Skip to content
Trust Center

What Bubaly may do, what it asks, and what we can prove

An assistant that acts for your family has to earn that. This page says exactly what is verified today, what is in place, what we inherit from our infrastructure providers, and what is still planned.

Privacy by Design

Every feature is built to expose as little as possible and to keep you in control.

Encrypted in transit and at rest

TLS for every connection and encryption at rest on our database and storage providers.

You're in control

Roles and permissions per member, and your data available or deleted on request.

Transparent & Accountable

Clear policies, a labelled evidence list, and a security team you can reach anytime.

Trust Center

How the assistant is allowed to act

  1. 1

    It handles on its own only the routine work allowed in Settings → Bubaly AI. Every area has a dial — Recommend, Prepare or Execute — and you can turn any area down to Recommend at any time.

  2. 2

    These areas always wait for a parent's OK, whatever the dial says:

    • Money: Finances, Banking
    • Health: Medical, Dental, Vision, Mental Health
    • Documents: Insurance, Passports, Documents
    • Safety: Driving, Emergency
  3. 3

    Every run keeps a step-by-step timeline; partly finished work is reported as partly finished.

  4. 4

    Quiet hours silence it, and every decision it makes is written to your family's trust ledger.

  5. 5

    Model-call telemetry records which task ran, which model answered, how many tokens and how long — never the text of your family's data. What you asked stays inside your family's own records.

  6. 6

    Your family's data is never used to train models.

Who can do what by default

RoleWhat the assistant may do
ParentBubaly may act for this role
AdultBubaly may act for this role
TeenA parent reviews actions for this role
ChildA parent reviews actions for this role
CaregiverA parent reviews actions for this role
GuestA parent reviews actions for this role

Health records are family-scoped and encrypted like everything else.

Verified, in place, inherited, or still planned

We show a badge only for what we can prove. Everything else is labelled for what it is.

Verified in the product
Enforced in code and covered by automated tests that run on every change.
In place
We do this today; evidence is published as it matures.
Provider-inherited
Held by the infrastructure we run on, not yet audited for Bubaly itself.
Planned
On the roadmap. No badge until it's done.
  • Row-level security on every family table

    Verified in the product

    Evidence

    • tests/rls-isolation-sweep.test.ts
    • tests/tenant-isolation-rls.test.ts
    • tests/sql-security-contract.test.ts
  • Append-only decision ledger, written by the server

    Verified in the product

    Evidence

    • tests/0260-trust-ledger-lockdown.test.ts
  • Money, health and documents always ask a parent

    Verified in the product

    Evidence

    • tests/trust-engine.test.ts
    • tests/tool-risk.test.ts
    • tests/assistant-trust-wrapper.test.ts
    • tests/marketing-trust-ledger.test.ts
  • Approvals expire instead of lingering

    Verified in the product

    Evidence

    • tests/approval-expiry.test.ts
  • Content Security Policy on every page

    Verified in the product

    Evidence

    • tests/csp-header.test.ts
    • tests/e2e/csp.spec.ts
  • Audit log of significant actions

    In place
  • Export or delete your family's data on request

    In place
  • Your family's data never trains a model

    In place
  • Encrypted in transit

    Provider-inherited
  • Encrypted at rest

    Provider-inherited
  • SOC 2 and ISO 27001 at our hosting providers

    Provider-inherited
  • Independent SOC 2 audit of Bubaly itself

    Planned
  • Third-party penetration test report

    Planned
  • Public bug bounty programme

    Planned
  • Public status page and uptime history

    Planned
  • Choice of data region

    Planned

Last reviewed:

Defense in Depth

Security at Every Layer

Four layers stand between a threat and your family's data. Each one is listed on the ledger above for what it is.

1

Transport security

Every connection is encrypted with TLS, and an HSTS header tells browsers never to use plain HTTP.

TLS on every connectionHSTS enforcedContent Security Policy on every page
2

Authorization

Row-level security policies on every family table mean a member only ever reads the rows their family owns. Roles start least-privilege and a parent widens them.

Row-level security (RLS)Role-based access controlLeast-privilege role defaults
3

Data at rest

Our database and storage providers encrypt data at rest. Documents are private and served only through short-lived signed URLs.

Encrypted at rest by our providersDocuments behind short-lived signed URLs
4

Backup and recovery

Backups and point-in-time recovery are provided by our database provider.

Provider backupsPoint-in-time recovery from the provider

Data Sovereignty

Your Data, Your Region

Today all family data is hosted in one region on infrastructure that holds SOC 2 and ISO 27001 reports; choosing your own region is planned.

Choice of data region

Your Data, Your Rules

You Have Full Control

Features built into every Bubaly account, not promises.

Granular access controls

Six roles, from parent to guest. Parents decide what children can see and do; caregivers and guests see only what they are given.

Export or delete on request

Ask us for a copy of your family's data. Delete individual items or a member's profile in the app, or ask us to delete your whole account.

No ads, no data sales

We don't show ads and we don't sell your family's data. Subscriptions pay for Bubaly.

A ledger of what the assistant did

Every assistant decision is written to your family's trust ledger, and significant actions are logged on the server.

Incident Response

When It Matters Most

Our incident response protocol is battle-tested and designed for speed, transparency, and accountability.

This is our policy, not a certification.

1

Detection

Monitoring and alerting on our infrastructure flag anomalies to the on-call engineer.

2

Assessment

We assess severity and scope, and begin containment.

3

Notification

Affected families are notified within 24 hours, with clear details and recommended actions.

4

Resolution

Root-cause analysis, remediation, and a written post-mortem shared with affected families.

Responsible Disclosure

Found a Vulnerability?

We take security vulnerabilities seriously and appreciate the work of security researchers who help us keep families safe. Our responsible disclosure program rewards researchers who follow coordinated disclosure practices.

24-hour acknowledgment

We confirm receipt of every report within one business day.

48-hour triage

Our security team assesses severity and begins work within 48 hours.

Safe harbor policy

Researchers acting in good faith are protected from legal action.

Credit & recognition

Researchers are credited on our security acknowledgments page.

Report a Vulnerability

Send your report to our security team. Include a description, steps to reproduce and the potential impact.

PGP Key

Available on request

Please do not report security issues via GitHub issues or public channels.

Our Commitment to You

Families trust us with what matters most. Security isn't a feature we added — it's the foundation we built on.

We never sell your data

Your family's information is never monetised — period.

We only collect what we need

Minimal data collection, with a purpose for every field.

We watch for problems

Monitoring and alerting on our infrastructure, and the incident process above when something goes wrong.

We give you control

Roles per member, and your data exported or deleted on request.

We're transparent about incidents

Written post-mortems and proactive notification for any security event that affects you.

Planned independent testing

Independent penetration testing is planned and will be listed on the ledger above when it exists.

Common Questions

Security FAQ

How we protect your family's data, in plain words.

All data is encrypted in transit with TLS and at rest by our database and storage providers. Access to every family table is enforced by row-level security that runs in our automated tests on every change.

Have a Security Question?

Our security team is here to help. Reach out anytime — we respond within 24 hours.

Knowledge Center

Answers about Bubaly Trust Center

Clear answers maintained by the Bubaly team and kept in sync with the public site.

Every family’s data is isolated with row-level security; documents are private and served via short-lived signed URLs. Privacy is a feature, not a footnote.