01 Current safeguards and limitations
The application uses password hashing, authenticated access checks, protected production session cookies and HTTPS deployment. Sensitive provider credentials are handled server-side. These measures do not amount to a certification, an independent security audit or a guarantee that compromise is impossible.
Email attachments and files shared through other applications extend beyond the account’s access controls. Protect your email account and devices. Do not share login credentials, password-reset links or a child’s report in public channels.
02 Reporting a suspected vulnerability
Write to hello@skillvelop.com, marked “Security report”, with affected URLs, a concise description and a minimal reproduction using your own account or non-personal test data. Do not send live credentials, API keys or another family’s report. Agree a protected exchange method if sensitive evidence is necessary.
This notice does not authorise penetration testing, intrusive scanning, bypassing controls, accessing another person’s records or denial-of-service activity. Stop if testing unexpectedly exposes personal information and report only the minimum facts. There is no promised bounty or blanket immunity under this notice.
03 Incident response
We will assess reports, contain confirmed incidents and determine remediation and any required notices or regulator reports under applicable law. We cannot promise a universal resolution time. Do not assume that a published policy alone means every statutory logging, breach-notification or response control has been completed.
Policy version
Published and last updated: 5 October 2026. Version 1.0. Changes will be published on this page and communicated where legally required. Mandatory rights prevail over conflicting wording.
Questions about this policy: hello@skillvelop.com.
