Storypark Group Security Disclosure Policy

Last updated: 21 September 2026

Storypark Group is committed to the security of the information entrusted to us by early childhood services and the families they work with. This Policy explains how to report a security vulnerability to us, and sets out the conditions under which we accept such reports.

In this Policy, Storypark Group has the meaning given in the Storypark Privacy Policy. By accessing or using our Products and Services, you acknowledge that you have read and understood this Policy.

Nothing in this Policy limits the obligations imposed on Customers and users under the applicable Customer Terms, End User Terms or AI Terms.

1. Reporting a Vulnerability

If you believe you have identified a security vulnerability in our Products and Services, please report it to us at security@storypark.com. Sensitive detail should be encrypted using the PGP key published at https://app.storypark.com/security-pgp-key.txt

Please include sufficient detail for us to reproduce the issue, and allow us a reasonable opportunity to respond before disclosing it to any third party. We will acknowledge your report and keep you informed of our progress.

We are grateful for reports made in good faith. Our Products and Services hold information about young children and their families, and we treat that responsibility accordingly.

2. Security Testing Is Not Authorised

Storypark Group does not authorise security testing of its Products and Services. This includes:

  • penetration testing;
  • vulnerability scanning and automated crawling;
  • fuzzing or the submission of deliberately malformed input; and
  • probing of authentication, authorisation, rate limiting or any other security control.

This restriction is contractual. The applicable Customer Terms provide that Customers and Authorised Users must not conduct penetration testing without Storypark Group's prior written consent (clause 4.1), and must not interfere with, disrupt, test, probe, circumvent or compromise the security, integrity, availability or functionality of the Products and Services or any connected systems or networks (clause 4.3(j)). The same restriction applies under the Storypark Assist supplementary terms.

Creating a trial account for the purpose of testing our Products and Services is subject to these provisions. Describing your activity as authorised, or as a test, does not constitute authorisation.

If you wish to conduct testing, contact security@storypark.com and obtain our prior written consent. We will confirm what is in scope and when testing may take place.

Our Products and Services are used by early childhood services during their working day. Testing against production risks sending communications to families, altering records relating to children, and disrupting a service that educators depend on. Those consequences fall on our Customers.

3. We Do Not Pay for Reports

Storypark Group does not operate a bug bounty programme and does not pay for vulnerability reports, whether solicited or unsolicited. We will not enter into payment negotiations, and we will not meet an invoice or fee request submitted with a report.

We will nonetheless read your report, act on it where it is valid, and acknowledge your contribution.

Security professionals seeking commercial engagement with Storypark Group are welcome to contact us directly.

4. Good Faith

Where you identify an issue incidentally, without conducting testing, without accessing information belonging to other people, and without disrupting our Products and Services, and you report it promptly and privately to security@storypark.com, Storypark Group will not pursue action against you in respect of that report.

This does not extend to:

  • testing conducted without our prior written consent;
  • accessing, copying or retaining information belonging to other people;
  • any act that disrupts or degrades our Products and Services; or
  • withholding a report, in whole or in part, pending payment.

5. Scope

This Policy applies to all Storypark Group Products and Services, including our web applications, application programming interfaces, mobile applications, media and file storage, and the supporting infrastructure on which they operate.

6. Contact Us

Security Team

security@storypark.com