Security & vulnerability reporting

We take the security of your family’s data seriously and welcome reports from the security community.

How we protect your data

CurriBloom is built with defense in depth: data is encrypted in transit; access to household data is scoped to your authenticated adult account and enforced at both the application and the database (PostgreSQL Row-Level Security); uploaded files live in private storage reached only through short-lived, authorized links; passwords are stored only as salted hashes; and households are isolated so one family’s data can never reach another.

Reporting a vulnerability

Found something? Email hello@curribloom.com with a description, the steps to reproduce, and the impact. We’ll acknowledge your report and work with you toward a fix.

For account help rather than a security issue, see Support.

Security & vulnerability reporting · CurriBloom