Skip to content

Security

Security at AlreadyBack.

Active resilience starts with security we can prove, not just claim. Here’s what’s in place, and how to reach us if you find something.

Encryption at rest
AES-256-GCM
In transit
TLS 1.3
Storage regions
United States or EU
Fire Drill
Monthly
Verification
Every backup & restore
AI on your content
Never
Bring your own key
Yes, on Resilience

Controls

Encryption

  • AES-256-GCM on every backup, encrypted before it leaves for storage — providers only ever hold ciphertext.
  • TLS 1.3 for all data in transit.
  • Per-organization keys — cryptographic tenant isolation, not just logical separation.
  • In managed mode our systems are technically able to decrypt your backups — used only to run the operations you request, and restricted and logged. Bring your own key to remove that ability.
  • Bring your own key (BYOK) on Resilience: you supply the key, we hold it sealed and use it only for your operations, and you rotate or revoke it anytime — revoking it cryptographically renders the corresponding backups unrecoverable, an instant erasure you control.

Infrastructure

  • Compute infrastructure hardened to documented baseline configurations.
  • Layered network segmentation and least-privilege access across all services.
  • Immutable, integrity-verified production releases — every deploy is a pinned, verified artifact, so what we test is exactly what runs.
  • Every change is peer-reviewed, automatically checked, and vulnerability-scanned before it ships.

Identity & access

  • Least-privilege access to production — granted only when it is needed.
  • Multi-factor authentication required on privileged accounts.
  • Administrative access is restricted, logged, and reviewed periodically.
  • On your side: single sign-on with your identity provider — included with Resilience.

Backups & recovery

  • Daily encrypted backups, kept in the region you choose.
  • A monthly Fire Drill dry-runs a full recovery and verifies that records, relationships, and computed fields come back intact.
  • A verification report on every backup and every restore — you see exactly what was captured or written.

Data residency

  • Pick your storage region at onboarding: United States or European Union.
  • Your encrypted backups stay in the region you choose — never permanently stored outside it.
  • The systems that run backups process data transiently in the United States; the stored copy stays in your chosen region. Your account data is held in the United States.

Specific data-residency requirements? Talk to us about enterprise options.

Monitoring

  • Continuous security monitoring and threat detection.
  • Critical alerts go straight to a human, not a ticket queue.
  • Centralized logging of security events, retained for investigation.
  • Incident notification: if a breach affects your data, we notify you within 24 hours of confirming it, with an update within 72 hours.

Compliance

  • GDPR: we process your data as your processor under a DPA with the EU Standard Contractual Clauses and the UK Addendum — EU or US residency, your choice.
  • CCPA / CPRA: know, delete, correct, and opt out — and we never sell or share personal data.
  • No AI or ML ever processes your backed-up content — contractually committed in our Terms and DPA.
  • A published sub-processor list, with 30 days’ notice before any change.
  • Data we refuse by design: health, children’s, biometric, regulated-financial, and consumer-health data.

Details on the compliance, DPA, and sub-processors pages.

See our shared responsibility model for the line-by-line split, and our sub-processor list for every vendor in scope. Additional security documentation — architecture, controls, and risk assessments — is available to enterprise customers under NDA. Contact security@alreadyback.com.

What we design for.

Backup exists because things go wrong. Our controls start from the assumption that they will:

  • Credentials can leak.
  • A source platform can go down or lose data.
  • People delete data by accident.
  • APIs change under you.

Encryption before storage, bring-your-own-key, provable recovery, and a monthly Fire Drill are the answers to those assumptions — not add-ons.

Report a vulnerability.

Found something that could compromise our customers? Tell us. We triage every report in good faith and will not take legal action against researchers who follow good-faith disclosure: contact us first, give us a reasonable time to fix, and don’t access data beyond what’s needed to demonstrate the issue.

Security contact
security@alreadyback.com

Encrypt sensitive findings to our PGP key — fingerprint 1EFF7D26E0366893D098D482CB15E0BC56112DC6 (expires April 2028). Email us for the public key.

Response times

  • Acknowledgment: within 48 hours.
  • Triage: within 7 days.
  • Fix targets: critical 30 days, high 60 days, moderate 90 days.

Security is never finished.

We publish the controls we operate today, not the certifications we may pursue tomorrow. If a control changes, this page changes with it.