Pearson · Vulnerability Disclosure
Pearson Vulnerability Disclosure
Vulnerability disclosure
Pearson runs a coordinated vulnerability disclosure program on Hackerone.
EducationLearningAssessmentCertificationPublishingEdTechQualificationsTestingLearning ManagementWorkforce Skills
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-13'
method: searched
source: https://www.pearson.com/en-us/legal-information/our-policies/responsible-security-disclosure-policy.html
source_status: 200
note: >-
Pearson publishes a real, anonymously reachable Responsible Security Disclosure Policy
on its own site. It is a coordinated-disclosure program with a named intake address and
a stated acknowledgement target, and no paid bounty.
program:
published: true
name: Pearson Responsible Security Disclosure Policy
url: https://www.pearson.com/en-us/legal-information/our-policies/responsible-security-disclosure-policy.html
type: coordinated-disclosure
bug_bounty: false
bug_bounty_note: >-
Pearson states it does not offer a paid bug bounty and provides no financial
compensation. No HackerOne, Bugcrowd or Intigriti program was found.
contact:
email: responsible.disclosure@pearson.com
response:
acknowledgement_target: 24 hours, with a ticket reference number
status_update_cadence: >-
Researchers are asked to request status no more than once every 14 days.
remediation: >-
Pearson assesses the report, assigns remediation work prioritized by severity, and
notifies the reporter on resolution.
safe_harbor:
stated: false
note: >-
The policy states no explicit legal safe harbor. It requires researchers to comply
with applicable law including the UK Computer Misuse Act 1990 and GDPR.
scope:
stated: >-
Pearson products that serve a security.txt file in their root directory, including
subdomains of an in-scope domain. Findings must be original and previously
unreported.
finding: >-
MATERIAL GAP. Pearson scopes its disclosure program by the presence of a
security.txt file, but serves no security.txt on any flagship domain we probed —
pearson.com, www.pearson.com, plc.pearson.com, www.pearsonvue.com and
home.pearsonvue.com all 404 at both /.well-known/security.txt and /security.txt
(see well-known/pearson-well-known.yml). As written and as deployed, the policy
currently scopes in no Pearson domain that a researcher can identify from outside,
which leaves a researcher unable to tell whether a finding is in scope before
reporting it.
out_of_scope:
- Volumetric / denial-of-service attacks
- TLS configuration weaknesses
- Non-exploitable vulnerabilities
- Missing security headers
- Email configuration gaps (SPF/DKIM/DMARC findings)
- Session management issues
- Password brute-force attacks
security_txt:
served: false
probed:
- url: https://www.pearson.com/.well-known/security.txt
status: 404
- url: https://www.pearson.com/security.txt
status: 404
- url: https://www.pearsonvue.com/.well-known/security.txt
status: 404
- url: https://plc.pearson.com/.well-known/security.txt
status: 404
- url: https://status.pearson.com/security.txt
status: 200
note: SPA HTML shell, not an RFC 9116 document. Counted as a miss.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pearson-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.