Security
Security at AlreadyBack.
Active resilience starts with security we can prove, not just claim. Here’s what’s in place, and how to reach us if you find something.
- Encryption at rest
- AES-256-GCM
- In transit
- TLS 1.2 or higher
- Storage regions
- United States or EU
- Fire Drill
- Monthly
- Verification
- Every backup & restore
- AI on your content
- Never
- Bring your own key
- Yes, on Resilience
Controls
See our shared responsibility model for the line-by-line split, and our sub-processor list for every vendor in scope. Additional security documentation — architecture, controls, and risk assessments — is available to enterprise customers under NDA. Contact security@alreadyback.com.
What we design for.
Backup exists because things go wrong. Our controls start from the assumption that they will:
- Credentials can leak.
- A source platform can go down or lose data.
- People delete data by accident.
- APIs change under you.
Encryption before storage, bring-your-own-key, provable recovery, and a monthly Fire Drill are the answers to those assumptions — not add-ons.
Report a vulnerability.
Found something that could compromise our customers? Tell us. We triage every report in good faith and will not take legal action against researchers who follow good-faith disclosure: contact us first, give us a reasonable time to fix, and don’t access data beyond what’s needed to demonstrate the issue.
Encrypt sensitive findings to our PGP key — fingerprint 1EFF7D26E0366893D098D482CB15E0BC56112DC6 (expires April 2028). Email us for the public key.
In scope
- alreadyback.com and its subdomains (marketing, app, authentication)
- api.alreadyback.dev (the public API)
Out of scope
- Third-party services we use (cloud, DNS, email, payments) — report those to the provider
- Denial of service, volumetric or resource-exhaustion testing
- Social engineering or phishing of our staff, customers, or providers
- Physical attacks, and findings that require a compromised device or account to begin with
Rules of engagement
- Test only against accounts and data you own or are authorized to use — never against another customer's backups
- Stop at the first evidence of a vulnerability; do not access, copy, or alter data beyond what proves the issue
- No automated scanning that degrades the service for others
- Report privately first and give us the time below to fix before any publication
What we commit to
- Acknowledgment within 48 hours, triage within 7 days, and a named contact for the life of the report
- Fix targets: critical 30 days, high 60 days, moderate 90 days — we tell you when the fix ships
- Credit, if you want it, once the issue is resolved
- Coordinated disclosure: we ask for 90 days from acknowledgment, or until the fix ships, whichever comes first
Safe harbor
Security research that follows this policy is authorized. We will not pursue legal action against you for it, and we will not refer you to law enforcement for it. If a third party takes action against you for research done in good faith under this policy, we will say so.
No bounty — yet
We do not run a paid bug bounty program today. We say so rather than imply one. What we offer is a fast, honest response and public credit.
Machine-readable contact for automated tooling: /.well-known/security.txt (RFC 9116).
Security is never finished.
We publish the controls we operate today, not the certifications we may pursue tomorrow. If a control changes, this page changes with it.