← Baby PhD中文 · EN

网站安全与数据保护

最近更新:2026-07-21

Baby PhD CASI 采用分层方式保护评估、报告和支付访问。以下内容是当前公开的安全原则,不披露密钥、内部凭据或可被滥用的防护细节。

1. 访问与支付

  • CASI 深度评估报告访问由服务器端购买授权验证控制,不依赖公共共享密码。
  • 支付凭据由 PayPal、支付宝等支付服务商处理;Baby PhD 不直接保存完整卡号或支付账户密码。
  • 退款、撤权或无效授权可使相关评估访问失效。

2. 报告与个人信息

  • 报告读取使用受签名会话和服务器端授权。
  • 报告相关页面使用 no-store / no-referrer 等缓存与引用限制。
  • 邮箱等必要联系信息在后端采用散列或加密方式用于匹配和服务交付。
  • 测试、Sandbox 与生产研究数据通过数据环境字段和排除标记进行隔离。

3. 网站安全响应头

网站部署包括 HTTPS/HSTS、禁止 iframe 嵌入、MIME 嗅探保护、Referrer Policy、Permissions Policy、Content Security Policy 等浏览器安全控制。由于支付组件和现有内联页面代码的兼容性,CSP 仍允许受限的内联脚本/样式,并只开放必要的支付与表单来源;后续版本会继续减少此范围。

4. 最小权限与数据最小化

生产数据库不向公共浏览器开放管理权限。敏感后台操作通过服务端环境变量和受限接口完成。CASI 不要求提交儿童真实姓名、照片、语音、学校或精确家庭地址。

5. 安全事件与漏洞报告

如发现可能影响 Baby PhD 网站、支付、评估或报告安全的问题,请发送至 privacy@babyphdsafety.com,主题写“Security Report”。请不要在公开渠道披露可利用细节,也不要访问、下载或修改不属于你的数据。

6. 责任边界

任何互联网服务都无法保证绝对安全。我们会持续修复已知问题、减少不必要的数据处理,并在适用法律要求下处理安全事件和通知义务。

Website Security & Data Protection

Last updated: 2026-07-21

Baby PhD CASI uses layered controls to protect assessment access, reports, and payment-related workflows. This page describes public security principles without exposing secrets, internal credentials, or exploitable defense details.

1. Access and payments

  • Full-report access is controlled by server-side purchase entitlement checks rather than a shared public password.
  • Payment credentials are handled by providers such as PayPal and Alipay. Baby PhD does not directly store full card numbers or payment-account passwords.
  • Refunded, revoked, or invalid entitlements can lose related assessment access.

2. Reports and personal information

  • Report access uses signed sessions and server-side authorization.
  • Report-related pages use no-store / no-referrer controls where applicable.
  • Necessary contact identifiers such as email are hashed or encrypted in backend workflows used for matching and service delivery.
  • Test/Sandbox and production research data are separated using environment provenance and analytics-exclusion controls.

3. Browser security headers

The deployment includes HTTPS/HSTS, anti-framing controls, MIME-sniffing protection, Referrer Policy, Permissions Policy, and Content Security Policy controls. For compatibility with payment components and existing inline page code, the CSP still permits limited inline scripts/styles and only the external payment/form origins needed by current workflows; future versions will continue to narrow this surface.

4. Least privilege and data minimization

The production database does not expose public browser-level administrative access. Sensitive backend operations use server-side environment secrets and restricted endpoints. CASI does not require a child’s real name, photo, voice, school, or precise home address.

5. Security incidents and vulnerability reports

To report a potential security issue affecting the Baby PhD website, payments, assessments, or reports, email privacy@babyphdsafety.com with the subject “Security Report”. Please do not publicly disclose exploitable details and do not access, download, or alter data that does not belong to you.

6. Limits

No internet service can guarantee absolute security. We continue to remediate known issues, minimize unnecessary data processing, and handle incident-response or notification obligations where required by applicable law.

PrivacyChildrenData RightsCookies