Trust & Security
How AllyProof protects your data and maintains operational security.
Last updated: September 6, 2026
Hosting and Data Region
AllyProof’s primary application servers run in Germany. Browser collection regions depend on the selected check: California privacy checks run in California.
Primary database storage uses EU-based PostgreSQL infrastructure. Collection regions, global edge services and external processing providers are separate from the primary storage location. Review the privacy policy and applicable data-processing agreement for processing details.
Static assets and edge caching are served via a global CDN with points of presence worldwide.
Encryption and Transport Security
- In transit: All connections use TLS 1.2 or higher, with automatic certificate renewal at the edge. HTTP Strict Transport Security (HSTS) is enforced.
- At rest: Database storage is encrypted using AES-256. Backups are encrypted before transfer to storage.
- API keys: Stored as SHA-256 hashes. The original key value is shown once at creation and never stored.
- Passwords: Hashed using bcrypt by our managed authentication provider. We never store plaintext passwords.
Authentication and Session Security
- Authentication uses a PKCE (Proof Key for Code Exchange) OAuth flow via our managed authentication provider.
- Email/password and Google OAuth sign-in are supported.
- Supabase manages cookie-based sessions with automatic refresh. The browser client accesses session credentials; authenticated requests are validated server-side.
- Row Level Security (RLS) policies enforce multi-tenant data isolation at the database level — users can only access data belonging to their organization.
- Role-based access control (RBAC) scopes owner, admin, member and guest access. All restricted actions are enforced server-side.
Data Retention and Deletion
- Account data: Account deletion is available in settings. Retention and deletion conditions are described in the privacy policy.
- Scan results: Retention depends on your plan and artifact type. Screenshots and retained findings can have different expiry dates.
- Activity logs: Retained for 90 days, then automatically purged.
- AI processing: Fix suggestions use bounded issue details and sanitized HTML examples. Other AI-assisted checks use the evidence required for their task. Provider processing and retention are governed by the applicable service terms and data-processing agreements.
Backup and Disaster Recovery
- Database backups: Contact our team for current backup schedules and recovery arrangements during your security review.
- Report storage: Scan reports and VPAT-based evidence drafts are stored separately from the application database in object storage.
- Recovery time: Any contractual recovery commitment must be specified in your service agreement.
- Recovery point: Confirm the agreed recovery scope and backup interval with our team for your deployment requirements.
Vulnerability Disclosure / Security Contact
If you discover a security vulnerability in AllyProof, please report it responsibly:
- Email: security@allyproof.com
- Please include a description of the vulnerability, steps to reproduce, and any relevant screenshots or logs.
- We will acknowledge receipt within 48 hours and provide an initial assessment within 5 business days.
- We do not pursue legal action against security researchers who act in good faith.
Incident Response Contact
For active security incidents or data breach notifications:
- Emergency: security@allyproof.com with subject line “INCIDENT”
- General support: support@allyproof.com
- We will notify affected customers within 72 hours of confirming a data breach, in accordance with GDPR Article 33.
Accessibility Testing Limitations
AllyProof uses automated scanning tools (axe-core, HTML_CodeSniffer) to detect accessibility issues. It is important to understand the limitations of automated testing:
- Automated testing covers only part of accessibility conformance. In Deque's published audit dataset, automated testing identified 57.38% of recorded accessibility issues. That is a share of issue volume, not the share of WCAG success criteria that can be fully evaluated automatically, and actual coverage varies by site.
- Automated scans cannot evaluate subjective criteria such as whether alt text is meaningful, whether content order is logical, or whether a user experience is truly accessible.
- A clean automated scan does not guarantee full WCAG conformance. Manual expert testing, assistive technology testing, and user testing are also necessary.
- AllyProof exports proprietary VPAT-based DRAFT assessments, not the official ITI report form or completed ACRs. A qualified accessibility professional must complete the official report before procurement use.
- AllyProof does not provide legal advice. Scan results should not be interpreted as a legal compliance assessment.
Browser Extension
- Local-first by default: Quick-scans run entirely in the user's browser (axe-core executes in the page context). Results live in
chrome.storageon the device and are not transmitted to AllyProof unless the user signs in and explicitly saves them. - Minimum permission surface:
activeTab,storage,sidePanel. The manifest does not request<all_urls>; the extension cannot read background tabs or browsing history. - Token storage model: Access tokens live in
chrome.storage.session(cleared on browser restart); refresh tokens live inchrome.storage.local.chrome.storage.syncis never used — tokens never propagate across the user's other Chrome devices. - No remote code execution: The extension does not load scripts from the network. All bundled JavaScript ships in the store-signed package and is reviewed by the respective store before delivery.
- No third-party tracking: No analytics SDK, no advertising scripts, no telemetry by default. An optional opt-in telemetry switch is disabled out of the box.
- Update channels: Chrome Web Store, Microsoft Edge Add-ons, Firefox Add-ons. Updates are signed by the respective store.
Sub-Processors
AllyProof uses a small number of vetted third-party providers to deliver the product: an EU database & authentication platform, an EU cloud infrastructure provider (Germany), a global CDN & security provider, a payment provider (Paddle.com Market Limited, our Merchant of Record), a US-based AI language-model provider (zero-retention API terms), and a US-based transactional email provider.
A complete, current list of sub-processors with vendor names and data processing terms is available on request at legal@allyproof.com. Customers with a Data Processing Agreement are notified of material sub-processor changes in advance.