Trust Center
Security
The controls that protect your account and files, described together with their limits — so you can judge them honestly.
Effective 9 August 2026
European infrastructure
Primary compute and customer storage run in European data centers operated by Hetzner Online GmbH. Internal service traffic uses private networking where the platform supports it; public traffic enters only through controlled TLS endpoints fronted by Cloudflare.
Hosting in Europe keeps customer content under European data-protection law by default. It does not by itself make data immune to every legal process; the Privacy Policy describes how requests concerning data are handled.
TLS 1.3 in transit
All public InfiniDrive endpoints — the marketing site, the drive, the account panel, and the status page — use TLS 1.3 with automated certificate management and strict transport-security headers. Connections from outdated clients that cannot negotiate modern TLS are refused rather than downgraded.
Limitation: InfiniDrive encrypts data in transit and protects infrastructure at rest, but does not currently offer client-side end-to-end encryption. We deliberately do not describe the service as "end-to-end encrypted".
Optional two-factor authentication
Every account can enable time-based one-time passwords (TOTP) in security settings: scan a QR code with any standard authenticator app, confirm one code, and from then on sign-in requires both your password and a current code. Active sessions can be reviewed and revoked from the same settings.
- Passwords are stored only in hashed form; the control plane never keeps them in plaintext.
- 2FA is optional today. Losing both password and authenticator makes account recovery deliberately slow — store recovery information safely.
RAID-backed storage redundancy
Customer files live on storage arrays with RAID-level redundancy, engineered to survive individual disk failures without data loss or downtime. Metadata and service databases run on separate managed block storage appropriate to their workload.
Limitation: RAID protects against disk failure, not against deletion, overwriting, ransomware on your devices, or site-level disaster. Version history and deleted-file recovery cover everyday mistakes; independent backups remain the right answer for irreplaceable data.
Automated service monitoring
Automated health checks continuously probe the drive, the account panel, and supporting services. Results feed the public status page at status.infinidrive.app, which anyone can read without an account, and alert the operations team when a check fails. Request identifiers let support trace individual incidents without exposing credentials.
Availability and change control
The platform is engineered to support hundreds of thousands of users: capacity is added ahead of demand, workloads are declaratively managed, and every production change is versioned and reviewed before rollout. These practices reduce operational risk; they do not eliminate every outage scenario, which is why the status page and incident history stay public.
What we do not claim
Honest security means naming boundaries. InfiniDrive currently does not offer client-side end-to-end encryption, does not publish an audited uptime percentage, and holds no third-party certifications. If any of that changes, it will appear here with verifiable detail — not as a marketing line.
Report a security issue
Found a vulnerability? Send a description, the affected URL, reproduction steps, and impact to [email protected]. Please do not access data that is not yours, degrade the service, or publish an unresolved issue before we have had a reasonable chance to fix it. We confirm receipt and keep you informed of the resolution.
