Kidder legal information
Security & Responsible Disclosure
This page describes high-level safeguards and the current path for reporting a suspected vulnerability. Kidder does not claim a security certification or guaranteed response time.
Document contents
1. Security approach
Kidder’s architecture uses authentication, protected application transport, access controls, account/session controls, data minimization, administrative masking, and audit mechanisms. These are layers of risk reduction, not a guarantee that an incident can never occur.
2. Current safeguards
- Parent and Child app connections to Kidder are configured to use HTTPS.
- Parent authentication tokens are stored using encrypted preferences.
- Child App backup is disabled; Parent backup uses configured extraction rules.
- Parent sessions and push registrations support revocation or deactivation.
- Administrative permissions distinguish ordinary and sensitive access.
- Selected Parent and Child values are masked or reduced in administrative views.
- Authentication, sensitive administrative access, device actions, and selected security events can be logged.
3. Family security guidance
- Keep Parent passwords, PINs, verification codes, and devices private.
- Use only the intended account, device, and pairing path.
- Review connected devices, sessions, permissions, and protection status.
- Keep Android and Kidder versions current where updates are available.
- Do not send passwords, authentication codes, or unnecessary child information through general contact channels.
4. Data minimization and boundaries
The Parent App does not request Parent-device location. Child-device Content Safety processes raw visible text locally and sends derived classifications rather than raw screen text. The apps do not include advertising or general-purpose analytics tools.
Security-sensitive child-device capabilities still require clear in-app explanations, narrow use, and ongoing review. Website policy text cannot replace those controls.
5. Reporting a suspected vulnerability
Kidder does not operate a dedicated security mailbox. Security-related concerns should be sent through the approved support address below and identified clearly as a security concern.
A report should include a concise description, affected URL or component, reproducible steps, observed impact, and safe supporting evidence. Do not access another person’s data, disrupt service, use social engineering, or retain unnecessary child or account information.
6. How reports are handled
Kidder intends to acknowledge, assess, validate, address, and communicate about reports according to severity and available evidence. No acknowledgement, resolution, disclosure, or reward timeline is currently promised.
Safe-harbor language, testing authorization, excluded systems, coordinated-disclosure expectations, and any bounty terms remain subject to legal and operational approval.
7. Security incidents
Incident response ownership, production logging, containment, user notification, regulator notification, evidence preservation, and recovery procedures require operational confirmation. Any notice obligation will depend on the facts and applicable law.
8. No unsupported certifications
Kidder does not claim SOC 2, ISO 27001, PCI DSS, HIPAA compliance, an external penetration-test certification, or another security seal. Any future claim must be supported by current, applicable evidence.