Limited Time Launch Offer: Save 90% on kMAPTA Exam Voucher Coupon: kMAPTA-90-OFF
Responsible disclosure

Help us keep the Academy secure.

If you discover a security vulnerability affecting Knight Squad Academy, report it privately. Please give us enough detail to reproduce the issue and time to investigate it before disclosure.

Submit a report
Authorized target

Program scope

Only test the following scope and only systems directly operated by Knight Squad Academy.

In scope *.knightsquad.academy/*
What we are interested in

Vulnerabilities by severity

Final severity depends on exploitability and demonstrated impact, not the vulnerability name alone.

Low

  • Limited information disclosure
  • Open redirect with a demonstrated attack path
  • Minor exploitable security weaknesses

Medium

  • Reflected or limited stored XSS
  • HTML injection with security impact
  • CSRF on meaningful actions

High

  • Stored XSS in a sensitive context
  • Broken access control or impactful IDOR
  • Privilege escalation or sensitive data exposure

Critical

  • Remote code execution (RCE)
  • SQL injection with serious impact
  • Authentication bypass or mass account takeover
Common exclusions

Generally out of scope

These findings are not eligible unless they demonstrate clear, practical security impact.

  • Missing security headers or cookie flags without a working exploit
  • Self-XSS, clickjacking without sensitive actions, and low-impact CSRF
  • Rate limiting, username enumeration, or brute-force concerns without demonstrated impact
  • TLS, DNS, SPF, DKIM, or DMARC configuration observations
  • Version disclosure, banners, verbose errors, or stack traces without exploitation
  • Social engineering, phishing, physical attacks, denial of service, or spam
  • Content, spelling, UI, or best-practice issues without a security consequence
Coupon grace periods

A coupon may remain active for a limited grace period after its promotional post or website listing ends. This is expected behavior, is out of scope, and does not need to be reported.

Your submission

Send a clear report

Include enough information for our team to reproduce and understand the vulnerability.

01

Affected asset

Provide the exact URL, endpoint, feature, and account role.

02

Reproduction

Give numbered steps and a minimal, safe proof of concept.

03

Impact

Explain what a realistic attacker could access, change, or execute.

04

Evidence

Add sanitized requests, responses, screenshots, or a short video.

Manually verify every finding. Automated scanner output, unverified AI-generated content, and bulk or template-based reports are not accepted. Before reporting, make sure you can reproduce the issue reliably and explain its real security impact.

Rules of engagement

Test safely

Good-faith research should protect our users, data, and service availability.

  • Use only accounts and data you own.
  • Use the minimum activity required to prove the issue.
  • Stop immediately if you encounter sensitive information.
  • Do not disrupt services, destroy data, or run high-volume scans.
  • Keep the report private until we resolve it or approve disclosure.

We will not pursue legal action for good-faith research performed within this policy. This does not authorize testing of third-party systems or activity that violates applicable law.

Researcher recognition

Hall of Fame

Researchers behind eligible, validated reports may be recognized here with their consent.

No researchers listed yet

Our Hall of Fame is ready for its first responsible security researcher.

Program rewards

Recognition beyond a thank-you

We review each submission for scope, reproducibility, novelty, and demonstrated impact. We may contact you if additional evidence is needed during validation.

We do not currently offer monetary bounties. Eligible Medium, High, or Critical findings may receive a complimentary certification voucher or an exclusive discount of up to 95%, depending on impact, severity, and report quality.