Skip to content

Trust

Trust at AlreadyBack.

One hub for every answer your security team, your auditor, and your data subjects will ask for. Each surface is a real document or control we ship — never aspirational language about what we’ll do later.

What we do and what we never do

What we do

  • Encrypt every backup with AES-256-GCM before it reaches storage
  • Let you hold your own key (BYOK), with crypto-erasure on revocation
  • Prove recovery every month with a Fire Drill
  • Publish our sub-processors — 30 days’ notice before any change

What we never do

  • Let any AI or ML system touch your backed-up content
  • Sell or share your data
  • Keep your data after you delete it
  • Claim a certification we don’t hold

Security

Security

Encryption (AES-256-GCM at rest, TLS 1.3 in transit), isolated production infrastructure with least-privilege access, data residency, a vulnerability disclosure policy — and no AI or ML ever processes your backed-up content.

Read security overview

Provable recovery

Every backup is proven restorable — a monthly Fire Drill dry-runs a full recovery, and a verification report accompanies every backup and every restore.

See how we prove it

Shared responsibility

Line-by-line split of who owns what across identity, encryption, backup integrity, residency, recovery, and deletion. Designed to simplify vendor security reviews.

See the split

Compliance & privacy

Compliance posture

GDPR and CCPA/CPRA supported by design, a published sub-processor list, and the data categories we refuse. What we hold ourselves to today — the controls we run, not badges we might pursue.

View compliance details

Data Processing Agreement

A self-serve DPA with the EU Standard Contractual Clauses and the UK Addendum. Read it in full, or request a countersigned copy for procurement.

Read DPA

Sub-processors

The list of every third party that processes data on our behalf — including each one’s purpose and the data categories involved — and 30 days’ notice before any change. A transparent supply chain.

View sub-processors

Privacy Policy

What we collect, how we protect it, how long we keep it, and the rights you have over it. Plain English, no fine print.

Read privacy policy

Exercise your data rights

Request access, rectification, erasure, portability, restriction, or objection under GDPR and CCPA. We respond within 30 days (GDPR) or 45 days (CCPA/CPRA).

Submit a privacy request

Need something specific?

Vendor due-diligence questionnaire, documentation under NDA, a custom DPA clause, or a security review call — point us to the row, ask us the question, we respond.

Security & compliance contact
security@alreadyback.com

To report a vulnerability, see the disclosure policy on our Security page. For data rights, use our privacy request page. For service status, our status page.