How we protect your data

The principles above are the summary. Here's what they mean in practice.

Encryption

Data moving to and from Storivo is encrypted in transit using TLS. Data at rest is encrypted on our storage nodes, so a physical disk or drive removed from our infrastructure isn't readable on its own. This applies across every plan tier; it isn't reserved for higher-priced plans.

Access control & sub-account isolation

Every access key is scoped to a specific account or, for white-label partners, a specific sub-account, so one client's key can't reach another client's data. Internally, employee access to infrastructure follows least-privilege principles and is reviewed on a regular schedule; access to customer content specifically is limited to what's needed to operate and support the service, and is logged.

Immutability with Object Lock

Object Lock uses a write-once-read-many (WORM) model: once an object is locked with a retention period, it can be read but not modified or deleted by anyone, including a compromised admin account or, deliberately, Storivo itself, until that period ends. It's the backbone of our ransomware-recovery story, and it's covered in more depth in our Object Lock guide.

Redundancy & availability

Objects are replicated across multiple storage nodes as part of the base service. Scale Partner customers can add multi-region replication for workloads that need to survive a full regional event, and that plan carries a 99.9% uptime commitment with service credits, described in our Terms of Service.

Monitoring & incident response

Our infrastructure is monitored for the signals that typically precede or accompany an incident: unusual access patterns, failed authentication spikes, and capacity or performance anomalies. If an incident affects customer data or availability, we notify affected customers directly and follow up with what happened and what we changed, not just that service is restored.

Compliance-friendly by design

Object Lock's configurable retention, encryption at rest and in transit, and access logging are built to support workflows that lean on regulatory retention requirements, such as finance, healthcare, and legal holds. Formal compliance documentation is available on request for qualifying accounts; if you have a specific framework you need to map against, tell us in your questionnaire and a specialist will follow up.

Responsible disclosure

If you're a security researcher and think you've found a vulnerability in Storivo, we want to hear about it before anyone else does. Email security@storivo.com with enough detail to reproduce the issue. We'll acknowledge good-faith reports, work with you on a fix, and won't pursue legal action against research conducted in good faith, without accessing or modifying customer data beyond what's needed to demonstrate the issue, and reported to us before any public disclosure.