Security architecture and controls

Control over keys, access and recovery.

The premium offering specifies a vault encrypted on devices, access governance and a recovery procedure. Server-side antivirus scanning covers the Drive and authorised uploads; it must not read the contents of the Vault. The deployment file sets out the permissions, procedures and acceptance checks.

Confidentiality, access and continuity

Encryption on devices, control of identities and document recovery: discover the choices behind the premium offering.

01

Your keys, your control

Vault architecture: encryption and decryption on authorised devices, keys controlled by your organisation and recovery kept separate from the account. Storage receives the encrypted files.

Understand the key model

02

Phishing-resistant access

Passkeys, revocable sessions, permissions by organisation and approval of sensitive actions. SSO integration in the Enterprise plan ties access to the lifecycle of your employees.

Manage AI-related risks

03

Recovery that gets tested

Backups at Infomaniak in a separate administration account, a restore procedure and checks on restored permissions. Enterprise includes a quarterly exercise within its scope.

Prepare for recovery after an attack

Three pillars

  • Identity through passkeys

    Public-key authentication, revocable sessions, an additional step for sensitive actions (export, deletion, new device).

  • Separation of organisations

    Each organisation is a boundary checked on every access, not merely an identifier sent by the browser.

  • Upload checks

    Every file uploaded by a client stays in quarantine until the antivirus has returned its verdict. An infected file is rejected and erased, never made available.

What we aim to prevent

  • Client A obtaining the files or AI answers of client B.
  • A stolen sharing link remaining usable after it has been revoked.
  • A booby-trapped file uploaded by a third party reaching a staff member’s workstation.
  • A privileged operator accessing content without a trace or justification.

The full register of risks and measures is available for technical review.

Audit status

No independent audit has been completed so far. Three internal security reviews of the code have been carried out; an external penetration test is planned before a first portal is opened to real data.