Cirrus Files

Security

Security is the product. Here is what that means in practice.

Encryption

All files are encrypted client-side with AES-256-GCM. Per-file keys are wrapped with keys derived from your workspace secret. In transit we require TLS 1.2+ with modern cipher suites and HSTS preloading.

Infrastructure

Storage runs on dedicated hardware in ISO 27001 certified data centres in Frankfurt and Amsterdam. Access to production is limited to a small on-call group, requires hardware keys, and is fully logged.

Compliance

Responsible disclosure

Found a vulnerability? Write to security@onekeysec.space. We acknowledge reports within one business day and never pursue researchers acting in good faith.