Product Security
NODI Vulnerability Disclosure Policy
Deutsch: Wir nehmen die Sicherheit unserer Produkte ernst, gerade weil Kinder sie nutzen. Wenn Du eine Sicherheitslücke in einem NODI-Produkt oder -Dienst entdeckst, melde sie uns bitte vertraulich an development@nodi.kids. Wir bestätigen den Eingang innerhalb von sieben Tagen, beheben bestätigte Schwachstellen so schnell wie möglich und gehen nicht rechtlich gegen Sicherheitsforschende vor, die sich an die unten beschriebenen Regeln halten. Die maßgebliche Fassung dieser Policy ist die folgende englische Version.
Version 2.0, 19.06.2026
At NODI (NoDi GmbH), the security and privacy of our customers is a top priority. We design our connected products with security in mind throughout their entire lifecycle, from development and manufacturing to deployment and end-of-life. This policy describes our security practices, what systems are in scope, how to report potential vulnerabilities, what you can expect from us, and the security support period for our products.
1. Our security commitment
We follow industry-recognized best practices for secure product development, including secure design and architecture reviews, threat modeling and risk assessment, penetration testing and independent security audits (most recently a full IT security assessment of the NODI Flip and the NODI App by Schutzwerk GmbH, April 2026), certification of the NODI Flip under the EN 18031 series and compliance with the UK PSTI Act 2022, continuous monitoring for newly disclosed vulnerabilities, and regular security updates during the defined support period.
2. Scope
This policy applies to: the NODI Flip device (firmware, hardware interfaces, Bluetooth/WiFi/LTE connectivity); the NODI App (iOS and Android); NODI backend services and APIs operated by us; and our websites nodi.kids, de.nodi.kids, uk.nodi.kids and us.nodi.kids.
Out of scope: third-party services we use but do not operate (e.g. Shopify, Stripe, Spotify, Klaviyo, Gorgias); denial-of-service testing; physical attacks against NODI offices or personnel; social engineering, spam or phishing; findings from automated scanners without a demonstrated security impact; and reports concerning missing or misconfigured HTTP response headers (e.g. Content-Security-Policy, Referrer-Policy, X-Frame-Options) without a demonstrable exploit. Please report issues in third-party services to the respective vendor.
3. How to report
Email development@nodi.kids, in English where possible, including at least: your contact information; the products and versions affected; time and date of discovery; a technical description of the potential vulnerability; proof of the exploit or vulnerability (e.g. photo, video, sample code); and any other supporting material. Anonymous reports are accepted.
4. What we commit to
- Acknowledgement within seven (7) days of receiving your report, with initial feedback on the issue.
- Status updates at least every two weeks until the issue is resolved.
- Remediation as fast as severity demands; for vulnerabilities affecting children’s data or device security we treat remediation as our highest engineering priority.
- We treat your report and your personal details confidentially and will not pass your identity to third parties without your permission, unless we are legally required to do so.
- We will inform you when the vulnerability is fixed, and, with your consent, credit you by name or handle.
- If a confirmed vulnerability poses a high-risk threat, we will promptly inform affected users.
- We comply with our statutory reporting obligations, including the reporting of actively exploited vulnerabilities and severe incidents under the EU Cyber Resilience Act once applicable, and personal data breach notification under Art. 33/34 GDPR where applicable.
5. Coordinated disclosure
Please give us a reasonable opportunity to remediate before any public disclosure. Our default coordination window is 90 days from your report, or 30 days after a fix is released, whichever is earlier. Because fixes for device vulnerabilities require an over-the-air firmware rollout to devices in the field, we may ask to keep critical vulnerabilities confidential until the patch has reached at least seventy percent of our active devices; in that case we will explain why and agree on a new date with you. We will not ask you to keep a vulnerability secret indefinitely. Fixed vulnerabilities are communicated through our software release notes.
6. Safe harbor
We will not initiate legal action, file criminal complaints, or claim damages against you for security research and reporting conducted in good faith and in accordance with this policy. Research conducted under this policy is considered authorized within the meaning of applicable computer crime provisions (including §§ 202a ff. StGB), and we waive claims based on the circumvention of technical protection measures to the extent the circumvention was necessary for good-faith research under this policy. If a third party initiates legal action against you for activity covered by this policy, we will make it known that your actions were authorized by us. The safe harbor does not apply if you violate the rules in Section 7, in particular if you access, modify, or exfiltrate data of other users.
7. Rules for researchers
Although we encourage investigation of potential security issues, we cannot tolerate any activity that may interfere with legitimate users or violate applicable computer abuse, cybersecurity and data protection regulations. You must: only test against accounts, devices, and data you own or are expressly authorized to use, never against accounts or devices of other families; stop immediately, report to us, and delete any data of other users (in particular data relating to children) that you inadvertently obtained, without copying, modifying, destroying or disclosing it; not degrade or disrupt the service (no DoS or DDoS, no resource exhaustion, no spam); not use social engineering or phishing; not publicly disclose the vulnerability before the coordination window in Section 5 has run; act in good faith, without coercion, dishonesty, or fraudulent intent; and comply with applicable law.
8. No bounty
We currently do not operate a paid bug-bounty program. Reports are voluntary; submitting a report does not create any payment claim. We deeply appreciate every responsible report and will say thank you accordingly.
9. Security update support period
We provide over-the-air (OTA) software updates to our connected products to continuously improve performance, add features, and address potential vulnerabilities. Software updates are applied automatically, with no user action required. We guarantee security updates and support for at least five (5) years from the date of purchase.
10. Changes and contact
We may update this policy from time to time; the current version with its date is published on this page. Changes do not retroactively narrow the safe harbor for reports already submitted. For questions about product security, update periods, or this policy, contact help@nodi.kids; for vulnerability reports, use development@nodi.kids.
NoDi GmbH, c/o Betahaus, Rudi-Dutschke-Straße 23, 10969 Berlin, Germany