For security researchers. If you have found a vulnerability, or a bug that seriously breaks Semantix for real learners, report it here and we will work with you on a fix. For everyday problems, use the Feedback button in the corner of any page.
Report an issue
You do not need a Semantix account. Reports go to a separate, triaged queue from general support.
Prefer email, or have a large attachment? Write to security@semantix.chat. Attachments up to roughly 30 MB are fine; link a larger video.
Rewards
- A free month of Semantix Pro.
- A place in the Hall of Fame below, with your permission.
Eligibility and severity are at our discretion. Cosmetic glitches, copy typos and low-impact edge cases are welcome through the Feedback button, but do not qualify for the reward.
In scope: security vulnerabilities
- Arbitrary code execution.
- Injection (SQL / NoSQL, or prompt injection that escalates privilege or exfiltrates data).
- Privilege escalation, from unauthenticated to user or from user to admin.
- Authentication or authorization bypass, including the admin surface.
- Circumventing plan or entitlement gating for paid features.
- Cross-site scripting or CSRF, except the cases listed as out of scope.
- Exposure of another learner's data: cards, conversations, profile or subscription.
In scope: high-impact bugs
- Account-recovery or login dead-ends a learner cannot get out of.
- Data loss or corruption of cards, review history or progress.
- A core flow broken end to end: chat, review, practice, checkout or email actions.
- Incorrect billing, access or entitlement state.
- Reproducible crashes that block a whole page or feature.
Out of scope
- Denial of service, brute force or volumetric attacks.
- Social engineering, phishing or physical attacks.
- SPF, DKIM or DMARC configuration opinions, and mail-system abuse.
- User or account enumeration.
- Missing security headers or non-sensitive cookie handling.
- CSRF on the login, logout or signup pages.
- Tokens that remain valid after logout or deletion, unless you show an authenticated action succeeding beyond the token's short lifetime.
- Missing best practices (rate limiting, password strength) without a concrete exploit.
Hall of Fame
Researchers who reported a valid issue and agreed to be named. We list someone only once they have said yes, under the name they asked for.
No entries yet - the page is new. Report something valid and you can be the first.
Rules and our commitments
- Do not access, modify or destroy another learner's account or data. Test with accounts you own.
- Do not run attacks that degrade the service for other learners, and no automated scanners.
- Only test semantix.chat and its subdomains.
- Give us reasonable time to ship a fix before disclosing publicly.
We respond as quickly as we can, keep you updated toward a fix, and will not pursue legal action against research that follows these rules. Not a security issue? Visit support.