ALLO can hold briefs, research, files, feedback, project history, and work in progress. We protect that data with established cloud infrastructure, access controls, encryption, backups, secure payment processing, and external application-security validation.
These safeguards cover the main systems and processes involved when customer data is stored, accessed, transmitted, backed up, and processed through ALLO.
Cloud infrastructure security
ALLO uses cloud infrastructure from AWS, Microsoft Azure, and Google Cloud Platform. These providers maintain physical security, monitoring, operational controls, and independent assurance programs for major standards including SOC and ISO 27001.
Access control
Access to customer data is limited to people and systems with a business or operational need. Administrative and technical controls are used to manage permissions and identify and respond to security risks.
Secure development process
ALLO uses automated checks and manual review throughout product development. Security requirements are considered during design, implementation, testing, and deployment to reduce the chance that vulnerabilities reach production.
Critical data is protected through encrypted backups, distributed infrastructure, and recovery procedures designed to support service resilience during failures and unexpected interruptions.
Data encryption
Data in transit is protected with TLS 1.2, and data at rest is encrypted with AES-256. These controls help protect the confidentiality and integrity of customer and workspace data.
Payment data protection
Payments are processed through Stripe, a PCI DSS Level 1 certified provider. Sensitive card details are not stored on ALLO servers.
ALLO completed CASA Tier 2 validation through the App Defense Alliance. The assessment uses application-security requirements aligned with OWASP ASVS, with validation evidence reviewed by authorized assessors.
Contact the security team if you need information for procurement, vendor assessment, or compliance work, or if you believe you have found a vulnerability.