Trust Center

Security

The controls that protect your account and files, described together with their limits — so you can judge them honestly.

Effective 9 August 2026

European infrastructure

Primary compute and customer storage run in European data centers operated by Hetzner Online GmbH. Internal service traffic uses private networking where the platform supports it; public traffic enters only through controlled TLS endpoints fronted by Cloudflare.

Hosting in Europe keeps customer content under European data-protection law by default. It does not by itself make data immune to every legal process; the Privacy Policy describes how requests concerning data are handled.

TLS 1.3 in transit

All public InfiniDrive endpoints — the marketing site, the drive, the account panel, and the status page — use TLS 1.3 with automated certificate management and strict transport-security headers. Connections from outdated clients that cannot negotiate modern TLS are refused rather than downgraded.

Limitation: InfiniDrive encrypts data in transit and protects infrastructure at rest, but does not currently offer client-side end-to-end encryption. We deliberately do not describe the service as "end-to-end encrypted".

Optional two-factor authentication

Every account can enable time-based one-time passwords (TOTP) in security settings: scan a QR code with any standard authenticator app, confirm one code, and from then on sign-in requires both your password and a current code. Active sessions can be reviewed and revoked from the same settings.

  • Passwords are stored only in hashed form; the control plane never keeps them in plaintext.
  • 2FA is optional today. Losing both password and authenticator makes account recovery deliberately slow — store recovery information safely.

RAID-backed storage redundancy

Customer files live on storage arrays with RAID-level redundancy, engineered to survive individual disk failures without data loss or downtime. Metadata and service databases run on separate managed block storage appropriate to their workload.

Limitation: RAID protects against disk failure, not against deletion, overwriting, ransomware on your devices, or site-level disaster. Version history and deleted-file recovery cover everyday mistakes; independent backups remain the right answer for irreplaceable data.

Automated service monitoring

Automated health checks continuously probe the drive, the account panel, and supporting services. Results feed the public status page at status.infinidrive.app, which anyone can read without an account, and alert the operations team when a check fails. Request identifiers let support trace individual incidents without exposing credentials.

Availability and change control

The platform is engineered to support hundreds of thousands of users: capacity is added ahead of demand, workloads are declaratively managed, and every production change is versioned and reviewed before rollout. These practices reduce operational risk; they do not eliminate every outage scenario, which is why the status page and incident history stay public.

What we do not claim

Honest security means naming boundaries. InfiniDrive currently does not offer client-side end-to-end encryption, does not publish an audited uptime percentage, and holds no third-party certifications. If any of that changes, it will appear here with verifiable detail — not as a marketing line.

Report a security issue

Found a vulnerability? Send a description, the affected URL, reproduction steps, and impact to [email protected]. Please do not access data that is not yours, degrade the service, or publish an unresolved issue before we have had a reasonable chance to fix it. We confirm receipt and keep you informed of the resolution.