Encryption
Hippora is being designed to encrypt your content in transit and at rest, using strong modern encryption and carefully managed keys. This page will describe the exact approach as each part is implemented.
Security
Hippora holds the most private thing you own. These are the specific measures behind that responsibility, written without marketing language.
Hippora is being designed to encrypt your content in transit and at rest, using strong modern encryption and carefully managed keys. This page will describe the exact approach as each part is implemented.
A very small number of engineers can reach production, under multi factor authentication and audited break glass procedures for incidents only.
There is no internal tool that lets anyone browse user content. Support cannot see your reflections.
We keep what you keep. Deleted content is removed from live systems immediately and from backups within thirty days.
Data is stored in the European Union. Any change would be announced before it happened, not after.
Your entire archive is being designed to export as readable files, at any time, on any plan.
Practice
Third party packages are pinned, scanned and updated on a schedule rather than when something breaks.
Every service holds the narrowest permissions that let it do its job, and nothing beyond.
Credentials live in a managed secret store. None are committed to a repository, ever.
We commission external penetration testing before each major release and publish a summary.
Found something? Write to us and we will respond within one working day. We do not threaten researchers.
If something happens, you will hear what happened, what was affected and what we changed, in plain English.
Security is how we protect it. Privacy is what we promise about it. Both are worth five minutes.