Security Policy
SparkWhy is built on a voice-first cloud system for children and their parents. Please report security issues privately so we can protect families, child data, and the integrity of the service.
Report A Vulnerability
Email security reports to security@sparkwhy.ai.
Do not open a public GitHub issue, discussion, social post, or support-thread with vulnerability details. If email delivery fails, send a minimal note to support@sparkwhy.ai with the subject SECURITY REPORT - CONTACT NEEDED; do not include exploit details in the fallback message.
Helpful reports include:
- A clear description of the issue and affected surface.
- Steps to reproduce, using only accounts, devices, or test data you control.
- Impact, including whether parent data, child data, credentials, billing data, logs, or safety controls may be affected.
- Request and response snippets, screenshots, or logs with secrets and personal information redacted.
- Your preferred contact information for follow-up.
If you encounter another family's data, child transcript, token, secret, or other sensitive information, stop testing immediately, do not copy or retain the data, and report what happened.
Response Targets
We aim to:
- Acknowledge new reports within 2 business days.
- Provide an initial triage decision within 5 business days.
- Send status updates at least every 10 business days until the issue is fixed or otherwise resolved.
Reports that may involve child data, account takeover, production secrets, or active exploitation are escalated as security incidents under the breach-response runbook.
Safe Harbor
We support good-faith security research. If you follow this policy and make a good-faith effort to avoid privacy violations, data destruction, service degradation, and interruption of other users, we will not initiate legal action or law-enforcement referral against you based solely on the research described in your report.
For SparkWhy-operated systems, security research conducted in accordance with this policy is authorized by SparkWhy in advance — you do not need to ask permission before testing. If a specific test seems like it might fall outside this policy's scope (for example, it could affect other users or systems we don't operate), contact us first so we can confirm before you proceed.
This safe harbor applies only to SparkWhy systems that we operate. It does not authorize testing of third-party services, cloud providers, payment processors, identity providers, vendors, or systems owned by other people.
To stay within safe harbor:
- Test only with accounts, devices, content, and data you own or were explicitly authorized to use.
- Use the minimum access needed to prove the issue.
- Stop immediately if testing exposes personal information, child data, secrets, or another user's account.
- Do not persist access, install malware, create backdoors, exfiltrate data, modify or delete data outside your own test account, or disrupt availability.
- Do not perform social engineering, phishing, spam, physical attacks, or denial of service.
- Do not publicly disclose details until we have completed remediation or agreed on a disclosure timeline.
Scope
In scope for vulnerability reporting:
- SparkWhy public website and waitlist surfaces.
- Parent account authentication and session handling.
- Parent-facing APIs, including parent dashboard, device management, onboarding, export, deletion, and feedback paths.
- Device pairing and provisioning endpoints where they affect parent accounts or child data.
- Security-sensitive configuration, repository code, or deployment artifacts that could expose production systems or user data.
Out of scope unless explicitly authorized in writing:
- Denial-of-service or high-volume load testing.
- Physical device attacks, firmware extraction, or hardware tampering.
- Attacks against Azure, OpenAI, Stripe, Apple, email vendors, analytics, hosting providers, or other third-party infrastructure.
- Social engineering of staff, support, parents, or children.
- Attempts to obtain, retain, or publish child data or another family's data.
- LLM safety jailbreaks that do not demonstrate a security boundary bypass.
Rewards
We do not currently operate a bug-bounty program. Reports are appreciated, but no reward, compensation, or swag is promised.
Coordinated Disclosure
Please give us a reasonable opportunity to investigate and remediate before public disclosure. We normally target coordinated disclosure within 90 days of triage, but child-data exposure, active exploitation, legal obligations, vendor coordination, or incomplete fixes may require a different timeline.
Pentest Scope
The lightweight external pentest scope for the parent-facing launch surface is tracked in docs/PENTEST_SCOPE.md.