Security & Compliance
From encryption to decentralized storage, every layer of our platform is built to ensure that only you control your data while meeting global compliance requirements.
Data Protection
Data is protected in transit, addressed by cryptographic hash, and retrievable only through explicit permission grants.
Multi-Layer Protection
- Transport layer security for all API and gateway traffic
- Content addressing - Every artefact is identified by its cryptographic hash
- Ledger anchoring - Hashes are notarized on-chain, making tampering detectable
- Permissioned retrieval - Access is gated by vault, stream and asset permissions
Standards
- TLS 1.3 for transport security
- SHA-256 for content hashing
- ECDSA (secp256k1) for signatures
Decentralized Storage
Filedgr uses IPFS to distribute encrypted data across a global node network, ensuring redundancy and no single point of failure.
Benefits of IPFS
- No single point of failure - Data distributed across multiple nodes
- Content addressing - Files identified by cryptographic hash
- Automatic deduplication - Identical files stored only once
- Global accessibility - Retrieve from nearest available node
Storage Flexibility
The platform's attestation can be applied to data stored:
- On-premise - Your own servers and infrastructure
- In the cloud - AWS, Azure, Google Cloud, or other providers
- On decentralized networks - IPFS, Arweave, or similar protocols
You maintain complete control over where your data physically resides.
Granular Access Control
You decide exactly who can access what and when. Control who accesses your data with flexible, role-based permissions and advanced security features.
Permission Levels
Vaults and assets use OWNER, ADMIN, EDITOR, VIEWER; vaults additionally support CUSTOM.
Streams use ADMIN, EDITOR, VIEWER.
- OWNER - Full control, including transfer
- ADMIN - Full control including permission management
- EDITOR - Modify content and add data
- VIEWER - Read-only access to data
- CUSTOM - Vault-level grant used for scoped stream collaboration
Access exists only where a grant has been made — there is no explicit "no access" level to assign.
Access Features
- Explicit grants only - Absence of a grant means no access
- Revocation - Grants can be revoked at any time by a vault or asset admin
- On-chain enforcement - Vault and stream permissions are settled on the ledger
- Activity logging - Permission changes are recorded with actor and timestamp
Multi-Factor Authentication
Enhance account security with multiple authentication options:
Account sign-in is handled by our identity provider, which issues the session token the platform verifies on every web and mobile request. The identity factors available to your users — email passwordless, social login, and any MFA policy — are the ones configured on the verifier for your tenant.
Machine-to-machine access uses API key and secret credentials instead, which are not subject to interactive sign-in. See Authentication.
Compliance & Regulations
Filedgr is built with privacy-by-design principles, and is designed to support customers operating under regulatory frameworks such as GDPR and CCPA.
GDPR Compliance
- Data minimization - Collect only necessary data
- Purpose limitation - Use data only for stated purposes
- Consent management - Clear opt-in/opt-out mechanisms
- Right to erasure - Delete personal data on request
- Data portability - Export data in standard formats
- Privacy by design - Built-in privacy protections
Other Standards
- CCPA - Designed to support California Consumer Privacy Act obligations
- ISO 27001 - Certification readiness underway
Verifiable Integrity
Filedgr's core guarantee is integrity: proof that a file is exactly the file that was notarized, checkable by anyone you share the evidence with.
Key Principles
- Content addressing - Every artefact is identified by its cryptographic hash
- Ledger anchoring - Hashes are anchored on-chain, so later tampering is detectable
- Permissioned retrieval - Access is gated by vault, stream and asset permissions
- Independent verification - A recipient can re-check the hash and the transaction without trusting Filedgr
How it works
Your File → Hash → Anchored On-Chain → Anyone Can Verify
Integrity and confidentiality are distinct guarantees. Where your data carries confidentiality requirements of its own, encrypt it before notarizing, so the proof covers ciphertext that stays under your control.
Audit & Monitoring
Real-time monitoring and immutable audit logs provide transparency and compliance-ready evidence.
Real-Time Monitoring
- Access attempt logging - Every login and data access
- Permission change tracking - Who modified what permissions
- Data modification alerts - Notifications of changes
- Suspicious activity detection - Unusual access patterns
Audit Trail Features
- Immutable logs - Cannot be altered after creation
- Blockchain anchoring - Cryptographic proof of log integrity
- Detailed timestamps - Precise timing of all events
- User attribution - Clear identification of actors
- Export capabilities - Logs available in multiple formats
Compliance Reporting
- Automated reports for regulatory requirements
- Custom dashboards for security teams
- Alert configurations for policy violations
- Integration APIs for SIEM systems
Network Security
Filedgr’s infrastructure is protected against threats to ensure continuous availability and data integrity.
Infrastructure Protection
- Managed cloud infrastructure - Hardened, continuously patched platform services
- CDN delivery - Global content delivery for published assets
API Security
- Authentication required - No anonymous access to the partner API
- Request validation - Every request body is schema-validated before processing
- Server-to-server credentials - API credentials are not usable from a browser
- Constant-time credential comparison - Secrets are compared without timing leaks
Incident Response
Filedgr maintains a robust incident response plan to detect, contain, and recover from security events.
Response Plan
- Detection - Automated monitoring and alerting
- Assessment - Determine scope and severity
- Containment - Isolate affected systems
- Investigation - Root cause analysis
- Recovery - Restore normal operations
- Communication - Notify affected users
User Notifications
- Security alerts for account-specific issues
- Platform updates for system-wide events
- Resolution status - Progress updates during incidents
- Post-mortem reports - Lessons learned and improvements
Data Retention & Deletion
Filedgr balances user control with compliance needs, ensuring secure deletion while maintaining auditable records.
How Deletion Works
- File Removal -You can remove files from active storage immediately.
- Metadata Preservation - However, for audit and compliance purposes, the permanent blockchain verification records remain preserved. This ensures regulatory proof even after a file is deleted.
- Cryptographic Erasure: - When files are removed from our systems, cryptographic erasure is used to make the data unrecoverable, ensuring secure deletion.
Retention & Recovery Policies
- User-Controlled Retention: - You can set your own data lifecycle and automatic expiration policies to align with your needs.
- Grace Period Recovery: - Deleted files are recoverable for a grace period, which may vary depending on your subscription tier. This allows you to restore accidentally deleted data.
- Legal Hold: - For compliance and legal requirements, data can be placed on a legal hold, preserving it beyond standard retention policies.
Balancing User Control & Compliance
Our policies are designed to meet both user expectations and strict regulatory standards.
- GDPR Right to Erasure: - We respect a user’s right to request the deletion of personal data.
- Audit Trail Preservation: - At the same time, we maintain the integrity of verification records to ensure a complete audit trail for compliance.
- Account Closure - Even if you close your account, verification records remain preserved to ensure continuous auditability.
Certifications & Standards
Filedgr adheres to industry standards and undergoes regular security assessments to ensure compliance.
Current
- Privacy by Design - Built into the platform architecture
- GDPR - Designed to support European privacy requirements
In Progress
- ISO 27001 - Certification readiness underway
Ongoing Assurance
- Independent security testing - Performed by external specialists
- Code security reviews - Automated and manual analysis in the development pipeline
If your procurement process needs current documentation or an assessment report, contact security@filedgr.com.
Getting Help
Security Questions
If you have questions about our security practices:
- Security Documentation - Detailed technical information
- Contact Security Team - Direct access to security experts
- Report a security concern - Disclose responsibly, directly to our team
Compliance Support
Need help with regulatory requirements:
- Compliance Guide - Step-by-step compliance information
- Contact our compliance team - Talk through your requirements
- Documentation Portal - Complete compliance documentation
Best Practices
Learn how to maximize security:
- Security Best Practices - Recommended configurations
- Training Resources - Security awareness materials
- Integration Security - Secure development practices
Security at Filedgr isn't an add-on feature—it's the foundation everything else is built on.