Security
Last updated 23 August 2026
This is a public summary of the evaluation deploy, not a pentest letter or a SOC 2 report. Coordinated disclosure: see security.txt.
What this deploy already does
HTTPS with HSTS, CSP
frame-ancestors 'none', X-Frame-Options DENY, COOP same-origin, nosniff, a strict referrer policy, and a permissions policy that disables camera, geolocation, payment, and USB. Grown-up passwords and child PINs are stored with scrypt hashes. Learner sessions are cookies, not tokens in the URL.Processors that can see traffic
Vercel — Application hosting, CDN, and serverless runtime
Vercel AI Gateway — Model routing for the Guide and related AI tools
Stripe — Card checkout, invoices, and customer portal — only when live billing is connected
Upstash — Optional Redis rate limiting
Resend — Transactional email (verification, magic links, password reset) when configured
What production still needs
Encrypted managed databases with backups, key rotation, least privilege, a staffed incident process, and an independent penetration test. Those are operator obligations, not claims this demo has finished.
Report a vulnerability
Email safety@wondermind.app with steps to reproduce. Do not include exploit code in a ticket that a child might see. Do not run brute-force, injection, or IDOR tests against the public demo family.