Trust Center
Last updated: July 2026
Controls first, certificates on the roadmap. We are an early-stage company and we do not yet hold SOC 2 or ISO 27001 certificates. What we can show you is better than a badge: the controls we actually run, documented openly on this page. Our internal security programme is aligned to those frameworks, and we intend to pursue formal certification as the company grows. If a claim isn't on this page, we don't make it.
Why families can trust allme.life
allme.life is built on a simple principle: your family's data belongs to your family — not to us, not to advertisers, and not to AI training pipelines. Our architecture is designed so that trust doesn't depend on our promises: end-to-end encryption means we mathematically cannot read your protected content, and every access by our AI features is time-limited, purpose-bound, and receipted.
Security & privacy controls
🔒 Data Privacy
- Zero-knowledge end-to-end encryption for protected content — we cannot read it (coverage is expanding content-type by content-type, and we say precisely which)
- Data minimisation: we collect only what the service needs
- Zero cookies and zero third-party tracking, on this website and in the product
- Your data is never sold and never used to train third-party AI models
- Full UK/EU GDPR rights: access, rectification, erasure, portability
🛡️ Product Security
- Zero-knowledge SRP-6a authentication — your password never leaves your device, and SRP is the only registration path
- Modern authenticated encryption at rest (ChaCha20-Poly1305) with X25519 key exchange and per-user key isolation
- Multi-device encrypted key sync; hardware security key (FIDO2/WebAuthn) support for key protection
- Post-quantum readiness: hybrid ML-KEM (Kyber) key exchange in active development — not yet shipped, and we won't claim it until it is
- Sealed AI processing: AI features decrypt inside short, time-limited windows, followed by deletion — each access produces an audit receipt
🌐 Infrastructure
- Primary hosting in EU data centres (Germany), with UK/EU data residency by default
- Two-layer firewalling: provider edge firewall plus host-level default-deny rules
- Databases, object storage and AI services are never exposed to the internet — reachable only over an encrypted private mesh (WireGuard)
- TLS 1.2+ for all data in transit; hardened SSH (key-only authentication, root password login disabled, non-standard port, fail2ban brute-force protection)
- Self-hosted AI inference on our own GPU infrastructure by default
🔧 Application Security
- All code changes go through pull-request review and automated CI checks
- Automated secret scanning blocks credentials from entering the codebase
- Audit receipts recording every AI access to protected data
- Infrastructure security audit completed July 2026 (external port scan + configuration review) — all internal services confirmed unreachable from the internet
🔑 Access Control
- Least-privilege access: staff access to production is restricted and individually credentialled
- Key-only SSH access to servers — no password logins
- Firewalled administrative interfaces, reachable only over our private mesh
- Per-environment credentials — development and production are separated
📋 Organisational
- Responsible disclosure policy — see security.txt
- Personal data breach notification to affected users and the ICO within 72 hours
- Data Processing Agreement available — see our DPA
- Incident record & review (IRR) practice: every operational incident gets a written record and review
Compliance posture
We believe in being precise about the difference between complying with a law, aligning with a framework, and holding a certificate. Here is exactly where we stand:
| Framework / Regulation | Status | What that means |
|---|---|---|
| UK GDPR & EU GDPR | Compliant by design | Lawful bases documented, data-subject rights supported, breach process in place, DPA available. See our Privacy Policy. |
| CCPA (California) | Aligned | We honour CCPA rights for California residents. We do not sell personal information. |
| UK Age Appropriate Design Code | Designed in | Family accounts with child members are being built with enhanced protections from the start. |
| CIS Controls v8 | Adopting | Our chosen technical foundation: an Implementation Group 1 baseline programme is underway, chosen deliberately as the substance beneath any future certificate. |
| Cyber Essentials (UK) | Planned | Planned as our first formal external attestation, following the CIS baseline work. |
| SOC 2 | Roadmap | Internal controls are being documented against the Trust Services Criteria. Planned sequence: Type I report first, then the Type II observation period. No report exists yet. |
| ISO 27001 / ISO 27701 | Roadmap | Our security and privacy programme is structured with ISO 27001 (security) and ISO 27701 (privacy) in mind. No certificates held yet. |
Sub-processors
We keep our list of third-party processors deliberately short. Where a third party touches personal data, it is listed here:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (SES) | Transactional email delivery only | EU (Ireland, eu-west-1) |
| Hetzner Online GmbH | Server and GPU infrastructure | Germany |
| Contabo GmbH | Server infrastructure | Germany |
Connected accounts: if you choose to connect Google or Microsoft accounts (email, calendar, drive), data flows under your own OAuth authorisation and those providers' terms — you can disconnect at any time. AI processing: our default is self-hosted inference on our own infrastructure. During the beta, some AI features may use a disclosed cloud AI provider; we are consolidating all AI processing onto self-hosted models and reviewing every provider's data-handling terms as part of that work. We will update this list before adding any new sub-processor.
Data residency & retention
- Customer data is stored in the EU (Germany), serving a UK/EU customer base.
- Encrypted user data is retained for the life of your account and deleted within 30 days of account closure.
- Website analytics are self-hosted, anonymised, and cookie-free; security logs holding IP addresses are erased after 30 days.
Report a vulnerability
We welcome good-faith security research. If you believe you've found a vulnerability, please contact us via the details in our security.txt or email security@allme.life. We commit to acknowledging reports promptly and will not pursue legal action against good-faith research.
Documents & questions
- Data Processing Agreement (DPA)
- Privacy Policy
- Terms of Service
- security.txt (responsible disclosure)
Security questionnaire to fill in, or a question this page doesn't answer? Email privacy@allme.life — a human will reply.