Skip to main content

Data Encryption & Key Management

Files.com encrypts stored customer data and supports encryption in transit. Whether a connection requires encryption depends on its protocol and customer-controlled settings. Encryption is reviewed annually as part of the Files.com SOC 2 Type II audit.

Encryption in Transit

Encrypted connections protect data while it travels between systems. Some customer-configured connections permit unencrypted transmission, including optional unencrypted FTP and certain Custom SMTP modes.

Web access is protected by HTTPS with TLS 1.2 or TLS 1.3 encryption. Insecure HTTP requests are automatically redirected to HTTPS.

FTP over port 990 requires 2048-bit SSL encryption. FTP over port 21 also supports 2048-bit SSL encryption and requires it by default; customers can optionally allow insecure FTP. SFTP connections use SSH encryption.

API traffic is encrypted using HTTPS with TLS. Webhooks use TLS when their destination is configured with HTTPS.

For Custom SMTP, customers choose whether encryption is required before authentication or message delivery through the SSL Mode setting. Require SSL (Explicit) requires STARTTLS, while Require SSL (Implicit) uses TLS from connection start. The default, Use If Available, can send credentials and messages unencrypted when STARTTLS is unavailable until a certificate-verified STARTTLS connection succeeds. That connection automatically changes the saved setting to Require SSL (Explicit), unless a parent Child Site Management Policy controls it. TLS failures prevent delivery without an unencrypted fallback. Never Use explicitly disables TLS and sends credentials and messages unencrypted. Select a required mode when encryption must be enforced from the first connection.

Encryption at Rest

All customer file contents, including backups, are encrypted at rest using AES-256 encryption.

Sensitive configuration data is also encrypted using AES-256 with randomly generated initialization vectors. This includes:

  • Cloud storage credentials (e.g., AWS S3, Azure Blob, Google Cloud Storage)
  • SMTP credentials
  • Active Directory / LDAP credentials
  • SSL certificate private keys
  • PGP/GPG private keys

Custom Encryption Options

Customers on Power and Enterprise plans may optionally apply customer-supplied GPG encryption keys to specific folders. This adds a layer of encryption that the customer fully controls.

SSL Certificate Management

Customers using a custom domain may request a free SSL certificate from Files.com or provide their own certificate from a trusted provider.

Encryption Key Management

Files.com uses HashiCorp Vault to manage encryption keys and secrets internally. For encryption at rest, key management and escrow are handled using AWS-native services.