Security
Report a security concern
Student safety and tenant isolation take priority. Report suspected vulnerabilities or unauthorized access privately so they can be investigated without exposing school information.
Effective August 15, 2026
How to report
Email [email protected] with the subject “Security report.” Include a concise description, affected URL, time observed, and safe reproduction steps. Do not access records that are not yours, disrupt a live school workflow, or include student data in the first message.
What happens next
We will acknowledge a credible report, preserve relevant logs, assess impact, contain active risk, and coordinate with affected schools when appropriate. We may request a secure method for additional evidence.
Current controls
PickupPass uses tenant-scoped records, hashed credentials and tokens, one-time staff links, secure sessions, authorization checks, safety holds, request limits, audit logs, backups, restrictive browser headers, and immediate session/device revocation.
Not a bug bounty
The public beta does not currently offer a paid bounty or authorize destructive testing. Good-faith, minimal, privacy-preserving reports are welcome.