Skip to main content

Security & Vulnerability Disclosure

Growing Standard LLC · Last updated April 2026

Growing Standard LLC operates Potato Class (potatoclass.com) and the Growing Standard marketing and district portal (growingstandard.com). We handle K-12 student data under FERPA, COPPA, and state student-data privacy laws. If you are a security researcher and you believe you have found a vulnerability in either site or in our backend services, this page tells you how to report it and what to expect from us.

Report a vulnerability: security@growingstandard.com
Machine-readable contact at /.well-known/security.txt (RFC 9116).

Scope

In scope.

Out of scope.

Safe harbor

We will not pursue legal action against good-faith security researchers who follow this policy. Specifically, as long as your research stays within the rules below, we consider your activity authorized under the Computer Fraud and Abuse Act (18 U.S.C. §1030), the Digital Millennium Copyright Act (17 U.S.C. §1201(j) for security research), and applicable state computer-crime laws. We will not ask law enforcement to investigate or charge you, and we will not pursue civil action, provided you act in good faith under this policy.

If a third party brings legal action against you for activity conducted in good faith under this policy, we will take reasonable steps to make it known that your activity was authorized.

Rules of engagement

What to include in your report

Response SLA

Recognition

We maintain an informal list of researchers who have reported valid issues to us and wanted public credit. If you would like to be listed, tell us in your report. We do not currently pay monetary bounties, but we will acknowledge your work publicly (with your permission) once the issue is fixed.

Coordinated incident disclosure to districts

If a confirmed incident affects student data of a district we serve, we will notify the district’s designated privacy contact within 24 hours of discovery and deliver a full written incident report within 72 hours, per our standard data privacy agreement and Va. Code §18.2-186.6. This applies regardless of whether the finding originated from this disclosure program or from our own monitoring.

Related resources

Growing Standard LLC · Virginia, USA · Contact: security@growingstandard.com