Last updated: 21 September 2026
Storypark Group is committed to the security of the information entrusted to us by early childhood services and the families they work with. This Policy explains how to report a security vulnerability to us, and sets out the conditions under which we accept such reports.
In this Policy, Storypark Group has the meaning given in the Storypark Privacy Policy. By accessing or using our Products and Services, you acknowledge that you have read and understood this Policy.
Nothing in this Policy limits the obligations imposed on Customers and users under the applicable Customer Terms, End User Terms or AI Terms.
If you believe you have identified a security vulnerability in our Products and Services, please report it to us at security@storypark.com. Sensitive detail should be encrypted using the PGP key published at https://app.storypark.com/security-pgp-key.txt
Please include sufficient detail for us to reproduce the issue, and allow us a reasonable opportunity to respond before disclosing it to any third party. We will acknowledge your report and keep you informed of our progress.
We are grateful for reports made in good faith. Our Products and Services hold information about young children and their families, and we treat that responsibility accordingly.
Storypark Group does not authorise security testing of its Products and Services. This includes:
This restriction is contractual. The applicable Customer Terms provide that Customers and Authorised Users must not conduct penetration testing without Storypark Group's prior written consent (clause 4.1), and must not interfere with, disrupt, test, probe, circumvent or compromise the security, integrity, availability or functionality of the Products and Services or any connected systems or networks (clause 4.3(j)). The same restriction applies under the Storypark Assist supplementary terms.
Creating a trial account for the purpose of testing our Products and Services is subject to these provisions. Describing your activity as authorised, or as a test, does not constitute authorisation.
If you wish to conduct testing, contact security@storypark.com and obtain our prior written consent. We will confirm what is in scope and when testing may take place.
Our Products and Services are used by early childhood services during their working day. Testing against production risks sending communications to families, altering records relating to children, and disrupting a service that educators depend on. Those consequences fall on our Customers.
Storypark Group does not operate a bug bounty programme and does not pay for vulnerability reports, whether solicited or unsolicited. We will not enter into payment negotiations, and we will not meet an invoice or fee request submitted with a report.
We will nonetheless read your report, act on it where it is valid, and acknowledge your contribution.
Security professionals seeking commercial engagement with Storypark Group are welcome to contact us directly.
Where you identify an issue incidentally, without conducting testing, without accessing information belonging to other people, and without disrupting our Products and Services, and you report it promptly and privately to security@storypark.com, Storypark Group will not pursue action against you in respect of that report.
This does not extend to:
This Policy applies to all Storypark Group Products and Services, including our web applications, application programming interfaces, mobile applications, media and file storage, and the supporting infrastructure on which they operate.