Trust & Security

How AllyProof protects your data and maintains operational security.

Last updated: September 6, 2026

Hosting and Data Region

AllyProof’s primary application servers run in Germany. Browser collection regions depend on the selected check: California privacy checks run in California.

Primary database storage uses EU-based PostgreSQL infrastructure. Collection regions, global edge services and external processing providers are separate from the primary storage location. Review the privacy policy and applicable data-processing agreement for processing details.

Static assets and edge caching are served via a global CDN with points of presence worldwide.

Encryption and Transport Security

  • In transit: All connections use TLS 1.2 or higher, with automatic certificate renewal at the edge. HTTP Strict Transport Security (HSTS) is enforced.
  • At rest: Database storage is encrypted using AES-256. Backups are encrypted before transfer to storage.
  • API keys: Stored as SHA-256 hashes. The original key value is shown once at creation and never stored.
  • Passwords: Hashed using bcrypt by our managed authentication provider. We never store plaintext passwords.

Authentication and Session Security

  • Authentication uses a PKCE (Proof Key for Code Exchange) OAuth flow via our managed authentication provider.
  • Email/password and Google OAuth sign-in are supported.
  • Supabase manages cookie-based sessions with automatic refresh. The browser client accesses session credentials; authenticated requests are validated server-side.
  • Row Level Security (RLS) policies enforce multi-tenant data isolation at the database level — users can only access data belonging to their organization.
  • Role-based access control (RBAC) scopes owner, admin, member and guest access. All restricted actions are enforced server-side.

Data Retention and Deletion

  • Account data: Account deletion is available in settings. Retention and deletion conditions are described in the privacy policy.
  • Scan results: Retention depends on your plan and artifact type. Screenshots and retained findings can have different expiry dates.
  • Activity logs: Retained for 90 days, then automatically purged.
  • AI processing: Fix suggestions use bounded issue details and sanitized HTML examples. Other AI-assisted checks use the evidence required for their task. Provider processing and retention are governed by the applicable service terms and data-processing agreements.

Backup and Disaster Recovery

  • Database backups: Contact our team for current backup schedules and recovery arrangements during your security review.
  • Report storage: Scan reports and VPAT-based evidence drafts are stored separately from the application database in object storage.
  • Recovery time: Any contractual recovery commitment must be specified in your service agreement.
  • Recovery point: Confirm the agreed recovery scope and backup interval with our team for your deployment requirements.

Vulnerability Disclosure / Security Contact

If you discover a security vulnerability in AllyProof, please report it responsibly:

  • Email: security@allyproof.com
  • Please include a description of the vulnerability, steps to reproduce, and any relevant screenshots or logs.
  • We will acknowledge receipt within 48 hours and provide an initial assessment within 5 business days.
  • We do not pursue legal action against security researchers who act in good faith.

Incident Response Contact

For active security incidents or data breach notifications:

  • Emergency: security@allyproof.com with subject line “INCIDENT”
  • General support: support@allyproof.com
  • We will notify affected customers within 72 hours of confirming a data breach, in accordance with GDPR Article 33.

Accessibility Testing Limitations

AllyProof uses automated scanning tools (axe-core, HTML_CodeSniffer) to detect accessibility issues. It is important to understand the limitations of automated testing:

  • Automated testing covers only part of accessibility conformance. In Deque's published audit dataset, automated testing identified 57.38% of recorded accessibility issues. That is a share of issue volume, not the share of WCAG success criteria that can be fully evaluated automatically, and actual coverage varies by site.
  • Automated scans cannot evaluate subjective criteria such as whether alt text is meaningful, whether content order is logical, or whether a user experience is truly accessible.
  • A clean automated scan does not guarantee full WCAG conformance. Manual expert testing, assistive technology testing, and user testing are also necessary.
  • AllyProof exports proprietary VPAT-based DRAFT assessments, not the official ITI report form or completed ACRs. A qualified accessibility professional must complete the official report before procurement use.
  • AllyProof does not provide legal advice. Scan results should not be interpreted as a legal compliance assessment.

Browser Extension

  • Local-first by default: Quick-scans run entirely in the user's browser (axe-core executes in the page context). Results live in chrome.storage on the device and are not transmitted to AllyProof unless the user signs in and explicitly saves them.
  • Minimum permission surface: activeTab, storage, sidePanel. The manifest does not request <all_urls>; the extension cannot read background tabs or browsing history.
  • Token storage model: Access tokens live in chrome.storage.session (cleared on browser restart); refresh tokens live in chrome.storage.local. chrome.storage.sync is never used — tokens never propagate across the user's other Chrome devices.
  • No remote code execution: The extension does not load scripts from the network. All bundled JavaScript ships in the store-signed package and is reviewed by the respective store before delivery.
  • No third-party tracking: No analytics SDK, no advertising scripts, no telemetry by default. An optional opt-in telemetry switch is disabled out of the box.
  • Update channels: Chrome Web Store, Microsoft Edge Add-ons, Firefox Add-ons. Updates are signed by the respective store.

Sub-Processors

AllyProof uses a small number of vetted third-party providers to deliver the product: an EU database & authentication platform, an EU cloud infrastructure provider (Germany), a global CDN & security provider, a payment provider (Paddle.com Market Limited, our Merchant of Record), a US-based AI language-model provider (zero-retention API terms), and a US-based transactional email provider.

A complete, current list of sub-processors with vendor names and data processing terms is available on request at legal@allyproof.com. Customers with a Data Processing Agreement are notified of material sub-processor changes in advance.