Security for the work your team relies on.

ALLO can hold briefs, research, files, feedback, project history, and work in progress. We protect that data with established cloud infrastructure, access controls, encryption, backups, secure payment processing, and external application-security validation.

Core safeguards, stated plainly.

TLS 1.2
Encryption for data in transit
AES-256
Encryption for data at rest
PCI L1
PCI-certified payment processing through Stripe
CASA
Validated through the App Defense Alliance

How ALLO protects customer data

These safeguards cover the main systems and processes involved when customer data is stored, accessed, transmitted, backed up, and processed through ALLO.

Cloud infrastructure security

ALLO uses cloud infrastructure from AWS, Microsoft Azure, and Google Cloud Platform. These providers maintain physical security, monitoring, operational controls, and independent assurance programs for major standards including SOC and ISO 27001.

Access control

Access to customer data is limited to people and systems with a business or operational need. Administrative and technical controls are used to manage permissions and identify and respond to security risks.

Secure development process

ALLO uses automated checks and manual review throughout product development. Security requirements are considered during design, implementation, testing, and deployment to reduce the chance that vulnerabilities reach production.

Source: App Defense Alliance CASA

Backup and recovery

Critical data is protected through encrypted backups, distributed infrastructure, and recovery procedures designed to support service resilience during failures and unexpected interruptions.

Data encryption

Data in transit is protected with TLS 1.2, and data at rest is encrypted with AES-256. These controls help protect the confidentiality and integrity of customer and workspace data.

Payment data protection

Payments are processed through Stripe, a PCI DSS Level 1 certified provider. Sensitive card details are not stored on ALLO servers.

Source: Stripe Security
CASA
Tier 2

Cloud application security assessment

ALLO completed CASA Tier 2 validation through the App Defense Alliance. The assessment uses application-security requirements aligned with OWASP ASVS, with validation evidence reviewed by authorized assessors.

Source: App Defense Alliance CASA

Need information for a security review?

Contact the security team if you need information for procurement, vendor assessment, or compliance work, or if you believe you have found a vulnerability.

This page describes ALLO's current security practices. Details may change as the product, infrastructure, and applicable requirements evolve.