Trust center

Verify, do not just trust.

Albena lives in your home, so security is part of the design. This page shows what we do, which frameworks we work toward, and what has not been independently audited.

Security overview

  • 01

    Local first

    Everyday requests, audio and memory stay on hardware in your home wherever possible.

  • 02

    Approval before action

    Reads are instant. Changes wait for you, and high-risk changes need a change record and PIN.

  • 03

    Least privilege

    Albena gets only the access you connect, with per-user permission tiers.

  • 04

    Encrypted in transit

    This site is HTTPS only, and traffic to any cloud service we call is encrypted.

  • 05

    Auditable

    A full audit log of what was asked and done, with rollback information.

  • 06

    Honest status

    We say what is done, what is in progress, and what has not been audited.

Read the full security practices, or report a vulnerability at security.txt.

Backups & integrity

Our database is exported nightly to private storage with a SHA-256 manifest, and the export is verified weekly. This indicator reads the live status of that job.

Checking backup status...

The first scheduled backup runs on October 10, 2026 (03:17 UTC). Until then this shows a neutral state, not a failure.

What changed today

  • Tamper-evident audit log: each entry is hash-chained to the one before it.
  • Nightly backups to private storage with checksums, 35-day retention and weekly verification.
  • Weekly automated security scans of our code and live site, filed as issues when something fails.
  • HTTPS only with HSTS preload, TLS 1.2 or newer, and a strict content security policy.
  • Admin pages now sit behind Cloudflare Access (owner-only, 8 hour sessions) and our code is protected by required reviews and checks. The owner can still bypass these as sole maintainer.
  • Control statuses re-scored against evidence; items waiting on us are marked partial.

Control frameworks

We use these frameworks to organize and check our work. Working toward a framework is not certification against it.

  • NIST SP 800-53 Moderate

    In progress

    Federal control catalog

    We are mapping our controls to the Moderate baseline and publishing the status of each one.

  • SOC 2 Trust Services Criteria

    Aligned

    Security, availability, confidentiality, privacy

    Our practices are aligned with the criteria. A formal SOC 2 audit has not been completed and we hold no SOC 2 report.

    Audit not yet completed

  • STIG / CIS hardening

    In progress

    System configuration baselines

    We are applying hardening baselines to the systems Albena runs on and recording deviations.

  • NIST CSF 2.0

    Aligned

    Cybersecurity framework

    Our security program is organized around Govern, Identify, Protect, Detect, Respond and Recover.

Control mapping

Every control, its frameworks, its status and its evidence, in one table.

  • 169 listed
  • 35 implemented
  • 80 partial
  • 54 planned
View control mapping