Trust center
Verify, do not just trust.
Albena lives in your home, so security is part of the design. This page shows what we do, which frameworks we work toward, and what has not been independently audited.
Security overview
- 01
Local first
Everyday requests, audio and memory stay on hardware in your home wherever possible.
- 02
Approval before action
Reads are instant. Changes wait for you, and high-risk changes need a change record and PIN.
- 03
Least privilege
Albena gets only the access you connect, with per-user permission tiers.
- 04
Encrypted in transit
This site is HTTPS only, and traffic to any cloud service we call is encrypted.
- 05
Auditable
A full audit log of what was asked and done, with rollback information.
- 06
Honest status
We say what is done, what is in progress, and what has not been audited.
Read the full security practices, or report a vulnerability at security.txt.
Backups & integrity
Our database is exported nightly to private storage with a SHA-256 manifest, and the export is verified weekly. This indicator reads the live status of that job.
Checking backup status...
The first scheduled backup runs on October 10, 2026 (03:17 UTC). Until then this shows a neutral state, not a failure.
What changed today
- Tamper-evident audit log: each entry is hash-chained to the one before it.
- Nightly backups to private storage with checksums, 35-day retention and weekly verification.
- Weekly automated security scans of our code and live site, filed as issues when something fails.
- HTTPS only with HSTS preload, TLS 1.2 or newer, and a strict content security policy.
- Admin pages now sit behind Cloudflare Access (owner-only, 8 hour sessions) and our code is protected by required reviews and checks. The owner can still bypass these as sole maintainer.
- Control statuses re-scored against evidence; items waiting on us are marked partial.
Control frameworks
We use these frameworks to organize and check our work. Working toward a framework is not certification against it.
NIST SP 800-53 Moderate
In progressFederal control catalog
We are mapping our controls to the Moderate baseline and publishing the status of each one.
SOC 2 Trust Services Criteria
AlignedSecurity, availability, confidentiality, privacy
Our practices are aligned with the criteria. A formal SOC 2 audit has not been completed and we hold no SOC 2 report.
Audit not yet completed
STIG / CIS hardening
In progressSystem configuration baselines
We are applying hardening baselines to the systems Albena runs on and recording deviations.
NIST CSF 2.0
AlignedCybersecurity framework
Our security program is organized around Govern, Identify, Protect, Detect, Respond and Recover.
Control mapping
Every control, its frameworks, its status and its evidence, in one table.
- 169 listed
- 35 implemented
- 80 partial
- 54 planned