How we protect your data
The principles above are the summary. Here's what they mean in practice.
Encryption
Data moving to and from Storivo is encrypted in transit using TLS. Data at rest is encrypted on our storage nodes, so a physical disk or drive removed from our infrastructure isn't readable on its own. This applies across every plan tier; it isn't reserved for higher-priced plans.
Access control & sub-account isolation
Every access key is scoped to a specific account or, for white-label partners, a specific sub-account, so one client's key can't reach another client's data. Internally, employee access to infrastructure follows least-privilege principles and is reviewed on a regular schedule; access to customer content specifically is limited to what's needed to operate and support the service, and is logged.
Immutability with Object Lock
Object Lock uses a write-once-read-many (WORM) model: once an object is locked with a retention period, it can be read but not modified or deleted by anyone, including a compromised admin account or, deliberately, Storivo itself, until that period ends. It's the backbone of our ransomware-recovery story, and it's covered in more depth in our Object Lock guide.
Redundancy & availability
Objects are replicated across multiple storage nodes as part of the base service. Scale Partner customers can add multi-region replication for workloads that need to survive a full regional event, and that plan carries a 99.9% uptime commitment with service credits, described in our Terms of Service.
Monitoring & incident response
Our infrastructure is monitored for the signals that typically precede or accompany an incident: unusual access patterns, failed authentication spikes, and capacity or performance anomalies. If an incident affects customer data or availability, we notify affected customers directly and follow up with what happened and what we changed, not just that service is restored.
Compliance-friendly by design
Object Lock's configurable retention, encryption at rest and in transit, and access logging are built to support workflows that lean on regulatory retention requirements, such as finance, healthcare, and legal holds. Formal compliance documentation is available on request for qualifying accounts; if you have a specific framework you need to map against, tell us in your questionnaire and a specialist will follow up.
Responsible disclosure
If you're a security researcher and think you've found a vulnerability in Storivo, we want to hear about it before anyone else does. Email security@storivo.com with enough detail to reproduce the issue. We'll acknowledge good-faith reports, work with you on a fix, and won't pursue legal action against research conducted in good faith, without accessing or modifying customer data beyond what's needed to demonstrate the issue, and reported to us before any public disclosure.