VULNERABILITY DISCLOSURE POLICY
Last updated August 13, 2026
Overview
Immersh takes the security of our platform and the data entrusted to us seriously. We welcome reports from security researchers, customers, students, and institutions who believe they have found a security vulnerability in an Immersh service, and we are committed to working with reporters to verify and remediate confirmed issues.
This page is the policy referenced by our security.txt file, published in accordance with RFC 9116.
Scope
This policy covers security vulnerabilities in:
- The Immersh Platform at https://immersh.com, including all subpages and the education application
- The Immersh API
- Immersh's LTI 1.3 integration endpoints
The following are outside the scope of this policy:
- Third-party services and websites not operated by Immersh (report issues in those services to their respective owners)
- Social engineering, phishing, or physical attacks against Immersh staff, users, or institutions
- Denial-of-service testing or any activity that degrades service for other users
- Reports based solely on automated scanner output without a demonstrated security impact
How to Report a Vulnerability
Email a description of the issue to security@immersh.com.
A useful report includes:
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue (URLs, request/response examples, screenshots, or proof-of-concept details)
- The date and time you observed the issue
- Any accounts or test data you used
- How you would like to be credited or contacted, if at all (anonymous reports are accepted)
We accept reports in English and Spanish.
What to Expect From Us
When you report a suspected vulnerability in good faith:
- We will acknowledge receipt of your report within 24 hours.
- We will assess the severity of the issue using the classification model in our incident response process.
- Confirmed vulnerabilities are remediated on a timeline based on severity. Our published remediation targets are: Critical within 24 hours, High within 7 days, Medium within 30 days, and Low within 90 days.
- We will keep you informed of our progress on a confirmed report where contact information was provided.
- If an issue is confirmed to have exposed protected student educational records, we notify affected institutions in line with our published FERPA breach notification commitment (72-hour target).
Immersh does not currently operate a paid bug bounty program.
Guidelines for Good-Faith Research
To protect our users and their data, we ask that you:
- Test only against accounts and data you own or are explicitly authorized to use
- Do not access, modify, or delete data belonging to other users or institutions; if you encounter such data unexpectedly, stop, do not retain it, and report it immediately
- Do not degrade, disrupt, or overload the service
- Do not publicly disclose the issue before we have had a reasonable opportunity to remediate it
- Act in good faith and comply with applicable law
Immersh supports good-faith security research conducted under these guidelines and will work constructively with reporters who follow them.
Contact
- Security reports: security@immersh.com
- General support: help@immersh.com
- Machine-readable disclosure information: https://immersh.com/.well-known/security.txt
Immersh, LLC Email: security@immersh.com