Security & Incident Response Plan

Last updated: July 9, 2026

Effective Date: July 9, 2026

At Ease Parent handles sensitive family coordination details, including household information, child-related notes, caregiver access, pickup details, handoffs, and emergency contacts. This plan explains how we protect user data and respond to suspected security incidents.

1. Security Principles

  • Protect family care information with care
  • Limit access to the people who need it
  • Use role-based permissions
  • Minimize sensitive data in emails, logs, and notifications
  • Secure data in transit and, where available, at rest
  • Review vendors before they process user data
  • Monitor for unauthorized access and suspicious activity
  • Prepare for incidents before they happen
  • Communicate clearly if something goes wrong
  • Never promise perfect security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. No app or digital service can guarantee complete security.

2. Security Controls

Account Security: Secure authentication, strong password requirements, password reset process, session expiration where appropriate, optional multi-factor authentication, and suspicious login monitoring.

Data Security: Encryption in transit, encryption at rest where supported, secure database configuration, access controls for admin users, principle of least privilege, and secure, access-restricted backups.

Permission Security: Role-based permissions, household admin controls, assigned-child-only access, temporary access expiration, helper access removal, permission audit logs, and regular permission review prompts.

Email and Notification Security: Avoiding sensitive child details in email subject lines and push notification previews, secure app links, confirming email links route to the correct app, and testing weekly readiness email links.

Logging Security: Avoiding logging sensitive child, health, allergy, emergency, or pickup details, restricting access to logs, retaining logs only as long as needed, and reviewing logs during incidents.

Vendor Security: Maintaining a vendor register, reviewing vendor privacy/security documentation, confirming deletion support, confirming child data is not used for behavioral advertising, reviewing SDKs before adding them, and updating Apple/Google disclosures when vendors change.

3. Internal Access Controls

Only authorized team members may access user data, based on job need. Admin access is reviewed regularly and removed promptly when no longer needed. Support access is limited to what is needed to resolve an issue. Sensitive family details are not copied into external tools unless necessary and approved, and child-related information is treated as confidential.

4. Security Incident Definition

A security incident may include unauthorized account or household access, misconfigured permissions, exposed child-related or caregiver information, incorrect email routing, exposed database or storage, lost or stolen admin credentials, a vendor breach affecting At Ease Parent data, malware, phishing, or account takeover, incorrect app store disclosures affecting user trust, unauthorized access to logs or backups, or public exposure of private files, links, or attachments.

5. Incident Severity Levels

Severity 1 (Critical): confirmed unauthorized access to child-related information, database exposure, compromised admin account, large-scale account access issue, or vendor breach — immediate escalation.

Severity 2 (High): limited unauthorized household access, wrong caregiver access to a child profile, incorrect email routing, sensitive data in logs or notifications, or repeated suspicious logins — same-day investigation and containment.

Severity 3 (Medium): non-sensitive routing issues, incorrect notification copy, minor permission bugs with no confirmed data exposure — investigated within 1–3 business days.

Severity 4 (Low): documentation mismatches or minor internal process gaps with no confirmed user impact — addressed during regular governance review.

6. Incident Response Process

Identify: document when and how the issue was discovered, what happened, systems and data involved, and whether child-related information may be affected.

Contain: disable affected features, revoke compromised credentials, remove incorrect access, pause automations, rotate keys, or restrict vendor access as needed.

Investigate: determine root cause, timeline, scope, data and users affected, and whether app store disclosures or the Privacy Policy are implicated.

Remediate: patch the issue, correct permissions, update routes or links, rotate credentials, update vendor settings or policies, and add safeguards to prevent recurrence.

Notify: legal counsel determines whether notification is required to affected users, household admins, caregivers, vendors, regulators, app stores, or law enforcement.

Document: a full incident record is created, including summary, timeline, data and users affected, root cause, containment and remediation actions, notifications sent, and follow-up owner.

Review: after closure, we conduct a post-incident review to identify what needs to change, which policies need updating, and which vendors need review.

7. Security Review Cadence

At Ease Parent conducts security and governance reviews before launch, before Apple or Google Play submission, when a new vendor or SDK is added, when new child-related fields are added, when payment or store features launch, after any security incident, and at least quarterly during early growth (annually thereafter).

8. Reporting a Security Concern

Found a security vulnerability or suspect a security incident? Please report it responsibly to hello@ateaseparent.com. We aim to acknowledge reports promptly and investigate every report we receive.

Contact Us

At Ease Parent LLC
Email: hello@ateaseparent.com
Mailing Address: 9783 E 116th Street #A492 Fishers, IN 46037-2822 United States
Website: www.ateaseparent.com