Security

How we protect data in transit, at rest, and in between.

Encryption

All transport uses TLS 1.3. Data at rest is encrypted with AES-256-GCM. With client-side encryption enabled, keys are derived on your machines and never transmitted.

Immutability

Snapshots are written once and cannot be altered or deleted before their retention window expires, including by an account administrator. This is the primary defence against ransomware that targets backups.

Isolation

Each tenant's data is separated by a distinct key hierarchy. Storage nodes never hold plaintext for client-side-encrypted tenants.

Compliance

We maintain SOC 2 Type II and undergo annual third-party penetration testing. Reports are available to Scale tier customers under NDA.

Reporting a vulnerability

Write to security@connecto.uk. We acknowledge within one business day and do not pursue legal action against good-faith research.