Safety and Security

Duckpins Vault - Data Storage, Encryption & Security Policy

Introduction

At Duckpins, we prioritize the security and privacy of your documents. As a leading provider of online document storage solutions, we are dedicated to implementing the highest standards of data protection. This document outlines our comprehensive security and storage standards, which include:

  • Data security and privacy compliance
  • Robust storage infrastructure
  • Stringent access control and authentication
  • State-of-the-art encryption
  • Comprehensive network security
  • Adherence to industry regulations

We continuously enhance our security measures to address emerging threats and ensure your information is protected. We are committed to maintaining transparency and providing you with the confidence you need in our services. In the following sections, we detail the specific standards and practices employed to safeguard your data.

Data protection & encryption

Data at rest

Advanced Encryption Standard (AES) 256-bit encryption. All stored data is encrypted to the highest standard.

Data in motion

We use Transport Layer Security (TLS) encryption protocol, certified by Google Trust Services. This protocol ensures secure delivery of data transferred over the internet. It protects the information being transferred and authenticates the website’s identity. All data also automatically passes through Cloudflare for Distributed Denial of Service (DDoS) Protection.

Data stored in the cloud

We leverage Amazon Web Services (AWS) components to provide reliable fault-tolerant and highly available systems in the cloud. Read more about AWS Cloud Security.

Data ownership

Your information

We appreciate that you have entrusted us with your personal information. We will never share, sell, or transfer any information about you, or any data that you store using our services without your consent or as outlined in our privacy policy.

Data deletion

Your account belongs to you. If you decide that you would like to delete your account, we will send you PDFs of your documents via email and then ensure that all information and documents associated with your account are completely and irreversibly removed (including all backups) within 30 days from your initial request. 

Identity management & authentication

Passwords

Your password secures your account. Additionally, we automatically log users out after an extended period of inactivity so that unauthorized users may not access the account. You are responsible for maintaining the security of your passwords - do not share your login information with anyone. If you wish to share your documents with others, you should do that through your Vault.

Reporting

In the event of a system outage, we have processes in place to help keep all data safe and secure. If you are aware of a security issue affecting Duckpins or our members and you wish to disclose it, email us at hello@duckpins.com. Likewise, if you have any other security concerns, please let us know.