Security
Security Model
Private, traceable and with as little trust as possible.
SideKids assumes a family-operated deployment: apps on the child's device, services on a family-owned server inside a private network (VPN/mesh). The public internet is not a trust boundary we expose services to.
Principles
Fail closed
Services require authentication for everything; unauthenticated requests are rejected, not degraded.
Secrets are hashed or absent
Device passwords are stored as hashes only. Cloud-account credentials exist solely on the family server.
No enumeration
Public identifiers are random (ULIDs), never sequential.
Brute-force protection
PIN/pattern entries rate-limit and lock.
Reproducible operations
Upstreams are pinned by commit and image digest; rebuild and restore procedures are scripted and tested.
Child Accounts
Children authenticate with device-bound credentials. A lost device can be invalidated server-side without touching the child's data. Child accounts cannot be silently impersonated: administrative actions are visible.
Parent Rights — Deliberately Limited
Parent tooling can:
- Approve content
- Set time budgets
- Set storage limits
- Share selected media
- Locate/ring a device in an emergency, as agreed with the child
Parent tooling can not:
- Read messages
- View screen contents
- Track location continuously
- Access the child's account data covertly
These limits are architectural (the capabilities are not built), not merely policy.
Tokens and Authentication
- Server APIs use bearer tokens or HttpOnly session cookies over TLS.
- Tokens are generated with ≥256 bits of entropy; only hashes are stored.
- Share links carry expiry, optional passwords and access limits.
Communication
All service communication runs inside the private network or over TLS. Nothing listens on public interfaces by default; reverse proxies allow-list the private network and deny everything else.
Vulnerability Reporting
Please report vulnerabilities privately via GitHub Private Vulnerability Reporting on the affected repository. Do not open public issues for security problems.
Response target: within 14 days.