Source: https://mokxi.com/security
Updated: 2026-10-05

Security

# Report a security problem

If you think you have found a security problem in Mokxi, thank you. Please tell us before anyone else, so we can fix it for everyone who uses it, including the students and teachers who sign in at school.

## How to report it

Email security@mokxi.com. You can also use the message form on our support page. Start the first line with "Security" and it becomes the subject of your ticket.

Please include:

- The steps to show the problem, from the start
- The page, URL or part of Mokxi it is in
- What someone could do with it, and who it would affect
- Screenshots or a short video, if they help

Use your own test account and made-up data. Please do not send us anyone else's real data, even to prove a point. If you came across some by accident, tell us what kind it was, not the data itself.

## What we promise

- A person reads every report, and we reply to you ourselves.
- We keep you updated while we look into it and fix it.
- If you would like, we credit you on this page once it is fixed, by the name or handle you choose.
- We will not take legal action over good-faith research that follows the rules below.

There is no paid bug bounty. We would rather say that plainly than leave you guessing.

## Safe harbor

If you research Mokxi in good faith and follow the rules on this page, we consider that research authorized. We will not pursue legal action or ask anyone else to, and if someone else brings a complaint about it, we will say that your research was authorized. If you are not sure whether something is allowed, ask us first.

## What is in scope

### In scope

- mokxi.com and its subdomains
- The editor and the simulator
- The Mokxi API
- The Mokxi CLI (@mokxi/cli)
- The Mokxi VS Code extension

### Out of scope

- Denial of service, or anything that floods or slows the site
- Spam, phishing or other social engineering of our team or our users
- Output from automated scanners with no proven impact
- Missing best-practice headers or settings, without a way to exploit it
- Other people's accounts or data

## Rules for testing

- Test only on your own account, or on accounts you made for testing.
- Do not access, change, download or keep anyone else's data. If you reach some by accident, stop there and tell us.
- Once you have shown the problem, stop and report it. Do not go further to see what else it opens.
- Give us reasonable time to fix it before you tell anyone else or publish it. We will keep you told along the way.

## How we protect your account

- Passwords are never stored as typed. Each one is hashed with PBKDF2-SHA256 and its own random salt.
- Two-factor authentication. You can turn on codes from an authenticator app, with recovery codes in case you lose your phone.
- Sign in without a password. You can sign in with Google, Microsoft, Apple or GitHub, or with a link we email you.
- Guessing is cut off. Ten wrong passwords in 15 minutes pauses password sign-in for that address for 15 minutes, and ten wrong two-factor codes in a row pauses codes on the account for 15 minutes. Either way, we email the account's owner.
- New sign-ins. When your account signs in from a browser and device it has not used before, we email you. Students in a class and children under 13 get no such email.
- You can see where you are signed in. Your account page lists your browsers and devices, and one button signs out everywhere else.
- HTTPS only. Pages asked for over plain HTTP are sent to HTTPS, and browsers are told to use only HTTPS for mokxi.com and its subdomains for a year (HSTS).
- Your sign-in cookie stays put. It is signed, sent only over HTTPS, kept out of reach of the page's scripts (HttpOnly) and held back from most requests other sites start (SameSite=Lax).
- Pages limit what can run on them. Every page has a Content Security Policy, and other sites cannot put our pages in a frame, except the project embed that is made for it.

How we handle student data is on student data privacy, and what we keep about everyone is in our privacy policy.

## Questions

How do I report a security problem in Mokxi?

Email security@mokxi.com, or send a message from mokxi.com/support whose first line starts with "Security". Tell us the steps, the page or URL and what someone could do with it. A person reads every report and replies.

Does Mokxi pay a bug bounty?

No. There is no paid bug bounty. We read every report, reply to you ourselves, keep you updated, and if you would like, we thank you by name on this page once it is fixed.

Will Mokxi take legal action over my security research?

Not for good-faith research that follows the rules on this page: test only your own account, do not access or keep anyone else's data, stop and report once you have shown the problem, and give us reasonable time to fix it before you go public.

## More about Mokxi

What Microsoft, Google and GitHub have verified about Mokxi is on Trust.
