Security disclosure
Read Revive Ltd welcomes responsible reports of security vulnerabilities in the school portal.
How to report an issue
Email support@readrevive.co.uk with the subject line Security disclosure. Please include enough detail for us to understand and reproduce the issue.
What to include
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce the issue, including URLs or affected features.
- Any proof-of-concept code, screenshots, or logs that may help investigation.
- Your contact details so we can follow up if we need clarification.
Scope
This process covers the Read Revive school portal at portal.readrevive.co.uk, including staff sign-in, school administration, and classroom workflows. The marketing website at readrevive.co.uk is operated separately; reports about that site can use the same contact address.
What to expect
We aim to acknowledge reports within five working days and will keep you informed as we investigate. Critical issues affecting live school or pupil data are prioritised. Please allow us reasonable time to remediate confirmed vulnerabilities before public disclosure.
Good-faith research
Do not access, modify, or delete data belonging to schools, staff, or pupils. Do not perform denial-of-service testing or social engineering against Read Revive staff or school users. We will not pursue legal action against researchers who act in good faith, follow this policy, and avoid privacy violations or service disruption.
Machine-readable contact details are also available in security.txt. Staff can return to the portal sign-in.