# Usalama Misuse Prevention Plan

**Plan date:** June 13, 2026  
**Applies to:** Parent-child MVP, closed pilot, and production planning  
**Status:** Required release gate  
**Safety boundary:** Usalama helps children alert trusted adults faster during high-stress situations. It does not guarantee delivery, response, rescue, or safety, and it does not replace `911`, emergency services, law enforcement, direct adult supervision, or professional monitoring.

## Purpose

Usalama handles child identity, trusted-adult access, emergency alerts, and a child's location during an incident. Misuse prevention is a product requirement, not a policy appendix.

No parent-child pilot should begin until the closed-pilot controls below are implemented, tested, documented, and reviewed by legal, privacy, child-safety, and security owners.

## Pilot Minimum Safety Layer

Before real parent-child pilot use, Usalama requires:

1. Parent or guardian consent.
2. Child data minimization.
3. Clear emergency disclaimer.
4. Attorney-reviewed Privacy Policy.
5. Attorney-reviewed Terms of Use.
6. Data access, export, correction, and deletion request process.
7. No real `911`, police, law-enforcement, or rescue claim unless formally integrated and legally approved.
8. Verified Safety Circle contacts with opt-in and rapid revoke.
9. Abuse-prevention controls for stalking, coercive control, ex-partner misuse, and custody disputes.
10. Pilot waiver confirming beta software limits and no guaranteed emergency response.

Approved public positioning:

> Usalama helps children alert trusted adults faster during high-stress situations.

Do not market Usalama as “this will save your child,” “prevents harm,” “prevents kidnapping,” “guarantees rescue,” or any equivalent safety guarantee.

## Hacking Safeguards Audit

| Risk | Required control | Current status | Current evidence | Pilot requirement |
| --- | --- | --- | --- | --- |
| Account takeover | MFA for parents | Missing | Demo has only an optional local device-verification exploration | Use a production auth provider with parent MFA or passkeys, secure recovery, login alerts, and session review |
| Fake guardian added | Verified guardian invites | Missing | Demo contacts are local and labeled as demo accepted | Require verified invite, explicit acceptance, parent approval, role assignment, and immediate revoke |
| Unauthorized location access | Role-based permissions | Missing | Demo pin appears only inside the local incident modal | Enforce server-side roles, incident-only location authorization, short retention, and access logs |
| Admin abuse | Admin audit logs | Missing | No production admin surface exists | Record every sensitive admin action, actor, target, reason, timestamp, and device or session context |
| Stolen child device | Device binding and parent revoke | Missing | PWA has no parent-controlled linked-device model | Bind child sessions to registered devices, support parent revoke, rotate tokens, and alert on new-device registration |
| API abuse | Rate limiting and anomaly detection | Partial demo | Incident idempotency keys exist; no production rate limits or anomaly review | Add per-account, per-device, and per-IP limits, duplicate suppression, abuse alerts, and operational review |
| Data breach | Encryption at rest and in transit | Partial | Netlify serves HTTPS; demo data is not a production encrypted datastore | Use encrypted managed storage, HTTPS everywhere, managed secrets, key rotation, backups, and tested restore procedures |
| Password exposure | Passwordless or strong auth provider | Missing | No parent authentication exists | Prefer passkeys or passwordless login; otherwise use a mature auth provider with strong password policy and MFA |
| Vendor leak | Vendor data-processing agreements | Missing | No production SMS, push, maps, or analytics vendors are approved | Maintain a public-facing vendor list, execute DPAs, minimize shared data, and review cross-border processing |
| Insider misuse | Least-privilege access | Missing | No production roles or support tooling exist | Separate support, engineering, and admin roles; log access; require reason codes; perform recurring access review |

## Incorrect Usage Safeguards Audit

| Misuse scenario | Required control | Current status | Current evidence | Pilot requirement |
| --- | --- | --- | --- | --- |
| Controlling parent uses app abusively | Child-visible emergency sharing status | Partial demo | Permissions dashboard explains the one-time emergency pin | Show the child when location is requested, who can access it, when access ends, and how to seek help |
| Custody dispute | Guardian verification and dispute policy | Missing | No parent or guardian identity model exists | Define verification, access suspension, court-order handling, support escalation, and account-review process |
| Fake emergency alerts | Cancel window and incident classification | Partial demo | Three-second hold and configurable cancel window exist | Add test versus live classification, duplicate suppression, false-alert review, and abuse-response thresholds |
| Parent expects guaranteed rescue | Clear terms and emergency disclaimer | Partial | Roadmap and documents state the boundary; in-app copy needs a persistent parent-facing version | Add counsel-approved onboarding, incident-screen, terms, and help-center language |
| Child presses accidentally | Three-second hold and cancel flow | Implemented demo | SOS requires a three-second hold and then opens a cancel window | Test timing with children, accessibility tools, stress conditions, and different devices |
| Guardian over-access | Time-limited permissions | Missing | No production guardian roles exist | Limit location access to active incidents, expire access after resolution, support revoke, and record every view |
| Someone tries to stalk a child | No public child search and no public live-location links | Partial | Demo has no child search; map link exists only in the local incident modal | Keep child profiles private, forbid search-by-child, use authenticated incident views, and never create public share links |
| Ex-partner or unauthorized adult attempts access | Verified guardian authority, invitation acceptance, access logs, and dispute workflow | Missing | No production identity or custody review model exists | Require parent authority verification, suspicious invite review, rapid revoke, and support escalation for coercive-control or custody concerns |

## Non-Negotiable Product Rules

- No continuous tracking.
- No route history.
- No public child profiles.
- No search-by-child feature.
- No public live-location links.
- No open adult-to-child chat.
- No hidden camera, microphone, or location collection.
- Optional emergency audio context must be explicit, off by default, short, incident-scoped, and captured only after SOS dispatch begins.
- No sale of child data.
- No targeted advertising using child data.
- No claim that Usalama saves children, prevents harm, guarantees rescue, or replaces `911`.
- No production launch without verified guardian access and a rapid revoke process.

## Required Access Model

| Role | Allowed | Not allowed |
| --- | --- | --- |
| Parent account owner | Create child profile, approve Safety Circle, revoke access, resolve incident, request deletion, review access logs | Secretly enable continuous tracking or grant public location access |
| Child | Trigger SOS, see emergency-sharing status, use test mode, understand who receives alerts | Add guardians, expose public location, or silently disable parent-required account protections |
| Safety Circle guardian | Receive approved alerts, view an active incident pin for a limited period, call child or emergency services when appropriate | Browse child history, view location outside an incident, invite other guardians, or privately message the child |
| Support staff | Handle documented account and safety escalations using least privilege | Browse child location without an approved case, alter logs, or grant guardian access |
| Security administrator | Review incidents and security events needed for response | Use standing access to child location without a documented security purpose |

## Location Access Rules

1. SOS dispatch begins first.
2. Usalama requests one current position.
3. The location is attached only to the active incident.
4. Only approved, authenticated incident participants can access it.
5. Every location view creates an access-log event.
6. Resolution expires guardian access and starts the retention countdown.
7. The parent can review access logs and request deletion subject to documented legal exceptions.

## Abuse Response Workflow

| Trigger | Immediate action | Owner | Required record |
| --- | --- | --- | --- |
| Suspected account takeover | Lock sensitive changes, revoke sessions, notify parent, start recovery | Security and support | Security incident and audit events |
| Custody or guardian-access dispute | Suspend disputed access, preserve minimal logs, escalate for policy review | Trained support and legal | Dispute case, evidence received, access decision |
| Stalking or coercive-control report | Rapid revoke, limit account changes, provide support path, escalate urgently | Safety support | Safety case with restricted visibility |
| Repeated fake alerts | Separate accidental-use coaching from deliberate abuse; rate-limit when necessary | Support and trust owner | Incident classifications and actions |
| Vendor breach | Disable affected integration where feasible, assess exposure, notify according to law and contract | Security, legal, and vendor owner | Incident timeline, affected data, remediation |
| Insider-access anomaly | Suspend access, preserve immutable logs, investigate | Security and legal | Admin audit records and investigation file |

## Required Records

Store the minimum needed to protect users and investigate misuse:

- Consent event: actor, child, policy version, timestamp.
- Guardian invite: inviter, recipient, role, acceptance, revocation.
- Registered device: owner, device identifier, session state, last seen, revoked time.
- Incident: child, classification, start, resolution, expiry.
- Location access: actor, role, incident, timestamp, session, reason or trigger.
- Admin audit: staff actor, action, target, reason code, timestamp.
- Abuse case: case type, actions, owner, review status, restricted notes.

Apply short retention by default. Document any legal hold or safety exception.

## Release Gates

### Investor demo

- Keep the demo clearly labeled as simulated.
- Keep emergency location fail-open and one-time only.
- Keep child search, public links, and chat absent.
- Document missing production controls honestly.

### Closed pilot

- Parent MFA or passkeys.
- Verified guardian invites, roles, and revoke.
- Registered child devices and parent-controlled revoke.
- Authenticated incident views with no public location link.
- Location-access logs and admin audit logs.
- Server-side rate limits, idempotency, and anomaly alerts.
- Encrypted managed storage and approved vendor DPAs.
- Custody-dispute and coercive-control support policies.
- Counsel-approved disclaimer and terms.
- Security, privacy, child-safety, and abuse-response review.

### Production launch

- External penetration test.
- Incident-response exercise.
- Vendor-risk review.
- Access-review cadence and immutable audit retention.
- Monitored abuse metrics and named operational owners.
- Staged rollout with rapid rollback and support coverage.

## Metrics

- Account-takeover reports.
- New-device alerts and revocations.
- Guardian invites, acceptance rate, and revocations.
- Location views per incident and suspicious-view rate.
- False-alert, cancellation, and repeat-alert rates.
- API rate-limit events and anomaly investigations.
- Support cases for stalking, coercion, and custody disputes.
- Admin-access reviews and policy exceptions.
- Vendor incidents and response time.

## Current Verdict

The live demo already proves a deliberate SOS hold, a cancel window, one-time emergency location, no constant tracking, idempotent incident creation, and the absence of public child discovery and chat.

It is not ready for a parent-child pilot. The critical missing safeguards are parent MFA, verified guardian invitations, role-based access, registered child devices with revoke, authenticated incident views, rate limiting, location-access logs, admin audit logs, approved vendor agreements, and abuse-response policies.
