Security at Ally
Ally holds sensitive personal notes. The security model is designed with that fact front and centre. Below is the short version; the full detail is in the security whitepaper.
Authentication
Passwordless magic-link sign-in. Tokens live 30 minutes, are single-use, and are Argon2id-hashed on the server. Optional TOTP 2FA on every account. Sessions are first-party cookies with server-side records; revocable per device from your cabinet.
Transport and storage
TLS 1.3 everywhere. AES-256 at rest on database and object storage. All hosting in the EU (Hetzner Falkenstein, Germany). Backups encrypted, 35-day rolling.
Video
Browser-to-browser end-to-end encryption via LiveKit self-hosted. Recording only with both-party in-room consent; recording stored in your cabinet under your control.
Practice
Annual independent penetration test. SOC 2 Type II audit programme in progress. Access to production data is role-based, all admin actions logged, quarterly access review. Vulnerability disclosure programme at security@allyhub.org.
Read the full whitepaper →