Security at Storywish
We respond to every security report within 3 business days. If you have found something that affects the safety of our users or their data, we want to hear from you.
In scope
storywish.ai and all subdomains
- The Storywish API at
api.storywish.ai
Out of scope
- Denial-of-service or volumetric attacks
- Social engineering of Storywish staff or contractors
- Physical attacks against Storywish facilities
- Findings from automated scanners without a working proof of concept
- Issues in third-party services we rely on (please report those to the vendor)
Safe harbor
We will not pursue legal action against researchers who follow this policy, act in good faith, and do not access data beyond what is necessary to demonstrate the issue.
How to report
Email security@storywish.ai. PGP is welcome but not required.
What to include
- A clear description of the issue
- Steps to reproduce
- Impact and any proof of concept
What we ask of you
- Do not access other users' data
- Do not degrade service for other users
- Give us a reasonable window to fix before public disclosure
Acknowledgments
We publicly thank researchers who help keep families safe on Storywish. This list is currently empty — contributions welcome.