Security

How we protect a life.

Hippora holds the most private thing you own. These are the specific measures behind that responsibility, written without marketing language.

Encryption

TLS 1.3 in transit. AES-256 at rest. Keys are managed in a dedicated key service and rotated on a fixed schedule.

Access control

A very small number of engineers can reach production, under multi factor authentication and audited break glass procedures for incidents only.

No casual reading

There is no internal tool that lets anyone browse user content. Support cannot see your reflections.

Retention

We keep what you keep. Deleted content is removed from live systems immediately and from backups within thirty days.

Where it lives

Data is stored in the European Union. Any change would be announced before it happened, not after.

Portability

Your entire archive exports as readable files in one action, at any time, on any plan.

Practice

How we work.

Dependencies reviewed

Third party packages are pinned, scanned and updated on a schedule rather than when something breaks.

Least privilege by default

Every service holds the narrowest permissions that let it do its job, and nothing beyond.

Secrets never in code

Credentials live in a managed secret store. None are committed to a repository, ever.

Independent testing

We commission external penetration testing before each major release and publish a summary.

Disclosure welcome

Found something? Write to us and we will respond within one working day. We do not threaten researchers.

Incidents told plainly

If something happens, you will hear what happened, what was affected and what we changed, in plain English.

Report a vulnerability

Read the privacy policy too.

Security is how we protect it. Privacy is what we promise about it. Both are worth five minutes.