Security Policy

SparkWhy is built on a voice-first cloud system for children and their parents. Please report security issues privately so we can protect families, child data, and the integrity of the service.

Report A Vulnerability

Email security reports to security@sparkwhy.ai.

Do not open a public GitHub issue, discussion, social post, or support-thread with vulnerability details. If email delivery fails, send a minimal note to support@sparkwhy.ai with the subject SECURITY REPORT - CONTACT NEEDED; do not include exploit details in the fallback message.

Helpful reports include:

If you encounter another family's data, child transcript, token, secret, or other sensitive information, stop testing immediately, do not copy or retain the data, and report what happened.

Response Targets

We aim to:

Reports that may involve child data, account takeover, production secrets, or active exploitation are escalated as security incidents under the breach-response runbook.

Safe Harbor

We support good-faith security research. If you follow this policy and make a good-faith effort to avoid privacy violations, data destruction, service degradation, and interruption of other users, we will not initiate legal action or law-enforcement referral against you based solely on the research described in your report.

For SparkWhy-operated systems, security research conducted in accordance with this policy is authorized by SparkWhy in advance — you do not need to ask permission before testing. If a specific test seems like it might fall outside this policy's scope (for example, it could affect other users or systems we don't operate), contact us first so we can confirm before you proceed.

This safe harbor applies only to SparkWhy systems that we operate. It does not authorize testing of third-party services, cloud providers, payment processors, identity providers, vendors, or systems owned by other people.

To stay within safe harbor:

Scope

In scope for vulnerability reporting:

Out of scope unless explicitly authorized in writing:

Rewards

We do not currently operate a bug-bounty program. Reports are appreciated, but no reward, compensation, or swag is promised.

Coordinated Disclosure

Please give us a reasonable opportunity to investigate and remediate before public disclosure. We normally target coordinated disclosure within 90 days of triage, but child-data exposure, active exploitation, legal obligations, vendor coordination, or incomplete fixes may require a different timeline.

Pentest Scope

The lightweight external pentest scope for the parent-facing launch surface is tracked in docs/PENTEST_SCOPE.md.