Security Stance
Last Updated: May 2026
Our Security Philosophy
Data security and privacy are not afterthoughts; they are the bedrock upon which Ibis Labs is constructed. We believe that being a boutique software provider is a distinct advantage: we make no pretense of being a global data security conglomerate. Instead, Ibis Labs LLC takes a “best-in-class” approach by offloading data storage and infrastructure security to the true industry experts—Google Cloud and Firebase. Our philosophy is simple: if we would not trust a platform with our own personal data, we will not ask you to trust it with yours. By leveraging the world-class, SOC 2 Type II, and ISO 27001-certified infrastructure provided by Google, we ensure your information is protected by the same technological standards used by major financial institutions.
Zero-Knowledge Architecture & End-to-End Encryption
For Thoth's Notebook and Trainer Notebook Pro, we employ zero-knowledge architecture. This means the heavy lifting of encryption occurs entirely on your device, and only the resulting unintelligible ciphertext is stored on the Firebase infrastructure. Neither Ibis Labs, nor Google/Firestore hold your decryption keys. This means we cannot access unencrypted versions of your workout logs, personal notes, or private messages. Direct messaging and writing on group “walls” among users who elect to participate in such groups are additionally protected by end-to-end encryption, ensuring that messages are readable only by the intended recipient. To be clear about the trade-off: because we never possess your keys, if you lose your 24-word (Thoth's Notebook) or 12-word (Trainer Notebook Pro) backup, we have no “backdoor” to recover your data. In this architecture, security means placing the power of privacy—and the responsibility of access—directly into your hands.
NOTE: Because communications on HOA-hub are potentially legally discoverable, they are not encrypted. Users should be aware that messages are not private: everything they write on the platform is data owned by their association and could be subject to legal discovery and/or association review. The messaging platform on HOA-hub includes a warning to this effect.
Infrastructure Security
Ibis Labs has no physical servers of its own. We utilize Google Cloud and Firebase, which provides us—and you—with world-class, SOC 2 Type II and ISO 27001-certified physical and network security. We leverage Firebase's Encryption at Rest for all data, ensuring that your information is protected by the same technological standards used by major financial institutions.
Authentication
We use Firebase Authentication to handle logins. Your password is never stored on any Ibis Labs LLC equipment. Firebase uses industry-standard hashing algorithms to keep your password safe. We encourage all users to implement strong, unique passwords. Ibis Labs LLC does not have access to your password, nor would we want it.
Access Controls
We operate under a strict least-privilege access model. There is no large team of contractors or third parties with access to your data. While we may retain assistance as needed to improve operational efficiency or security, at no time will any individual or third party be granted direct access to user data without thorough vetting and signed, legally binding privacy agreements. Our own access to the production environment is utilized only when necessary to perform essential maintenance or improvements. In this case we will limit our access to the minimum amount of production data required to perform such maintenance. We may also access data to assist with a support request initiated by a user.
Incident Response
In the unlikely event of a security incident affecting your data, Ibis Labs LLC will not hide behind corporate legal counsel. We will notify you directly via email within 72 hours of confirming a breach, clearly detailing what happened, what data was potentially affected, and the exact steps we are taking to mitigate the situation.
Responsible Disclosure
If you are a security researcher and you believe you have found a vulnerability in an Ibis Labs product, we want to hear from you. Please email [email protected] with the subject line “Security Disclosure.” Include a description of the issue and steps to reproduce it. We promise to acknowledge receipt within 48 hours and work to address confirmed issues. We value the security community and will not take legal action against individuals who report vulnerabilities in good faith.
Security Contact
Please direct all security-related communications to [email protected] with the subject line “Security Disclosure.”