How your files are protected
A plain account of what we do today, including what we have not done yet.
| In transit | TLS 1.3 between your machines, the web app and our servers |
|---|---|
| At rest | AES-256, with a separate key for each share |
| Location | Data centres in Europe. Files do not leave the region |
| Copies | Every block is stored on three machines in two buildings |
| Sign-in | Password plus a one-time code from an authenticator app |
| Certifications | None yet. We plan an independent audit before the beta ends |
Who can open your files
People you add to a share, and anyone who has one of your links and its password. You can see every member, link and API key for a share on one page and remove any of them.
Our staff do not open customer files. Support staff can see file names and sizes when you ask for help with a specific share, and that access is logged.
If you lose a machine
Sign in on the web, open Devices and disconnect it. The client on that machine stops syncing and removes its local copy the next time it comes online.
Report a vulnerability
Write to security@uncutstorage.org with steps to reproduce. We reply within three working days and will not take legal action over good-faith research.