Security & vulnerability reporting
We take the security of your family’s data seriously and welcome reports from the security community.
How we protect your data
CurriBloom is built with defense in depth: data is encrypted in transit; access to household data is scoped to your authenticated adult account and enforced at both the application and the database (PostgreSQL Row-Level Security); uploaded files live in private storage reached only through short-lived, authorized links; passwords are stored only as salted hashes; and households are isolated so one family’s data can never reach another.
Reporting a vulnerability
Found something? Email hello@curribloom.com with a description, the steps to reproduce, and the impact. We’ll acknowledge your report and work with you toward a fix.
- Please give us a reasonable chance to fix an issue before disclosing it publicly.
- Only test against your own account and data — do not access, modify, or delete other people’s information, and don’t run attacks that could degrade the service for others.
- Acting in good faith under this guidance, we won’t pursue action against you.
For account help rather than a security issue, see Support.