invespire protects accounts and how to report a security vulnerability.

Last updated · Version 1.0.0

Legal information is being finalised

This document is a draft that has not yet been reviewed by legal counsel, and some of the operator's details (such as the Grievance Officer's contact) may not be published yet. Until then, reach us through the Contact page or the Report a concern page.

On this page

1. How we protect the Platform#

No system is perfectly secure, and we do not hold any security certification. If you find a weakness, please tell us.

  • All traffic uses HTTPS, and browsers are told to use only HTTPS.
  • Passwords are stored as bcrypt hashes. Email-confirmation and password-reset links contain single-use codes that are stored only as hashes and expire after 24 hours and 1 hour respectively.
  • Sessions are held in an encrypted, http-only cookie. Resetting a password signs out other sessions, and suspended accounts are signed out on their next request.
  • Sign-in, sign-up, password-reset, booking, upload, message and report actions are rate-limited.
  • Uploaded images are checked by their content and limited to PNG, JPEG and WebP.
  • Pages cannot be embedded in other sites, and standard security headers are set, including a Content Security Policy that blocks scripts loaded from other sites. It is one layer of defence, not a guarantee against every kind of script injection.

2. Reporting a vulnerability#

Email info@invespire.com with a description of the issue, the steps to reproduce it, the affected page or URL, and its potential impact. Please do not include other people's personal data in your report.

We will acknowledge your report within 5 working days, keep you informed of our progress, and tell you when the issue is fixed. With your permission, we are happy to credit you.

Our contact details are also published in machine-readable form at https://mentoring.invespire.com/.well-known/security.txt.

3. Testing guidelines#

When looking for or reporting vulnerabilities, please:

  • test only against accounts you created for testing, and never access, change or delete other people's data; if you come across personal data by accident, stop, do not keep it, and tell us;
  • avoid degrading the service: no denial-of-service or load testing, no automated scanning at a rate that affects other users, and no spamming users or our email system;
  • do not use social engineering, phishing or physical attacks against users, our staff or our providers;
  • do not test the systems of our providers (such as Vercel, MongoDB Atlas, our email provider, Cloudinary or Google); report issues in their services to them;
  • give us a reasonable time to fix the issue before sharing any details publicly.

4. Good-faith research#

If you follow this policy in good faith, we will treat your research as authorised, will not take legal action against you for it, and will work with you to understand and fix the issue. This applies only to our own systems; we cannot give permission on behalf of third parties.

5. Scope#

In scope: the Mentoring @ Invespire website and application at https://mentoring.invespire.com.

Generally out of scope unless you can show a real impact: reports from automated scanners without a working proof of concept; missing security headers without an exploit; clickjacking on pages without sensitive actions; email configuration reports (SPF, DKIM, DMARC) on their own; and the fact that registration tells a visitor when an email address is already registered, which is a known and accepted limitation.

6. Rewards#

Mentoring @ Invespire is free and has no bug bounty programme, so we cannot offer payment for reports.

Questions about this page? Contact us