ELSA Security Disclosure Program

Last Updated: December 2024

Our Commitment to Security

At ELSA Corp, we take the security and privacy of our users seriously. We serve over 50 million learners worldwide, and protecting their data is our top priority. We value the security research community and welcome responsible disclosure of potential security vulnerabilities in our systems.

Program Overview

This is an invitation-only security research program designed to work with a select group of trusted security researchers. We believe in building long-term partnerships with the security community rather than opening ourselves to unlimited submissions.

Program Type: Private, Invitation-Only
Reward Budget: Modest monetary rewards + ELSA Premium subscriptions
Focus: Quality over quantity

How to Report a Security Vulnerability

Contact Information

Primary Contact: [email protected]

What to Include in Your Report:

Response Timeline
We are committed to responding promptly to security reports:

Scope

In-Scope Assets

We welcome security research on the following production systems:

APIs and Backend Services:

Web Applications:

Mobile Applications:

Out-of-Scope

The following are explicitly not in scope and will not qualify for rewards:

Environments:

Third-Party Services:

Attack Types:

Non-Security Issues:

Vulnerability Severity Classification

We classify vulnerabilities based on their potential impact using the following criteria:

SeverityExamplesReward
🔴 CriticalRemote Code Execution (RCE), SQL Injection with data exfiltration, Authentication bypass, Mass PII exposure, Payment fraud, SSRF with significant impact$50 + Lifetime Premium
🟠 HighAccount takeover, Privilege escalation, IDOR with sensitive data, XSS with significant impact, Auth/session flaws, API key exposure$25 + 1Y ELSA Premium
🟡 MediumXSS with limited impact, CSRF on sensitive actions, IDOR with limited exposure, Info disclosure of non-sensitive data, Missing security headers3 months ELSA Premium + Recognition
🟢 LowSecurity misconfigurations with minimal impact, Minor info disclosure, Minor auth weaknesses, CSRF on non-sensitive actions1 month ELSA Premium + Recognition
ℹ️ InfoSecurity best practices, Low-impact configs, Findings without clear exploit pathThanks + Recognition

Reward Structure

Monetary Rewards

Valid, original security vulnerabilities will be eligible for monetary rewards based on severity:

ELSA Premium Subscriptions

In addition to monetary rewards, validated findings will receive:

Recognition

With your permission, we will:

Payment Process

Safe Harbor

ELSA Corp is committed to protecting security researchers who act in good faith. We will not pursue legal action against researchers who:

Protected Activities

Required Conduct

Security researchers must:

Frequently Asked Questions

Q: Is this program open to everyone?
A: Currently, this is an invitation-only program. We work with a select group of trusted researchers. If you’re interested, please introduce yourself via [email protected] with your background and experience.

Q: Can I use automated scanners?
A: Automated scanning is discouraged and may trigger our security monitoring. If you must use scanners, please request permission first and provide the source IPs you’ll be scanning from.

Q: How long does the whole process take?
A: From report to fix deployment, expect 4-12 weeks depending on severity and complexity. Critical issues are prioritized and may be fixed within days.

Q: Can I submit multiple vulnerabilities?
A: Yes! Each unique, valid vulnerability is eligible for a reward. However, we consider similar vulnerabilities in the same component as a single issue.

Q: I need production credentials to test. Can you provide them?
A: For specific testing scenarios, we may provide test accounts. Contact us at [email protected] with your requirements.

About ELSA

ELSA (English Language Speech Assistant) is the world’s most advanced AI-powered English pronunciation coach. Our mission is to enable the 1.5 billion English learners globally to speak with confidence.
Platform: Mobile (iOS, Android) & Web
Users: 50+ million learners across 200+ countries
Technology: AI-powered speech recognition and personalized coaching

We’re committed to protecting our users’ data and maintaining the highest security standards in the EdTech industry.

Thank you for helping us keep ELSA secure!
For questions or to report a vulnerability, contact:
[email protected]