- Docs
- Compliance
- Shared Responsibility Model
Shared Responsibility Model
Files.com follows a Shared Responsibility Model for platform security and compliance. This model defines which controls and obligations are handled by Files.com, and which remain the responsibility of the customer.
This division is essential to protecting the Confidentiality, Integrity, and Availability (CIA) of your data. Files.com provides the secure infrastructure, tooling, and platform features—but customers must configure and use those tools appropriately to meet their specific compliance and security goals.
Files.com Responsibilities
Files.com is responsible for securing and operating the platform infrastructure, including:
- Physical security of data centers and hardware
- Software, networking, and compute layers
- Platform availability, uptime, and performance
- Internal security controls and continuous monitoring
- Delivery of tools for secure access, storage, sharing, and audit logging
- Ensuring the reliability and functionality of security features we provide
Customer Responsibilities
Customers are responsible for how Files.com is configured and used, including (but not limited to):
- File and folder permissions
- User provisioning, deprovisioning, and training
- SSO / LDAP configuration and settings
- Storage location selection
- Public sharing, expiration, and deletion settings
- IP whitelisting and country-based access restrictions
- Encryption options (e.g., PGP/GPG on supported plans)
- Virus scanning, content classification, and DLP controls
- Governance and compliance configuration
- Automation and integration with remote systems
- Session timeout, SSL configuration, and security policies
These responsibilities reflect the high level of control available within Files.com. You must configure your site to match your internal security, legal, and compliance requirements.
Built-In Security Controls Available to You
Files.com provides a rich set of controls to help meet your security goals, including:
Authentication & Access
- Multiple Two-Factor Authentication (2FA) options
- 2FA enforcement and password policy controls
- SSO/LDAP integrations (multiple per site)
- Session IP pinning and session expiration
Network & Environment
- IP allowlisting and geo-restrictions
- Custom SSL certificates
- Public sharing controls (Share Links, Public Hosting, Inboxes)
Storage & Encryption
- Regional storage selection (account or folder-level)
- PGP/GPG encryption (on supported plans)
- Deleted file retention and expiration policies
Audit & Visibility
- Full user and file history with API export
- File hash values via API
- Access logs and configuration exports