generated: '2026-09-13' method: searched source: https://www.pearson.com/en-us/legal-information/our-policies/responsible-security-disclosure-policy.html source_status: 200 note: >- Pearson publishes a real, anonymously reachable Responsible Security Disclosure Policy on its own site. It is a coordinated-disclosure program with a named intake address and a stated acknowledgement target, and no paid bounty. program: published: true name: Pearson Responsible Security Disclosure Policy url: https://www.pearson.com/en-us/legal-information/our-policies/responsible-security-disclosure-policy.html type: coordinated-disclosure bug_bounty: false bug_bounty_note: >- Pearson states it does not offer a paid bug bounty and provides no financial compensation. No HackerOne, Bugcrowd or Intigriti program was found. contact: email: responsible.disclosure@pearson.com response: acknowledgement_target: 24 hours, with a ticket reference number status_update_cadence: >- Researchers are asked to request status no more than once every 14 days. remediation: >- Pearson assesses the report, assigns remediation work prioritized by severity, and notifies the reporter on resolution. safe_harbor: stated: false note: >- The policy states no explicit legal safe harbor. It requires researchers to comply with applicable law including the UK Computer Misuse Act 1990 and GDPR. scope: stated: >- Pearson products that serve a security.txt file in their root directory, including subdomains of an in-scope domain. Findings must be original and previously unreported. finding: >- MATERIAL GAP. Pearson scopes its disclosure program by the presence of a security.txt file, but serves no security.txt on any flagship domain we probed — pearson.com, www.pearson.com, plc.pearson.com, www.pearsonvue.com and home.pearsonvue.com all 404 at both /.well-known/security.txt and /security.txt (see well-known/pearson-well-known.yml). As written and as deployed, the policy currently scopes in no Pearson domain that a researcher can identify from outside, which leaves a researcher unable to tell whether a finding is in scope before reporting it. out_of_scope: - Volumetric / denial-of-service attacks - TLS configuration weaknesses - Non-exploitable vulnerabilities - Missing security headers - Email configuration gaps (SPF/DKIM/DMARC findings) - Session management issues - Password brute-force attacks security_txt: served: false probed: - url: https://www.pearson.com/.well-known/security.txt status: 404 - url: https://www.pearson.com/security.txt status: 404 - url: https://www.pearsonvue.com/.well-known/security.txt status: 404 - url: https://plc.pearson.com/.well-known/security.txt status: 404 - url: https://status.pearson.com/security.txt status: 200 note: SPA HTML shell, not an RFC 9116 document. Counted as a miss.