What Bubaly may do, what it asks, and what we can prove
An assistant that acts for your family has to earn that. This page says exactly what is verified today, what is in place, what we inherit from our infrastructure providers, and what is still planned.
Privacy by Design
Every feature is built to expose as little as possible and to keep you in control.
Encrypted in transit and at rest
TLS for every connection and encryption at rest on our database and storage providers.
You're in control
Roles and permissions per member, and your data available or deleted on request.
Transparent & Accountable
Clear policies, a labelled evidence list, and a security team you can reach anytime.
Trust Center
How the assistant is allowed to act
- 1
It handles on its own only the routine work allowed in Settings → Bubaly AI. Every area has a dial — Recommend, Prepare or Execute — and you can turn any area down to Recommend at any time.
- 2
These areas always wait for a parent's OK, whatever the dial says:
- Money: Finances, Banking
- Health: Medical, Dental, Vision, Mental Health
- Documents: Insurance, Passports, Documents
- Safety: Driving, Emergency
- 3
Every run keeps a step-by-step timeline; partly finished work is reported as partly finished.
- 4
Quiet hours silence it, and every decision it makes is written to your family's trust ledger.
- 5
Model-call telemetry records which task ran, which model answered, how many tokens and how long — never the text of your family's data. What you asked stays inside your family's own records.
- 6
Your family's data is never used to train models.
Who can do what by default
| Role | What the assistant may do |
|---|---|
| Parent | Bubaly may act for this role |
| Adult | Bubaly may act for this role |
| Teen | A parent reviews actions for this role |
| Child | A parent reviews actions for this role |
| Caregiver | A parent reviews actions for this role |
| Guest | A parent reviews actions for this role |
Health records are family-scoped and encrypted like everything else.
Verified, in place, inherited, or still planned
We show a badge only for what we can prove. Everything else is labelled for what it is.
- Verified in the product
- Enforced in code and covered by automated tests that run on every change.
- In place
- We do this today; evidence is published as it matures.
- Provider-inherited
- Held by the infrastructure we run on, not yet audited for Bubaly itself.
- Planned
- On the roadmap. No badge until it's done.
- Verified in the product
Row-level security on every family table
Evidence
tests/rls-isolation-sweep.test.tstests/tenant-isolation-rls.test.tstests/sql-security-contract.test.ts
- Verified in the product
Append-only decision ledger, written by the server
Evidence
tests/0260-trust-ledger-lockdown.test.ts
- Verified in the product
Money, health and documents always ask a parent
Evidence
tests/trust-engine.test.tstests/tool-risk.test.tstests/assistant-trust-wrapper.test.tstests/marketing-trust-ledger.test.ts
- Verified in the product
Approvals expire instead of lingering
Evidence
tests/approval-expiry.test.ts
- Verified in the product
Content Security Policy on every page
Evidence
tests/csp-header.test.tstests/e2e/csp.spec.ts
- In place
Audit log of significant actions
- In place
Export or delete your family's data on request
- In place
Your family's data never trains a model
- Provider-inherited
Encrypted in transit
- Provider-inherited
Encrypted at rest
- Provider-inherited
SOC 2 and ISO 27001 at our hosting providers
- Planned
Independent SOC 2 audit of Bubaly itself
- Planned
Third-party penetration test report
- Planned
Public bug bounty programme
- Planned
Public status page and uptime history
- Planned
Choice of data region
Last reviewed:
Defense in Depth
Security at Every Layer
Four layers stand between a threat and your family's data. Each one is listed on the ledger above for what it is.
Transport security
Every connection is encrypted with TLS, and an HSTS header tells browsers never to use plain HTTP.
Authorization
Row-level security policies on every family table mean a member only ever reads the rows their family owns. Roles start least-privilege and a parent widens them.
Data at rest
Our database and storage providers encrypt data at rest. Documents are private and served only through short-lived signed URLs.
Backup and recovery
Backups and point-in-time recovery are provided by our database provider.
Data Sovereignty
Your Data, Your Region
Today all family data is hosted in one region on infrastructure that holds SOC 2 and ISO 27001 reports; choosing your own region is planned.
Choice of data regionYour Data, Your Rules
You Have Full Control
Features built into every Bubaly account, not promises.
Granular access controls
Six roles, from parent to guest. Parents decide what children can see and do; caregivers and guests see only what they are given.
Export or delete on request
Ask us for a copy of your family's data. Delete individual items or a member's profile in the app, or ask us to delete your whole account.
No ads, no data sales
We don't show ads and we don't sell your family's data. Subscriptions pay for Bubaly.
A ledger of what the assistant did
Every assistant decision is written to your family's trust ledger, and significant actions are logged on the server.
Incident Response
When It Matters Most
Our incident response protocol is battle-tested and designed for speed, transparency, and accountability.
This is our policy, not a certification.
1
Detection
Monitoring and alerting on our infrastructure flag anomalies to the on-call engineer.
2
Assessment
We assess severity and scope, and begin containment.
3
Notification
Affected families are notified within 24 hours, with clear details and recommended actions.
4
Resolution
Root-cause analysis, remediation, and a written post-mortem shared with affected families.
Responsible Disclosure
Found a Vulnerability?
We take security vulnerabilities seriously and appreciate the work of security researchers who help us keep families safe. Our responsible disclosure program rewards researchers who follow coordinated disclosure practices.
24-hour acknowledgment
We confirm receipt of every report within one business day.
48-hour triage
Our security team assesses severity and begins work within 48 hours.
Safe harbor policy
Researchers acting in good faith are protected from legal action.
Credit & recognition
Researchers are credited on our security acknowledgments page.
Report a Vulnerability
Send your report to our security team. Include a description, steps to reproduce and the potential impact.
PGP Key
Available on request
Please do not report security issues via GitHub issues or public channels.
Our Commitment to You
Families trust us with what matters most. Security isn't a feature we added — it's the foundation we built on.
We never sell your data
Your family's information is never monetised — period.
We only collect what we need
Minimal data collection, with a purpose for every field.
We watch for problems
Monitoring and alerting on our infrastructure, and the incident process above when something goes wrong.
We give you control
Roles per member, and your data exported or deleted on request.
We're transparent about incidents
Written post-mortems and proactive notification for any security event that affects you.
Planned independent testing
Independent penetration testing is planned and will be listed on the ledger above when it exists.
Common Questions
Security FAQ
How we protect your family's data, in plain words.
Have a Security Question?
Our security team is here to help. Reach out anytime — we respond within 24 hours.
Answers about Bubaly Trust Center
Clear answers maintained by the Bubaly team and kept in sync with the public site.
