Uncut

How your files are protected

A plain account of what we do today, including what we have not done yet.

In transitTLS 1.3 between your machines, the web app and our servers
At restAES-256, with a separate key for each share
LocationData centres in Europe. Files do not leave the region
CopiesEvery block is stored on three machines in two buildings
Sign-inPassword plus a one-time code from an authenticator app
CertificationsNone yet. We plan an independent audit before the beta ends

Who can open your files

People you add to a share, and anyone who has one of your links and its password. You can see every member, link and API key for a share on one page and remove any of them.

Our staff do not open customer files. Support staff can see file names and sizes when you ask for help with a specific share, and that access is logged.

If you lose a machine

Sign in on the web, open Devices and disconnect it. The client on that machine stops syncing and removes its local copy the next time it comes online.

Report a vulnerability

Write to security@uncutstorage.org with steps to reproduce. We reply within three working days and will not take legal action over good-faith research.