Skip to main content

Key management

Every byte of customer data that Sally stores is encrypted, and the keys that unlock it stay with Aliru. This page explains what we encrypt, how the keys are generated, where they live, when they rotate, and why the infrastructure provider cannot access decrypted data at rest.

At-rest cipher
AES-256
In-transit protocol
TLS 1.3
Key rotation
Annual + event-driven
Provider access to keys
None

What we encrypt

All customer data at rest
Transcripts, summaries, audio and video recordings, metadata, and backups are encrypted with AES-256 in German data centers.
Backups on a separate storage instance
Backups sit on a physically separate storage instance in Germany and are AES-256 encrypted, with the same key ownership rules as production.
Everything in transit
Client-to-server and inter-service traffic runs on TLS 1.3. HTTP downgrades are refused.
Mobile media
Laptops and mobile storage that could hold customer data are full-disk encrypted, centrally managed with Microsoft Intune.

Where the keys live

The encryption keys are generated and held exclusively by Aliru. They are never given to the infrastructure provider, and they are never stored on their systems in clear text.

That has two practical consequences:

  1. Hetzner and any other infrastructure provider have no access to the keys or to the decrypted data at rest, even physically at the datacenter.
  2. A subpoena to the infrastructure provider cannot unlock the data. They physically do not have what would be needed.

Support and operations at Aliru only access decrypted content when a customer-appointed contact has explicitly released a temporary, purpose-bound, and logged support session (see the DPA § 8 and the TOMs).

Rotation and lifecycle

Annual rotation
Encryption keys used for data at rest are rotated once per year at minimum, following a documented procedure.
Event-driven rotation
Keys are rotated additionally on defined events (e.g. suspected exposure, staff role changes affecting key custody, or on customer request tied to a security event).
TLS certificates
TLS certificates and their private keys follow standard modern lifetimes and are rotated ahead of expiry.
Audit trail
Rotation events are documented. The audit trail can be shared during vendor assessments alongside the TOMs.

What this means for you

  • Confidentiality of Art. 9 GDPR content is preserved even if the infrastructure provider is compelled to hand over storage volumes.
  • BYO LLM customers operate on the same key model. The self-hosted language model in Germany reads only what Aliru's key material decrypts for the request.
  • Compliance evidence for ISO 27001, DORA, and customer vendor assessments can be produced from the TOMs (Annex 1 § 9) and the rotation records on request.