Trust & Security
How we protect the files businesses trust us with, what we commit to contractually, and where we actually stand on formal audit.
Technical and organizational measures
The measures below describe the safeguards FileBackerz applies.
| Area | Measures |
|---|---|
| Encryption | Customer Content encrypted at rest using AES-256. All data in transit encrypted using TLS 1.2 or higher, with TLS 1.3 preferred. Encryption keys managed through a dedicated key management service with restricted access and periodic rotation. |
| Access control — personnel | Role-based access control with least privilege. Unique named accounts; shared administrative credentials prohibited. Multi-factor authentication required for all administrative and production access. Access reviewed periodically and revoked promptly on role change or departure. |
| Access control — customer | Seven-level granular folder and file permissions, group-based permission management, configurable session timeouts, optional two-factor authentication, password complexity enforcement, and optional IP allow-listing. |
| Logging and monitoring | Audit logging of uploads, downloads, deletions, permission changes, share-link creation, and authentication events, each with actor, timestamp, and IP address. Administrative access to production is logged. Logs retained for twelve months. |
| Pseudonymization and minimization | Passwords stored only as salted hashes. Internal analytics performed on aggregated or de-identified data where practicable. Personal data collected at signup limited to what is necessary, with optional fields marked as such. |
| Resilience and availability | Redundant storage with automated integrity checking. Regular automated backups with defined recovery point and recovery time objectives. Documented restoration procedures, tested periodically. |
| Business continuity | Documented incident response and business continuity procedures, with defined roles, escalation paths, and communication templates. Reviewed at least annually. |
| Vulnerability management | Dependency and infrastructure vulnerability scanning, timely patching of security updates according to documented severity-based timelines, and a published channel for external vulnerability reports at [email protected]. |
| Secure development | Version-controlled source code, peer code review, separation of development, staging, and production environments, and secrets held in a managed secrets store rather than in source code. |
| Subprocessor management | Written data protection terms with each Subprocessor, security review before engagement, and periodic reassessment. |
| Personnel | Confidentiality obligations in all personnel agreements; security and data protection awareness training; documented access provisioning and deprovisioning. |
| Physical security | Production infrastructure hosted in third-party data centers operated by our infrastructure Subprocessors, which maintain physical access controls, environmental controls, and independent security certifications. FileBackerz does not operate its own data centers. |
| Deletion | Documented deletion procedures for live systems, with backup purge within thirty-five days as described in Section 12. |
| Governance | Named individual accountable for information security. Written information security policy reviewed at least annually. FileBackerz does not hold a SOC 2 Type II attestation and does not represent that it does. |
Audit and certification, honestly
FileBackerz does not hold a SOC 2 Type II attestation, an ISO 27001 certificate, or any other third-party security certification, and we will not claim one until an auditor has issued it. We would rather tell you that plainly than have you discover it during procurement.
What we can offer instead is specificity: the measures above are the ones we commit to contractually in Annex II of our Data Processing Addendum, and we will answer a security questionnaire in detail.
HIPAA: the Service is not offered as a HIPAA compliance solution. Protected health information may only be uploaded under a Business Associate Agreement executed with us, as set out in the Acceptable Use Policy.
Reporting a vulnerability
If you believe you have found a security vulnerability, write to [email protected]. We will acknowledge your report, keep you updated while we investigate, and will not pursue action against good-faith research that respects customer data and does not degrade the Service.
Abuse and unlawful content should go to [email protected]. Copyright notices go to our designated agent at [email protected] (U.S. Copyright Office registration DMCA-1077736); see the Copyright and DMCA Policy for what a valid notice must contain.