We take security extremely seriously, especially since Me is designed for children.
Me is designed with child safety as the top priority:
-
No internet access: Programs cannot make network requests
-
No file system access: Programs cannot read or write files
-
No code execution: Cannot execute arbitrary system commands
-
Sandboxed environment: All code runs in a safe, isolated sandbox
-
No data collection: We never collect any data from users
-
Navigate to Report a Vulnerability
-
Click “Report a vulnerability”
-
Complete the form with as much detail as possible
Important: Do not report security vulnerabilities through public GitHub issues.
We treat the following as highest priority:
-
Sandbox escapes: Any way to break out of the safe environment
-
Network access bypass: Any way to make network requests
-
File system access: Any way to read or write files
-
Code injection: Any way to execute arbitrary code
-
Data leakage: Any way to collect or transmit user data
Given the child safety implications:
| Stage | Timeframe |
|---|---|
Initial Response |
24 hours |
Triage |
48 hours |
Resolution |
As fast as possible |
If you conduct security research in accordance with this policy:
-
We will not initiate legal action against you
-
We will not report your activity to law enforcement
-
We will work with you in good faith to resolve issues
Keeping children safe while they learn to code is our top priority.
Last updated: 2025