Security at Storvio

Your files, protected at every layer

Security isn’t a setting you switch on later — at Storvio it’s the default. From AES-256 encryption to independent audits, here’s exactly how we keep your data safe.

Defense in depth

Four layers between threats and your data

Encryption, access control, infrastructure and people — each one hardened independently.

🔐
Encryption everywhere

Files are encrypted with AES-256 at rest and protected by TLS 1.3 in transit. For your most sensitive folders, optional end-to-end encryption means the keys never leave your device — not even we can read them.

🔑
Strong access control

Two-factor authentication, SSO and granular role-based permissions keep accounts locked down. Every login and device is tracked, and admins can revoke access in one click.

🏢
Hardened infrastructure

Data lives in tier-IV data centers with 24/7 monitoring, redundant power and geographically separated backups. Every file is replicated across at least three zones.

👁
Continuous monitoring

A 24/7 security team, automated intrusion detection and a public bug-bounty program mean issues are caught early. Every action is written to a tamper-evident audit log.

How encryption works

AES-256, the way it should be done

When a file reaches Storvio, it’s split into encrypted blocks. Each block is sealed with a unique AES-256 key, and those keys are themselves encrypted with a master key stored in a hardware security module (HSM). Decryption only ever happens in memory, for the moment you need the file.

In transit, every connection uses TLS 1.3 with modern ciphers and forward secrecy, so traffic captured today can’t be decrypted tomorrow. Turn on end-to-end encryption for a folder and the keys are derived on your device — Storvio stores only ciphertext it cannot open.

  • At rest: AES-256 with per-block keys, master keys in an HSM
  • In transit: TLS 1.3, forward secrecy, HSTS enforced
  • End-to-end: client-side keys for folders you choose
  • Key rotation: automatic, with zero downtime
Your device encrypts a file before it ever leaves — Storvio stores only ciphertext.
Account protection

Two-factor authentication, on by a tap

A password alone isn’t enough, so Storvio supports the methods security teams actually trust — and lets admins require them across the whole organisation.

  • Authenticator apps (TOTP)
  • Hardware keys — FIDO2 / WebAuthn
  • Single sign-on with SAML & OIDC
  • Per-device approval and remote sign-out
2FA enabled

Enter your 6-digit code

A sample of the verification step every protected account sees at sign-in.

Compliance & certifications

Audited, certified and accountable

Independent auditors verify our controls so you don’t have to take our word for it.

SOC 2 Type II

Annually audited against security, availability and confidentiality criteria.

🌍
GDPR

Full data-subject rights, EU data residency options and a signed DPA on request.

🔒
ISO 27001

Certified information-security management across our systems and processes.

🏥
HIPAA-ready

BAAs available for healthcare teams handling protected health information.

Trusted at scale

Security millions of people rely on

2.8M+
Active users
120 PB
Data protected
99.99%
Uptime SLA
4.8★
38,000 reviews
Uptime

99.99% SLA

Backed by redundant infrastructure and a public status page you can subscribe to.

Recovery

3-zone backups

Every file is replicated across at least three zones with 180-day version history.

Transparency

Bug bounty

Researchers are rewarded for responsible disclosure through our public program.

Security FAQ

Common security questions

No. Files are encrypted at rest, and access by staff is blocked by policy and technical controls. For folders with end-to-end encryption enabled, the keys live only on your devices — we physically cannot read the contents.
In tier-IV data centers with a choice of EU or US data residency. Each file is replicated across at least three geographically separated zones for durability.
Yes. Team and enterprise plans include SAML and OIDC SSO plus SCIM provisioning, so access is granted and revoked automatically with your identity provider.
Through our public bug-bounty program. Responsible disclosures are acknowledged quickly and eligible for rewards. Reach the security team from the Contact page.

Security that lets you sleep at night

Start free and keep every file encrypted from the very first upload.