Trust centre
Security
When security is done right, you mostly can't see it. Here's what we do and what we're working towards. And how to tell us if you find a problem.
Security practices
Encrypted everywhere
Data is encrypted when it is sent (TLS) and when it is stored. Our system holds no copy of your family's data that is not encrypted.
UK hosting
Assembly runs in Microsoft Azure's UK South region. That covers hosting, the database, storage, background jobs and checks on the system. Sign-in links and our other emails go through Microsoft's email service, Azure Communication Services. It is on the same Azure account, under the same agreement. It does not sit in one region. Instead, we set where its data is held, and we have set that to the UK. Microsoft says stored data stays there. But it also says data may pass through, or be handled in, other parts of the world. So an email may be processed outside the UK. Your child's profile, answers and reports are stored in the UK, in Microsoft Azure. To write a report or a reply in chat, Microsoft's AI service may process the request in another Azure region; what is kept is kept in the UK, and nothing you give us is used to train AI models. Usage analytics (PostHog) is processed in the EU: it's linked to a session, not your name, and it never receives your child's profile, answers or reports. The list of who processes your data says what each provider does and where it runs.
Only the access people need
Only the few people who need it to run the service can reach live data. Every way in asks them to prove who they are.
Safe ways of building
Every change is reviewed and must pass our checks before it goes live, unless we override a check and record why. We watch the code we use from others and fix security flaws fast.
Kept apart by design
Each family's data is kept apart by account. The database itself keeps it apart, not just the app's code.
If something goes wrong
If a breach ever affects your family's data, we tell you. We do this even where UK GDPR would not strictly require it. We also tell the ICO where the law says we must. We say what happened, what it means, and what we've done.
Independent assurance, where we are, honestly
We are getting ready to work with NHS services. So we're working through four sets of checks. They are the NHS Digital Technology Assessment Criteria (DTAC 2.0), the Data Security and Protection Toolkit (DSPT), Cyber Essentials, and outside testing that tries to break in. We'll say each one is done here when it is, and not before. Are you an NHS or school team that checks how data is handled? For the full, current status, email info@helloassembly.com and we'll share our pack of evidence.
Found a vulnerability?
We want to hear about it, and we won't take legal action against good-faith research. Email info@helloassembly.com with enough detail for us to see the problem for ourselves. We'll tell you we got your report and keep you updated as we fix it. We'll credit you if you'd like. Please don't look at other people's data while testing. Use your own account. This policy is also linked from /.well-known/security.txt .