Security
Security at AlreadyBack.
Active resilience starts with security we can prove, not just claim. Here’s what’s in place, and how to reach us if you find something.
- Encryption at rest
- AES-256-GCM
- In transit
- TLS 1.3
- Storage regions
- United States or EU
- Fire Drill
- Monthly
- Verification
- Every backup & restore
- AI on your content
- Never
- Bring your own key
- Yes, on Resilience
Controls
See our shared responsibility model for the line-by-line split, and our sub-processor list for every vendor in scope. Additional security documentation — architecture, controls, and risk assessments — is available to enterprise customers under NDA. Contact security@alreadyback.com.
What we design for.
Backup exists because things go wrong. Our controls start from the assumption that they will:
- Credentials can leak.
- A source platform can go down or lose data.
- People delete data by accident.
- APIs change under you.
Encryption before storage, bring-your-own-key, provable recovery, and a monthly Fire Drill are the answers to those assumptions — not add-ons.
Report a vulnerability.
Found something that could compromise our customers? Tell us. We triage every report in good faith and will not take legal action against researchers who follow good-faith disclosure: contact us first, give us a reasonable time to fix, and don’t access data beyond what’s needed to demonstrate the issue.
Encrypt sensitive findings to our PGP key — fingerprint 1EFF7D26E0366893D098D482CB15E0BC56112DC6 (expires April 2028). Email us for the public key.
Response times
- Acknowledgment: within 48 hours.
- Triage: within 7 days.
- Fix targets: critical 30 days, high 60 days, moderate 90 days.
Security is never finished.
We publish the controls we operate today, not the certifications we may pursue tomorrow. If a control changes, this page changes with it.