Vulnerability Disclosure Policy
Last updated September 07, 2026
Anna is built by Braid Research Inc. Families trust Anna with calendars, messages, email and the details of their children's lives, so we take reports about the security of our systems seriously and we would rather hear about a problem from you than from a customer.
This page tells you how to reach us, what we will do with your report, and what we ask of you in return. Please read it before you test anything.
We do not run a paid bug bounty.
We offer no monetary reward, and we are not able to negotiate payment for a report before or after you send it. What we do offer is a real person reading what you send, a fix when the issue is real, and public credit if you would like it. If a bounty is what you are looking for, we would rather tell you plainly now than waste your time.
How to report something
Email security@hianna.ai. That address reaches our engineering team directly. Please do not report security issues through our public support address, our social accounts, or a GitHub issue, and please do not disclose the issue publicly until we have had a chance to fix it.
A report we can act on usually has:
- The URL, endpoint or app surface affected.
- What an attacker could actually do with it, in one or two sentences.
- Steps to reproduce it, in enough detail that we can follow them.
- Any screenshots, request/response captures or a short video, if they help.
- How you would like to be credited, or that you would prefer not to be.
Write to us in English if you can. One issue per email is easier for both of us to track.
What we will do
- Read what you send, and reply as quickly as we can with whether we are treating it as a valid issue.
- Keep you updated while we work on a fix, and let you know when it ships.
- Confirm your finding in writing once it is fixed, if that is useful to you.
- Not take legal action against you for research that follows this policy.
We are a small team, so we are not going to quote you a response time we cannot hold to. What we will do is read it, tell you where it stands, and not go quiet on you.
Scope
These are ours, and reports about them are welcome:
- hianna.ai — this marketing site
- app.hianna.ai — the Anna web app
- api.hianna.ai — the Anna API
- The Anna iOS and Android apps
Everything else is out of scope. That includes services we use but do not run — our email, analytics, payment and hosting providers among them — along with our social media accounts and any site that merely links to us. If you find something in a third party's product, please report it to that third party.
What we ask you not to do
Anna holds real families' private information. Testing that would be merely untidy on another product can do genuine harm here, so we ask you to stay inside these lines:
- Do not access, modify, download or keep data belonging to anyone but yourself. If you stumble into someone else's data, stop, do not save a copy, and tell us what happened.
- Do not run automated scanners, brute-force tooling or high-volume fuzzing against our systems. It degrades the service for families who depend on it, and we will block it.
- Do not attempt denial of service, or anything else that degrades or interrupts the service for other people.
- Do not use social engineering, phishing, or physical attempts against our team, our customers, or our vendors.
- Do not use a finding beyond the minimum needed to prove it exists, and do not leave any backdoor, test account or payload behind.
- Use your own test account. Set one up rather than testing against a real family's account.
- Do not make your report public, or share it with anyone else, before we have shipped a fix.
What we do not accept
We get a steady volume of reports that are the output of a public scanner with no demonstrated impact behind them. To save you the effort, we do not treat the following as vulnerabilities on their own. If you can chain one into something with real impact, show us the impact and we will absolutely look at it.
- Missing or misconfigured security headers, including CSP, HSTS, X-Frame-Options and Referrer-Policy.
- SPF, DKIM, DMARC, DNSSEC, CAA or other DNS and email configuration findings.
- TLS configuration, cipher suite or certificate findings from a public scanner.
- Clickjacking on pages with no state-changing action.
- Self-XSS, or anything that needs the victim to paste code into their own console.
- Missing rate limiting or CAPTCHA on endpoints that do not authenticate.
- Version or banner disclosure, and any report whose impact is "this software is out of date".
- Missing cookie flags on cookies that carry no session or personal data.
- User enumeration through timing or error text.
- Content spoofing or text injection with no HTML or script execution.
- Reports about hosts, domains or products that are not ours.
- Raw scanner or automated tool output pasted in without validation.
- Findings that need a rooted or jailbroken device, a physical device we hold, or an attacker who already has the victim's credentials.
- Theoretical issues with no working path to exploitation.
Safe harbour
If you make a good-faith effort to follow this policy while researching and reporting an issue to us, we will treat your research as authorised. We will not bring a legal claim against you over it, and if a third party brings one, we will make it known that your work was authorised under this policy.
Good faith means you stayed inside the scope and the rules above, you stopped as soon as you had proved the issue, you did not access or keep anyone else's data, and you gave us a reasonable chance to fix the problem before telling anyone else. Research that goes outside those lines is not covered, and nothing here limits our obligations under the law or waives any right a third party holds.
If you are not sure whether something you want to try is covered, ask us at security@hianna.ai before you try it. We would much rather answer the question.
Credit
Once a fix is live, we are happy to confirm your report in writing — what you found, when you told us, and that you handled it responsibly — so you have something you can show an employer or a client. Tell us in your first email whether that would be useful and what you need it to say.
We do not keep a public credits list on this site, so this is a private confirmation rather than a public listing. There is no payment attached to any of it, and there is no reward tier to negotiate.