Pearson · Vulnerability Disclosure

Pearson Vulnerability Disclosure

Vulnerability disclosure

Pearson runs a coordinated vulnerability disclosure program on Hackerone.

EducationLearningAssessmentCertificationPublishingEdTechQualificationsTestingLearning ManagementWorkforce Skills
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

pearson-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-13'
method: searched
source: https://www.pearson.com/en-us/legal-information/our-policies/responsible-security-disclosure-policy.html
source_status: 200
note: >-
  Pearson publishes a real, anonymously reachable Responsible Security Disclosure Policy
  on its own site. It is a coordinated-disclosure program with a named intake address and
  a stated acknowledgement target, and no paid bounty.

program:
  published: true
  name: Pearson Responsible Security Disclosure Policy
  url: https://www.pearson.com/en-us/legal-information/our-policies/responsible-security-disclosure-policy.html
  type: coordinated-disclosure
  bug_bounty: false
  bug_bounty_note: >-
    Pearson states it does not offer a paid bug bounty and provides no financial
    compensation. No HackerOne, Bugcrowd or Intigriti program was found.
  contact:
    email: responsible.disclosure@pearson.com
  response:
    acknowledgement_target: 24 hours, with a ticket reference number
    status_update_cadence: >-
      Researchers are asked to request status no more than once every 14 days.
    remediation: >-
      Pearson assesses the report, assigns remediation work prioritized by severity, and
      notifies the reporter on resolution.
  safe_harbor:
    stated: false
    note: >-
      The policy states no explicit legal safe harbor. It requires researchers to comply
      with applicable law including the UK Computer Misuse Act 1990 and GDPR.
  scope:
    stated: >-
      Pearson products that serve a security.txt file in their root directory, including
      subdomains of an in-scope domain. Findings must be original and previously
      unreported.
    finding: >-
      MATERIAL GAP. Pearson scopes its disclosure program by the presence of a
      security.txt file, but serves no security.txt on any flagship domain we probed —
      pearson.com, www.pearson.com, plc.pearson.com, www.pearsonvue.com and
      home.pearsonvue.com all 404 at both /.well-known/security.txt and /security.txt
      (see well-known/pearson-well-known.yml). As written and as deployed, the policy
      currently scopes in no Pearson domain that a researcher can identify from outside,
      which leaves a researcher unable to tell whether a finding is in scope before
      reporting it.
  out_of_scope:
    - Volumetric / denial-of-service attacks
    - TLS configuration weaknesses
    - Non-exploitable vulnerabilities
    - Missing security headers
    - Email configuration gaps (SPF/DKIM/DMARC findings)
    - Session management issues
    - Password brute-force attacks

security_txt:
  served: false
  probed:
    - url: https://www.pearson.com/.well-known/security.txt
      status: 404
    - url: https://www.pearson.com/security.txt
      status: 404
    - url: https://www.pearsonvue.com/.well-known/security.txt
      status: 404
    - url: https://plc.pearson.com/.well-known/security.txt
      status: 404
    - url: https://status.pearson.com/security.txt
      status: 200
      note: SPA HTML shell, not an RFC 9116 document. Counted as a miss.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pearson-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.