Skip to main content

How Files.com Handles Customer Data

Files.com treats customer data as confidential by default. We do not access the contents of customer files, we do not use customer data for marketing or sales, and we apply tightly controlled internal access policies to the systems that store it. This page describes those practices and the responsibilities that fall to the customer under our Shared Responsibility Model.

Customer Data Handling

Files.com does not view, scan, or process the contents of customer-uploaded files unless the customer explicitly authorizes it. Malware Scanning, Content Validation, and TransformScript all work this way.

Customer Data Classification

Files.com cannot know what data you store in the platform. Classifying that data, including identifying whether it contains sensitive information such as PII, PHI, or copyrighted material, is your responsibility as the customer. See the Shared Responsibility Model for the full split.

Metadata Access for Support and Operations

Files.com Customer Support and Engineering staff may access configuration settings, logs, and file metadata (not file contents) to troubleshoot issues and ensure system stability. Access is tightly controlled, logged, and granted only as needed.

Internal Data Access is Strictly Controlled

Only select senior, U.S.-based engineers have root access to production systems. These employees are full-time, background-checked, and bound by confidentiality agreements. Root access is not granted until at least one year of tenure, or else executive approval. All direct access is logged.

Multi-Tenant Isolation

Customers share the underlying Files.com infrastructure, while access controls keep each customer's data and configuration logically separate. Files.com applies same-day corrections for critical security issues in shared request-processing components, with changes tested before deployment. Customer Isolation explains Site and Workspace boundaries, administrative access, and intentionally granted access between them.

Reducing Multi-Tenancy via the Files.com Agent

The Files.com Agent can perform file operations in your environment while Files.com continues to provide authentication, permissions, and administration. The transfer and processing path determines where file contents travel and where temporary copies are required.

The Agent is part of ITAR-aligned and CGR-aligned configurations. Work with your Account Executive and Onboarding Engineer to plan the deployment, identify the operations performed in your environment, and configure the connections that remain in the cloud.

Encryption in Transit and at Rest

All customer data is encrypted in transit using HTTPS and at rest using Amazon S3's server-side encryption. Customers on Power and Enterprise plans can also enable GPG encryption for file contents using their own encryption keys.

Customer Data Storage and Redundancy

Files.com stores the contents of customer files in the Amazon S3 Simple Storage Service. Objects are redundantly stored across multiple devices and facilities within an Amazon S3 Region. Amazon S3 regularly verifies data integrity using checksums and repairs any corruption using redundant data.

Metadata Storage and Backup Retention

Files.com stores customer metadata in Amazon Aurora. Multiple hot-backup servers operate across availability zones, and point-in-time restore capabilities are available for the prior 7 days. Full database snapshots are stored in Amazon S3 every 24 hours and retained for at least 7 days. Backups are audited as part of the Backup and Restoration Test Procedure.

Global Acceleration and Data Routing

To improve performance, customer-uploaded data may first pass through the region closest to the user before being stored in the selected storage location. Customers can disable this behavior by turning off Global Acceleration.

No Use of Customer Data for Marketing or Sales

Files.com does not sell customer data or use it for advertising purposes. Device identifiers such as cookies or IP addresses may be used on the public website for analytics and marketing, but this data is not tied to customer-uploaded files and is handled in accordance with applicable privacy laws.

Files.com complies with lawful data disclosure requests under applicable jurisdiction. Our Privacy Officer reviews every request and handles it in accordance with our Privacy Policy.

Privacy Oversight and Contact

Files.com's Privacy Officer is Chief Legal Counsel Chris Chaffin. For privacy-related inquiries, customers may contact: privacy@files.com.