Security

Encrypted before it leaves your device.

Backup is only useful if it is trustworthy. This page describes how Nuvanta Cloud handles your data, in plain terms and without claims we cannot support.

  1. Your file

    On your computer

  2. Encrypted on device

    AES-256 or equivalent

  3. Secure transfer

    TLS 1.3

  4. Encrypted cloud storage

    Redundant object storage

Encryption modes

Two modes. One irreversible trade-off.

Standard protection

Designed for convenience. Your data is still encrypted on your device, but Nuvanta Cloud manages key custody so that account recovery is possible if you forget your password.

Private Key Mode

Maximum privacy. Only you possess the encryption key. No support agent, process or legal request can produce your file contents.

If you lose your private encryption key, Nuvanta Cloud cannot recover it.

Architecture

How the pieces fit together.

  1. 01

    Desktop client

    Encrypts and chunks

  2. 02

    Encrypted backup API

    Authenticated ingest

  3. 03

    Metadata service

    File index and versions

  4. 04

    Object storage cluster

    Encrypted objects

  5. 05

    Redundant storage

    Multi-node replication

Implementation specifics — vendors, key hierarchy details and network topology — are deliberately not published here.

Encryption

Files are encrypted on your device with AES-256 or an equivalent modern cipher before any data is transmitted. Transfers use TLS. Data at rest remains encrypted in object storage, and encryption keys are stored separately from the data they protect.

Authentication

Accounts use password authentication with two-factor authentication available, session revocation, and notification of new sign-ins. Administrative actions in business accounts require an authenticated session with the appropriate role.

Infrastructure

Backup data is stored on redundant object storage across multiple failure domains. Metadata and file content are handled by separate services so that a compromise of one does not trivially yield the other. Specific vendor and topology details are shared with business customers under NDA.

File integrity

Every uploaded chunk is checksummed on the client and re-verified on receipt. Stored objects are periodically re-verified against their recorded hashes, and mismatches are repaired from redundant copies.

Version history

Historical versions are retained for the window included in your plan. History is append-only from the client's perspective: the desktop agent cannot rewrite or purge past versions, which is what makes ransomware rollback possible.

Account security

Destructive actions — deleting a device, cancelling retention, changing encryption mode — require re-authentication and are recorded in the account activity log with a delay before they take effect.

Data residency

India data residency is available on eligible plans. The storage region for each device is shown in your account before the first backup runs and does not change silently.

Disaster recovery

Backups are replicated so that the loss of a single storage node or facility does not lose customer data. Restore capacity includes physical drive shipment for datasets too large to download comfortably.

Responsible disclosure

Report suspected vulnerabilities to security@nuvanta.in. We will acknowledge reports, work with you on a fix, and will not pursue action against good-faith research that avoids privacy violations and service disruption.

Privacy

We collect the minimum needed to run backups and bill correctly. File contents are not scanned, mined or used for training. In Private Key Mode we cannot read your files at all.

Certifications

Nuvanta Cloud does not currently hold ISO 27001 or SOC 2 certification. Formal audit is planned and we will publish the scope and date when the process begins. We would rather say that than imply otherwise.

Ask a security question