Skip to content

Security

Last updated 23 August 2026

This is a public summary of the evaluation deploy, not a pentest letter or a SOC 2 report. Coordinated disclosure: see security.txt.

What this deploy already does
HTTPS with HSTS, CSP frame-ancestors 'none', X-Frame-Options DENY, COOP same-origin, nosniff, a strict referrer policy, and a permissions policy that disables camera, geolocation, payment, and USB. Grown-up passwords and child PINs are stored with scrypt hashes. Learner sessions are cookies, not tokens in the URL.
Processors that can see traffic

VercelApplication hosting, CDN, and serverless runtime

Vercel AI GatewayModel routing for the Guide and related AI tools

StripeCard checkout, invoices, and customer portal — only when live billing is connected

UpstashOptional Redis rate limiting

ResendTransactional email (verification, magic links, password reset) when configured

What production still needs
Encrypted managed databases with backups, key rotation, least privilege, a staffed incident process, and an independent penetration test. Those are operator obligations, not claims this demo has finished.
Report a vulnerability
Email safety@wondermind.app with steps to reproduce. Do not include exploit code in a ticket that a child might see. Do not run brute-force, injection, or IDOR tests against the public demo family.