Security
A backup service holds the most sensitive data people have. Here's how we design for that.
Encryption
- Personal plans are end-to-end encrypted. Files are encrypted on your device with a key derived from your passphrase before they’re uploaded. We store ciphertext and can’t read your files.
- Recovery kit. Because we can’t reset your encryption passphrase, you’ll be given a recovery kit to print or store safely when you set up the app.
- Business and enterprise vaults are encrypted at rest. You can also bring your own keys from your KMS or HSM.
- All traffic uses TLS 1.2 or newer.
Separation
- Each cloud copy is stored with a different provider, under separate credentials. A compromise of one doesn’t expose the other.
- Customer data is kept apart from our website and billing systems.
Immutability
Business and enterprise vaults support object lock. Locked versions can’t be modified or deleted by anyone, including you and us, until their retention date passes. This is the strongest defence against ransomware that targets backups.
Verification
Every object is checksummed when it is uploaded, and again after it is replicated to the second provider. Before any region is marked live, it must pass scheduled test restores, and those tests keep running afterwards.
Reporting a vulnerability
Email security@triplicate.in. We’ll acknowledge your report within two working days and keep you updated until it’s fixed.