Skip to content
Enterprise-Grade Security

Your family's privacy
is our top priority.

Bubaly is built with the same security standards used by leading banks and healthcare providers — because your family deserves nothing less.

Privacy by Design

Every feature is architected to minimize data exposure and maximize your control.

Bank-Level Security

AES-256 encryption, TLS 1.3, and the same standards used by leading financial institutions.

You're in Control

Granular permissions, data export, and instant deletion — always at your fingertips.

Transparent & Accountable

Clear policies, public audits, and a dedicated security team you can reach anytime.

Defense in Depth

Security at Every Layer

Six layers of protection stand between a threat and your family's data. Each layer is independently audited and continuously monitored.

Layer 1

Edge Protection

DDoS mitigation, WAF rules, and rate limiting at the edge via Cloudflare. Malicious traffic is blocked before it reaches our infrastructure.

DDoS protectionWeb Application FirewallBot detectionRate limiting
Layer 2

Transport Security

All data in transit is encrypted with TLS 1.3. HSTS headers enforce HTTPS. Certificate pinning prevents man-in-the-middle attacks.

TLS 1.3 encryptionHSTS preloadingCertificate transparencyPerfect forward secrecy
Layer 3

Authentication

Multi-factor authentication, biometric login, secure session tokens with automatic rotation, and brute-force protection.

Multi-factor auth (TOTP/SMS)Biometric loginSession token rotationBrute-force lockout
Layer 4

Authorization

Row-level security policies ensure family members only access data they are permitted to see. Every API call is authorized individually.

Row-level security (RLS)Role-based access controlPer-request authorizationPrinciple of least privilege
Layer 5

Data Encryption

AES-256 encryption at rest for all data. Encryption keys are managed in a hardware security module (HSM) and rotated automatically.

AES-256 at restHSM key managementAutomatic key rotationColumn-level encryption for PII
Layer 6

Backup & Recovery

Point-in-time recovery with continuous WAL archiving. Encrypted backups stored in geographically separate regions with 30-day retention.

Continuous WAL archivingPoint-in-time recoveryGeo-redundant backup storage30-day backup retention

Trust Center

Certified. Compliant. Trusted.

Bubaly meets and exceeds the highest industry standards. Our compliance posture is independently verified and continuously maintained.

SOC 2

Audited annually

Independent auditors verify our security controls, availability, and confidentiality practices annually.

GDPR

EU compliant

Full compliance with EU General Data Protection Regulation including data portability and right to erasure.

HIPAA

Healthcare ready

We implement administrative, physical, and technical safeguards required for protected health information.

CCPA

California compliant

California residents have full rights to know, delete, and opt-out of data sale (we never sell data).

Annual penetration testing
Continuous vulnerability scanning
Bug bounty program
99.99% uptime SLA

Data Sovereignty

Your Data, Your Region

Choose where your family's data lives. All regions run on AWS infrastructure with SOC 2, ISO 27001, and ISO 27018 certifications. Data never leaves your selected region unless you explicitly request a transfer.

Multi-AZ deployment for high availability
Automatic failover within region
Encrypted cross-region backups
🇺🇸

United States

US-East (Virginia)

AWS
🇪🇺

European Union

EU-West (Frankfurt)

AWS
🇦🇺

Asia Pacific

AP-Southeast (Sydney)

AWS

Your Data, Your Rules

You Have Full Control

We believe your data belongs to you. These aren't just words — they're features built into every Bubaly account.

Granular Access Controls

Invite family members and assign specific permissions. Parents manage what children can see and do. Grandparents get a simplified read-only view.

Full Data Portability

Export all your family's data anytime in standard formats (JSON, CSV). Your data belongs to you — always.

Instant Deletion

Permanently delete individual records, a family member's data, or your entire account. Deletion is irreversible and includes backups within 30 days.

Zero Ads. Zero Tracking.

We don't show ads, sell data, or track your family across the web. No third-party analytics scripts run on your dashboard.

Session Management

View all active sessions, see device details, and revoke access to any device instantly from your security settings.

Audit Logs

Every significant action is logged with timestamps. Review who accessed what, when, and from where in your family's activity log.

Incident Response

When It Matters Most

Our incident response protocol is battle-tested and designed for speed, transparency, and accountability.

Phase 1

Detection

< 5 min

Automated monitoring detects anomalies within minutes via 24/7 alerting systems.

Phase 2

Assessment

< 30 min

On-call security engineer assesses severity, scope, and begins containment.

Phase 3

Notification

< 24 hrs

Affected users are notified within 24 hours with clear details and recommended actions.

Phase 4

Resolution

Ongoing

Root cause analysis, remediation, and a public post-mortem for transparency.

Responsible Disclosure

Found a Vulnerability?

We take security vulnerabilities seriously and appreciate the work of security researchers who help us keep families safe. Our responsible disclosure program rewards researchers who follow coordinated disclosure practices.

24-hour acknowledgment

We confirm receipt of every report within one business day.

48-hour triage

Our security team assesses severity and begins work within 48 hours.

Safe harbor policy

Researchers acting in good faith are protected from legal action.

Credit & recognition

Researchers are credited on our security acknowledgments page.

Report a Vulnerability

Send your report to our security team. Include a detailed description, steps to reproduce, and potential impact. We'll work with you to understand and address the issue.

PGP Key

Available on request

Please do not report security issues via GitHub issues or public channels.

Our Commitment to You

We know families trust us with what matters most. That's why security isn't a feature we added — it's the foundation we built on. Every decision, from architecture to hiring, prioritizes your family's safety.

We never sell your data

Your family's information is never monetized — period.

We only collect what we need

Minimal data collection with purpose limitation for every field.

We protect your data 24/7

Automated monitoring, alerting, and on-call security engineers around the clock.

We give you full control

Export, delete, or modify your data anytime from your dashboard.

We're transparent about incidents

Public post-mortems and proactive notification for any security events.

We invest in continuous improvement

Regular penetration tests, security audits, and infrastructure upgrades.

Common Questions

Security FAQ

Everything you need to know about how we protect your family's data.

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Encryption keys are stored in hardware security modules (HSMs) and rotated automatically. Sensitive fields like medical records and financial data receive additional column-level encryption.

Have a Security Question?

Our security team is here to help. Reach out anytime — we respond within 24 hours.

Knowledge Center

Answers about Bubaly Security

Clear answers maintained by the Bubaly team and kept in sync with the public site.

Every family’s data is isolated with row-level security; documents are private and served via short-lived signed URLs. Privacy is a feature, not a footnote.