Security Practices
Last updated: March 26, 2026
At Archil, security is foundational to our cloud filesystem platform. This page describes the technical and organizational measures we use to protect your data. We will expand this page as our security program matures and additional certifications are obtained.
Encryption
In Transit
All data transmitted between your systems and Archil is encrypted using TLS 1.2 or higher. Internal service-to-service communication is also encrypted in transit.
At Rest
All customer data stored within Archil is encrypted at rest using AES-256 encryption. Data replicated to customer-owned S3 buckets inherits the encryption configuration of those buckets.
Infrastructure
Archil runs on Amazon Web Services (AWS) infrastructure, which maintains a comprehensive set of compliance certifications including SOC 2, ISO 27001, and FedRAMP. Our infrastructure is deployed across multiple availability zones for redundancy and durability.
Access Controls
- Access to production systems is restricted to authorized personnel and requires multi-factor authentication
- We follow the principle of least privilege for all internal access
- Access to customer data is logged and auditable
- Employee access is reviewed regularly and revoked promptly upon offboarding
Data Isolation
Customer data is logically isolated. Each customer's data is segregated and inaccessible to other customers. Data is replicated to customer-owned S3 buckets, ensuring customers retain direct control over their data at all times.
Incident Response
We maintain an incident response process for identifying, investigating, and responding to security incidents. In the event of a data breach affecting your data, we will notify you in accordance with our contractual obligations and applicable law.
Vulnerability Management
We regularly scan our infrastructure and application code for vulnerabilities. Security patches for critical vulnerabilities are prioritized and applied promptly.
Responsible Disclosure
If you discover a security vulnerability in Archil, please report it to security@archil.com. We ask that you give us reasonable time to investigate and address the issue before making any public disclosure.
We pay bounties for responsibly disclosed vulnerabilities. Bounty amounts are determined based on the severity and impact of the reported issue. Please include a detailed description and reproduction steps in your report.
Questions
For security-related inquiries, contact security@archil.com.