Skip to main content

Security & Compliance

From encryption to decentralized storage, every layer of our platform is built to ensure that only you control your data while meeting global compliance requirements.

Data Protection

Data is protected in transit, addressed by cryptographic hash, and retrievable only through explicit permission grants.

Multi-Layer Protection

  • Transport layer security for all API and gateway traffic
  • Content addressing - Every artefact is identified by its cryptographic hash
  • Ledger anchoring - Hashes are notarized on-chain, making tampering detectable
  • Permissioned retrieval - Access is gated by vault, stream and asset permissions

Standards

  • TLS 1.3 for transport security
  • SHA-256 for content hashing
  • ECDSA (secp256k1) for signatures

Decentralized Storage

Filedgr uses IPFS to distribute encrypted data across a global node network, ensuring redundancy and no single point of failure.

Benefits of IPFS

  • No single point of failure - Data distributed across multiple nodes
  • Content addressing - Files identified by cryptographic hash
  • Automatic deduplication - Identical files stored only once
  • Global accessibility - Retrieve from nearest available node

Storage Flexibility

The platform's attestation can be applied to data stored:

  • On-premise - Your own servers and infrastructure
  • In the cloud - AWS, Azure, Google Cloud, or other providers
  • On decentralized networks - IPFS, Arweave, or similar protocols

You maintain complete control over where your data physically resides.

Granular Access Control

You decide exactly who can access what and when. Control who accesses your data with flexible, role-based permissions and advanced security features.

Permission Levels

Vaults and assets use OWNER, ADMIN, EDITOR, VIEWER; vaults additionally support CUSTOM. Streams use ADMIN, EDITOR, VIEWER.

  • OWNER - Full control, including transfer
  • ADMIN - Full control including permission management
  • EDITOR - Modify content and add data
  • VIEWER - Read-only access to data
  • CUSTOM - Vault-level grant used for scoped stream collaboration

Access exists only where a grant has been made — there is no explicit "no access" level to assign.

Access Features

  • Explicit grants only - Absence of a grant means no access
  • Revocation - Grants can be revoked at any time by a vault or asset admin
  • On-chain enforcement - Vault and stream permissions are settled on the ledger
  • Activity logging - Permission changes are recorded with actor and timestamp

Multi-Factor Authentication

Enhance account security with multiple authentication options:

Account sign-in is handled by our identity provider, which issues the session token the platform verifies on every web and mobile request. The identity factors available to your users — email passwordless, social login, and any MFA policy — are the ones configured on the verifier for your tenant.

Machine-to-machine access uses API key and secret credentials instead, which are not subject to interactive sign-in. See Authentication.

Compliance & Regulations

Filedgr is built with privacy-by-design principles, and is designed to support customers operating under regulatory frameworks such as GDPR and CCPA.

GDPR Compliance

  • Data minimization - Collect only necessary data
  • Purpose limitation - Use data only for stated purposes
  • Consent management - Clear opt-in/opt-out mechanisms
  • Right to erasure - Delete personal data on request
  • Data portability - Export data in standard formats
  • Privacy by design - Built-in privacy protections

Other Standards

  • CCPA - Designed to support California Consumer Privacy Act obligations
  • ISO 27001 - Certification readiness underway

Verifiable Integrity

Filedgr's core guarantee is integrity: proof that a file is exactly the file that was notarized, checkable by anyone you share the evidence with.

Key Principles

  • Content addressing - Every artefact is identified by its cryptographic hash
  • Ledger anchoring - Hashes are anchored on-chain, so later tampering is detectable
  • Permissioned retrieval - Access is gated by vault, stream and asset permissions
  • Independent verification - A recipient can re-check the hash and the transaction without trusting Filedgr

How it works

Your File → Hash → Anchored On-Chain → Anyone Can Verify
note

Integrity and confidentiality are distinct guarantees. Where your data carries confidentiality requirements of its own, encrypt it before notarizing, so the proof covers ciphertext that stays under your control.

Audit & Monitoring

Real-time monitoring and immutable audit logs provide transparency and compliance-ready evidence.

Real-Time Monitoring

  • Access attempt logging - Every login and data access
  • Permission change tracking - Who modified what permissions
  • Data modification alerts - Notifications of changes
  • Suspicious activity detection - Unusual access patterns

Audit Trail Features

  • Immutable logs - Cannot be altered after creation
  • Blockchain anchoring - Cryptographic proof of log integrity
  • Detailed timestamps - Precise timing of all events
  • User attribution - Clear identification of actors
  • Export capabilities - Logs available in multiple formats

Compliance Reporting

  • Automated reports for regulatory requirements
  • Custom dashboards for security teams
  • Alert configurations for policy violations
  • Integration APIs for SIEM systems

Network Security

Filedgr’s infrastructure is protected against threats to ensure continuous availability and data integrity.

Infrastructure Protection

  • Managed cloud infrastructure - Hardened, continuously patched platform services
  • CDN delivery - Global content delivery for published assets

API Security

  • Authentication required - No anonymous access to the partner API
  • Request validation - Every request body is schema-validated before processing
  • Server-to-server credentials - API credentials are not usable from a browser
  • Constant-time credential comparison - Secrets are compared without timing leaks

Incident Response

Filedgr maintains a robust incident response plan to detect, contain, and recover from security events.

Response Plan

  1. Detection - Automated monitoring and alerting
  2. Assessment - Determine scope and severity
  3. Containment - Isolate affected systems
  4. Investigation - Root cause analysis
  5. Recovery - Restore normal operations
  6. Communication - Notify affected users

User Notifications

  • Security alerts for account-specific issues
  • Platform updates for system-wide events
  • Resolution status - Progress updates during incidents
  • Post-mortem reports - Lessons learned and improvements

Data Retention & Deletion

Filedgr balances user control with compliance needs, ensuring secure deletion while maintaining auditable records.

How Deletion Works

  • File Removal -You can remove files from active storage immediately.
  • Metadata Preservation - However, for audit and compliance purposes, the permanent blockchain verification records remain preserved. This ensures regulatory proof even after a file is deleted.
  • Cryptographic Erasure: - When files are removed from our systems, cryptographic erasure is used to make the data unrecoverable, ensuring secure deletion.

Retention & Recovery Policies

  • User-Controlled Retention: - You can set your own data lifecycle and automatic expiration policies to align with your needs.
  • Grace Period Recovery: - Deleted files are recoverable for a grace period, which may vary depending on your subscription tier. This allows you to restore accidentally deleted data.
  • Legal Hold: - For compliance and legal requirements, data can be placed on a legal hold, preserving it beyond standard retention policies.

Balancing User Control & Compliance

Our policies are designed to meet both user expectations and strict regulatory standards.

  • GDPR Right to Erasure: - We respect a user’s right to request the deletion of personal data.
  • Audit Trail Preservation: - At the same time, we maintain the integrity of verification records to ensure a complete audit trail for compliance.
  • Account Closure - Even if you close your account, verification records remain preserved to ensure continuous auditability.

Certifications & Standards

Filedgr adheres to industry standards and undergoes regular security assessments to ensure compliance.

Current

  • Privacy by Design - Built into the platform architecture
  • GDPR - Designed to support European privacy requirements

In Progress

  • ISO 27001 - Certification readiness underway

Ongoing Assurance

  • Independent security testing - Performed by external specialists
  • Code security reviews - Automated and manual analysis in the development pipeline

If your procurement process needs current documentation or an assessment report, contact security@filedgr.com.

Getting Help

Security Questions

If you have questions about our security practices:

Compliance Support

Need help with regulatory requirements:

Best Practices

Learn how to maximize security:

Security at Filedgr isn't an add-on feature—it's the foundation everything else is built on.