Security

Security Model

Private, traceable and with as little trust as possible.

SideKids assumes a family-operated deployment: apps on the child's device, services on a family-owned server inside a private network (VPN/mesh). The public internet is not a trust boundary we expose services to.

Principles

Fail closed

Services require authentication for everything; unauthenticated requests are rejected, not degraded.

Secrets are hashed or absent

Device passwords are stored as hashes only. Cloud-account credentials exist solely on the family server.

No enumeration

Public identifiers are random (ULIDs), never sequential.

Brute-force protection

PIN/pattern entries rate-limit and lock.

Reproducible operations

Upstreams are pinned by commit and image digest; rebuild and restore procedures are scripted and tested.

Child Accounts

Children authenticate with device-bound credentials. A lost device can be invalidated server-side without touching the child's data. Child accounts cannot be silently impersonated: administrative actions are visible.

Parent Rights — Deliberately Limited

Parent tooling can:

  • Approve content
  • Set time budgets
  • Set storage limits
  • Share selected media
  • Locate/ring a device in an emergency, as agreed with the child

Parent tooling can not:

  • Read messages
  • View screen contents
  • Track location continuously
  • Access the child's account data covertly

These limits are architectural (the capabilities are not built), not merely policy.

Tokens and Authentication

  • Server APIs use bearer tokens or HttpOnly session cookies over TLS.
  • Tokens are generated with ≥256 bits of entropy; only hashes are stored.
  • Share links carry expiry, optional passwords and access limits.

Communication

All service communication runs inside the private network or over TLS. Nothing listens on public interfaces by default; reverse proxies allow-list the private network and deny everything else.

Vulnerability Reporting

Please report vulnerabilities privately via GitHub Private Vulnerability Reporting on the affected repository. Do not open public issues for security problems.

Response target: within 14 days.