triplicate

Security

A backup service holds the most sensitive data people have. Here's how we design for that.

A padlock on a shield, with a file turning into scrambled blocks as it is encrypted

Encryption

  • Personal plans are end-to-end encrypted. Files are encrypted on your device with a key derived from your passphrase before they’re uploaded. We store ciphertext and can’t read your files.
  • Recovery kit. Because we can’t reset your encryption passphrase, you’ll be given a recovery kit to print or store safely when you set up the app.
  • Business and enterprise vaults are encrypted at rest. You can also bring your own keys from your KMS or HSM.
  • All traffic uses TLS 1.2 or newer.

Separation

  • Each cloud copy is stored with a different provider, under separate credentials. A compromise of one doesn’t expose the other.
  • Customer data is kept apart from our website and billing systems.

Immutability

Business and enterprise vaults support object lock. Locked versions can’t be modified or deleted by anyone, including you and us, until their retention date passes. This is the strongest defence against ransomware that targets backups.

Verification

Every object is checksummed when it is uploaded, and again after it is replicated to the second provider. Before any region is marked live, it must pass scheduled test restores, and those tests keep running afterwards.

Reporting a vulnerability

Email security@triplicate.in. We’ll acknowledge your report within two working days and keep you updated until it’s fixed.