Dear Alli
Dear Alli
Security

Straight answers to the questions a security review asks. Where the answer is no, it says no. A vendor who overstates this at the start is a vendor you find out about later.

Read this first. Dear Alli is built and run by Go To 11 Communication Strategies, a small Toronto company. It holds no SOC 2 report, no ISO 27001 certificate, and has not had a third party penetration test. If your policy requires any of those from a vendor, Dear Alli does not meet it today, and no amount of the rest of this page changes that.

The company

Who are we?
Go To 11 Communication Strategies, Toronto, Canada. Dear Alli is operated by Kenny Solway.
Who has access to customer data?
Two people. Kenny Solway, for support and to check coaching quality. Alli Rizacos of Authentic Results, who reads the private review channel where every draft is mirrored, to correct the coaching. Nobody else at Go To 11 and no contractor.
Are staff background checked, and is there security training?
No formal programme. With one operator and one reviewer, access control is the fact that there are two named people and no one else.

Where the data is

Where is it stored?
Notion holds coach profiles and conversation history. Netlify runs the application and holds short term storage. Both are in the United States. There is no self-hosted database and no other copy.
Can we choose a region?
No. There is one region and it is the United States.
Encryption?
TLS on every connection, inbound and outbound, with no plaintext fallback. At rest, whatever Notion and Netlify provide as platforms. Dear Alli does not add its own encryption layer on top, and does not hold its own keys.

Who else receives it

Sub-processors?
Anthropic writes the coaching, so every message reaches it. OpenAI transcribes voice notes, and is reached only when someone sends audio. Notion stores profiles and history. Netlify runs the application. Slack, the private review channel where every draft is mirrored, and the legacy channel for the few coaches still on Slack. Supabase, the function log: timings, status codes and token counts keyed to the coach id, never message text. Authentic Results, Alli Rizacos of Authentic Results, who reads the review channel to correct drafts and train the coaching. Resend sends account email, no conversation content. Stripe takes payment; card details go straight to Stripe and never reach us.

That list is checked against the code on every release. A new outbound call fails the build until it is either added here or recorded as carrying no customer data.
Is customer data used to train models?
No. Anthropic keeps what it receives for up to 30 days under its API terms, then deletes it, and does not train on it. Dear Alli does not sell data and does not share it with anyone outside the list above.

Access and authentication

How does a user sign in?
A 32 character random access code, issued per person. It can be replaced or revoked instantly from the account owner's screen, and revocation takes effect within a minute.
Do you support SSO or SAML? Is MFA enforced?
No, and no. The access code is the whole of user authentication. For a managed fleet the code is never emailed around: your admin pushes one enrolment token by Chrome policy and each install claims its own seat.
How is one customer kept out of another's data?
Every profile and every conversation is looked up by an identifier belonging to one person. A draft is only ever returned to the coach it was written for. Where two customers ever share a name, the system refuses to show either of them any history rather than risk showing the wrong one. Those three rules are asserted by automated tests that run before every release and block it on failure.
Server to server calls?
HMAC signed and verified. An unsigned call to the coaching engine is refused.

Operations

What is logged?
Who called, what failed, and counts. Not the text of anyone's messages.
Backups?
Notion's own. Deleted records sit in its trash and are recoverable for thirty days, after which they are gone.
Monitoring and uptime?
A recovery net retries and rescues any coach message that stalls, with a daily heartbeat that alarms if the net itself stops running. There is no published uptime SLA.
Security headers?
Every page is served with a Content Security Policy that names each third party host it loads, plus HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and a Permissions-Policy. A build check scans every page and refuses to deploy if one starts loading from a host the policy does not name. Exports never contain a cell a spreadsheet would run as a formula.
Incident response?
No formal policy document, and no rehearsed plan. The commitment is written down: if customer data were exposed with a real risk of significant harm, Kenny contacts affected customers directly and without undue delay, reports it to the Office of the Privacy Commissioner of Canada as PIPEDA requires, and says what is known and what is not yet known. Every breach, whatever its size, goes in a record kept for twenty-four months.
Change management?
Every release runs a suite of automated checks first and cannot deploy if any fail. Several of those checks exist specifically to protect the separation between customers.
Reporting a vulnerability?
Email kennysolway@goto11.ca. You will get a person, same day.

Your data, your call

Retention?
Kept while the account is open, because the history is what makes the coaching improve. When the account closes we delete everything within thirty days, whether or not anyone asks. Notion's own trash then holds the deleted records a further thirty days before they are unrecoverable.
Deletion?
Ask, and everything goes: profile, conversations, drafts, scoreboard. The one exception is the private review channel drafts are mirrored to, which is not cleared by hand and instead ages out on its own within ninety days. Full detail at dearalli.goto11.ca/your-data.
Export?
Yes. Ask and you get your conversations in a file.
Is there a data processing agreement?

Last updated 30 August 2026. Anything unanswered, email kennysolway@goto11.ca.

Dear Alli home  ·  A Go To 11 Communication Strategies Build