Security & Privacy
Your sensitive genealogical data is protected with layered encryption, strict access control, and privacy-first design
Our Security Principles
Genealogical research — especially in IGG and cold case work — involves sensitive personal information. CanopyLink is built from the ground up to keep that data safe.
Encrypted & Secure
Encrypted in transit, with names and notes encrypted again before they reach the database
Private by Default
Projects are visible only to you — sharing is opt-in and fully controlled
Data Integrity
Referential integrity enforced at the database level to keep trees consistent
Export Anytime
Your data belongs to you — export as GEDCOM whenever you want
How We Keep Your Data Safe
CanopyLink employs multiple layers of security to ensure your family trees and genealogical documents remain private and protected.
Secure Sign-In
Sign in with an email and password, or use your existing Google or Microsoft account. Passwords are hashed with bcrypt and checked against known-breached password lists at sign-up — they are never stored in a readable form. Add time-based two-factor authentication for another layer.
Application-Level Encryption
Traffic is encrypted in transit over HTTPS. The most sensitive fields — names, research notes, project and tree names, and source citations — are additionally encrypted with AES-256 before they are written to the database, so they remain unreadable even to someone with direct database access.
To be precise: CanopyLink holds the encryption keys, so this is not end-to-end encryption — our systems can decrypt data in order to run the service. Uploaded files, dates and place names are protected by transport encryption, access control and storage-layer encryption rather than this additional field-level layer.
Access Control
Every project is private by default. When you share a project, you choose whether each person can view only or view and edit. Only you — the project owner — can delete it. Every request is authorised on the server, so access is enforced rather than assumed.
Data Integrity
Family tree data requires precise relationships. CanopyLink enforces referential integrity at the database level with foreign key constraints, ensuring parent-child, spouse, and sibling relationships always remain consistent and accurate.
Infrastructure & Practices
HTTPS Everywhere
All connections use TLS encryption, with HTTP Strict Transport Security enforced so browsers refuse to connect any other way.
Automatic Backups
The database is backed up nightly to separate, access-controlled storage that is encrypted at rest, with alerting if a backup ever fails.
CSRF & XSS Protection
Built on Laravel's security framework with CSRF tokens, input sanitization, and output escaping on every page.
Input Validation
All user input is validated and sanitized before processing. Parameterized queries prevent SQL injection.
Data Portability
Export your projects as GEDCOM files at any time. Your data is never locked in — you're always in control.
Your Rights
We believe your data belongs to you. Always.
Right to Access
You can view and export all of your data at any time through your account dashboard.
Right to Deletion
You can delete your projects or your entire account at any time. Deletion is immediate and permanent — there is no recycle bin — and uploaded documents and photos are removed from storage too. Deleted data then ages out of our rolling backups.
Right to Portability
Export your trees as industry-standard GEDCOM files that work with any other genealogy software.
No Data Selling, No AI Training
We will never sell, share, or monetize your genealogical data. CanopyLink has no AI or large language model integration of any kind — your trees, names and notes are never sent to any AI service. Your research is yours alone.
Ready to Get Started?
Experience secure, worry-free genealogy research with CanopyLink.