Trust
Security & trust
Albena lives in your home, so security is part of the design, not an add-on. This page explains the practices behind the product and this website, and where we are still early.
Where we are today
Albena is pre-release software in early access. Our security practices are aligned with the SOC 2 Trust Services Criteria (security, availability, confidentiality and privacy), but a formal SOC 2 audit has not yet been completed and we do not hold a SOC 2 report or any other third-party certification. We will say so here if that changes.
Encryption and HTTPS
This website is served only over HTTPS with TLS, and traffic between Albena components and any cloud service we call is encrypted in transit.
Local-first processing
Everyday requests, audio, device data and memory are processed on hardware in your home wherever possible, so less data exists in places we or anyone else could expose. When a hard request needs a larger cloud model, only the information needed for that request is sent, to a provider acting on our behalf, and Albena tells you what leaves your home. See the Privacy Policy for details.
Approval before actions
Albena proposes; you decide. Sending a message, unlocking a door or changing a setting requires your approval, and you can review and delete what she remembers.
Access control and least privilege
- Albena only gets access to the services and devices you connect, and you can disconnect them at any time.
- Integrations request the narrowest permissions that the feature needs.
- Our own administrative access uses unique accounts, multi-factor authentication where available and least privilege, and is removed when no longer needed.
Logging and monitoring
We keep operational logs to detect errors and abuse, and avoid recording the content of your conversations or personal data in them beyond what is needed to run the service. Our hosting provider may keep standard server logs for this website.
This website
albena.ai is a static site. It sets no cookies of its own and runs no analytics or advertising trackers. Fonts and scripts are served from the site itself. The only third-party script is Cloudflare Turnstile, which loads on pages with a form to block automated spam. A Content Security Policy restricts what the pages can load or run, and external links use rel="noopener". Some protections, such as HSTS and anti-framing headers, depend on our hosting provider’s response headers and are applied at the network edge where supported.
Vendors and subprocessors
We use a small number of providers (website hosting and DNS, and cloud AI models only when you need a request that local models cannot handle). We choose providers with published security practices, give them only the data required for the task, and do not allow them to sell it. We review this list as the product grows.
Report a vulnerability
We welcome good-faith security research. Email omar@dbaomarhuertasllc.com with the details and steps to reproduce, and give us a reasonable time to investigate and fix the issue before any public disclosure. We will acknowledge reports promptly and keep you updated. Please do not access other people’s data or disrupt the service. Our machine-readable policy is at /.well-known/security.txt.
Incident response
We maintain a process to triage, contain, investigate and fix security incidents, and to notify affected people and regulators when the law requires it. If an incident affects your data, we will tell you what happened, what was involved and what to do next. Questions: omar@dbaomarhuertasllc.com.
Related: Privacy Policy, Terms and Accessibility.