Last updated: 2026-08-20 · Reports: support@guardnilu.com · Machine-readable: /.well-known/security.txt
Security & Vulnerability Disclosure
Effective date: 2026-08-20 · Version 1
Reporting a problem
Email support@guardnilu.com with “Security” in the subject line. A report is most useful when it carries the URL or endpoint, the account role you were signed in as, the steps that reproduce it, and what you were able to reach that you should not have been. Screenshots and a request/response capture help.
Do not include another family's data in the report. Describe what you could reach and stop there; we can confirm it from our own logs.
What we commit to
- Acknowledgement within 3 business days of the report reaching that inbox.
- A severity and a plan within 10 business days, including whether we consider it a vulnerability and why.
- Containment inside 1 hour for anything that is actively exposing a child's data, and triage inside 4 hours. That is the internal target our incident plan already runs on.
- Credit if you want it, on this page, once the fix is live.
We do not pay bounties. We are a small company and would rather tell you that than let you spend a weekend expecting one.
Safe harbour for good-faith research
If you follow this policy, we will not pursue legal action against you and will treat your work as authorised. That means: use only accounts you created, stop at the first record that proves the finding, do not run automated scanning that degrades the service for families, do not modify or delete anyone's data, and give us the acknowledgement window before publishing.
Out of scope: social engineering of our staff or vendors, physical access, denial-of-service, spam or rate-limit exhaustion, and findings that only affect the marketing pages. Reports generated wholesale by a scanner, with no demonstrated impact, are read but rarely actionable.
If a breach affects your family
We notify affected parents directly by email once an incident is confirmed, along with what was reached and what to do about it. The statutory deadline for that notice depends on the state you live in, and the specific state timelines in our incident plan are being confirmed with privacy counsel rather than guessed at here. We are not going to publish a number we have not verified.
Payment card and bank credentials are held by Stripe and never reach our servers, so a breach here does not expose them. See the security section of the State of the App for what is and is not protected today.
What we have not done
No outside firm has performed a penetration test, and we hold no SOC 2 or ISO 27001 attestation. Our access-control testing is our own: fifteen adversarial tests that sign in as real accounts and try to reach data belonging to other families. There is no third party standing behind that, and a reviewer should weigh it accordingly.
Related
- Privacy Policy — what we collect and who processes it
- State of the App — the current, plain-language account of what is built
- security.txt — RFC 9116 contact record