MyLittleWorld
HomeFeaturesFor FamiliesOperationsResourcesPricing
/
Log inGet started

Vulnerability Disclosure Policy

Last updated August 20, 2026

MyLittleWorld Inc. values the work of independent security researchers who help us keep our platform safe for the childcare organizations, staff, and families who rely on it. This policy explains how to report a security vulnerability to us, what you can expect from us in return, and the ground rules for testing.

Scope

This policy applies to:

  • The MyLittleWorld web application (the core childcare management platform)
  • The MyLittleWorld marketing website

If you're unsure whether a system is in scope, email us before testing — we'd rather answer a question than have you hold back a legitimate finding, or accidentally test something that isn't ours.

What's in scope

We're especially interested in reports involving:

  • Cross-site scripting (XSS)
  • Authentication or session-management bypass
  • Authorization bypass, including any way to access another organization's data (this includes any bypass of our Row-Level Security tenant-isolation controls — this category is a top priority for us)
  • Data exposure (e.g., sensitive data returned in an API response that shouldn't be, insecure direct object references)
  • SQL injection or other injection vulnerabilities
  • Server-side request forgery (SSRF)
  • Remote code execution
  • Significant misconfigurations with a real security impact

What's out of scope

To protect the real children, families, and childcare organizations using our platform, please do not:

  • Run automated scanners, fuzzers, or load-testing tools against our production systems in a way that could degrade service for real customers
  • Attempt denial-of-service (DoS or DDoS) testing
  • Attempt social engineering against MyLittleWorld staff, contractors, or customers (e.g., phishing, pretexting, vishing)
  • Attempt physical attacks against our offices, data centers, or infrastructure providers
  • Access, modify, download, or exfiltrate real customer data beyond the minimum necessary to demonstrate a vulnerability
  • Test on behalf of, or by using the credentials of, a real customer organization without their explicit permission — instead, create your own test account where possible

Reports of missing security headers, cookie flags, or other best-practice-but-low-impact findings without a demonstrated exploit path are welcome but may be closed as informational/low priority rather than acted on immediately.

How to report

Email security@mylittleworld.ca with as much detail as you can provide, including:

  • A clear description of the vulnerability and its potential impact
  • Step-by-step reproduction instructions
  • Any proof-of-concept code, screenshots, or requests/responses that help us reproduce the issue
  • The URL(s) or endpoint(s) involved

A PGP key is not currently required to report — plain email is fine. Detailed, reproducible reports let us investigate and fix issues much faster than a report without steps to reproduce.

What to expect from us

  • Acknowledgment: We aim to acknowledge receipt of your report within 3 business days.
  • Communication: We'll keep you reasonably informed of our progress as we investigate and work toward a fix. If we need more information to reproduce the issue, we'll ask.
  • Remediation timeline: This varies depending on the severity and complexity of the issue. We prioritize critical issues (like tenant-isolation or authentication bypasses) for the fastest possible remediation.
  • Credit: We don't currently run a paid bug bounty program (see below), but if you'd like public credit for a validated finding, we're happy to acknowledge your work once the issue is resolved, with your permission.

Safe harbor

MyLittleWorld will not pursue legal action against, or report to law enforcement, a security researcher who:

  • Makes a good-faith effort to comply with this policy;
  • Reports a vulnerability to us promptly and does not publicly disclose it before we've had a reasonable opportunity to investigate and remediate it;
  • Does not access, modify, or exfiltrate real customer data beyond what is strictly necessary to demonstrate the vulnerability, and deletes any such data promptly once the report is made;
  • Does not degrade the service or availability of our platform for real customers; and
  • Otherwise acts in good faith and avoids privacy violations, destruction of data, and interruption or degradation of our services.

This safe harbor applies only to research and disclosure activity conducted in accordance with this policy. It does not apply to activity that violates the "out of scope" section above.

No bug bounty program (currently)

To be transparent: MyLittleWorld does not currently offer a paid bug bounty program. This is something we may introduce in the future as the company and program mature, but today, we cannot offer monetary rewards for reports. We can, and will, offer public credit and our genuine thanks to researchers who help us find and fix real issues, if that's something you'd like.

Questions

For questions about this policy, email security@mylittleworld.ca.

MyLittleWorld
© 2026 MyLittleWorld. Made for childcare teams.
HomeFeaturesFor FamiliesOperationsResourcesPricingAboutSecurityTrust CenterFAQPrivacyTermsContact