Security · Technical architecture

Securoo's security,
explained without omissions.

This page is built for CISOs, DPOs, compliance officers and professionals evaluating Securoo with the rigour it deserves. No vague claims: real architecture, signed decisions, and the reasoning behind every technical choice.

Client-side encryption
AES-256 (GCM)
Identity keys
RSA-OAEP 2048
Model
Zero-knowledge
Zero-knowledge encryption

Keys never pass through our servers.

Encryption happens directly in your browser or mobile app, before any data leaves your device. Securoo cannot decrypt or read your files — not under court order, not in case of a security breach.

Each user has their own keypair

When you activate Securoo, a hash+salt login and a unique RSA-OAEP 2048-bit keypair are generated. Data stays cryptographically tied to the rightful owner. No one else can access it — not even Securoo.

Mnemonic Recovery Key

When you activate Securoo Business, a mnemonic Recovery Key is generated. It allows recovering access without weakening encryption or surrendering control to third parties. Your data sovereignty stays intact.

  1. 1

    The file is split into chunks encrypted locally with random AES-256 keys.

  2. 2

    Each AES key is encrypted and signed with your private RSA-OAEP 2048-bit key.

  3. 3

    Only encrypted chunks and encrypted keys reach our servers — never plaintext.

  4. 4

    To decrypt, your device uses your private key. Securoo doesn't have it.

100%
European infrastructure.
Data sovereignty

European infrastructure. Servers and storage are hosted at OVH in France; the immutable backup copy is in Germany. Transactional email runs on our own mail server. Two processors are outside the EU and we name them: Stripe (payments) and Twilio (WhatsApp import, only if you enable it). Neither of them can read your documents — nobody can.

Is your firm truly protected against the regulator? Answer 5 questions and get a GDPR compliance diagnosis in 3 minutes. No signup.
Take the free test
Traceability & audit

Every access, recorded.

Every operation on a document is recorded with the user, the IP address, the device and the exact time. Signature cases go further: each event is chained to the previous one with a SHA-256 hash, so no record can be altered or removed without breaking the chain — and the chain is recomputed every time it is displayed.

  • File openings and downloads with IP, device and timestamp
  • Permission changes and share links, created and revoked
  • Hand-signed documents tied to the SHA-256 fingerprint of the exact file
  • Downloadable traceability certificate (PDF) that anyone can re-verify independently
FileUserAction
Contract-Fernandez-2024.pdf [email protected] today, 09:14 View
POA-Herrero-Lopez.pdf [email protected] today, 08:52 Sign
Defense-Memo-Q1-2025.docx [email protected] yesterday, 17:38 Share
KYC-Martinez-Holdings.zip [email protected] yesterday, 14:05 Download
NDA-Tecnova-SL.pdf [email protected] Mon, 11:20 Sign

Each event chained to the previous with SHA-256 · Tamper-evident log, re-verified on every view

Continuity & backup

Your data, redundant and recoverable.

Real-time backup on WORM-locked S3

Your data lives on high-availability S3 storage in a 3-AZ configuration (99.9999% data resilience). In real time the S3 bucket is replicated to a second bucket with Object Lock (WORM) enabled — the protected copy cannot be altered or deleted, guaranteeing a redundant, tamper-proof backup.

  • 99.9999% data resilience — S3 across 3 availability zones
  • Real-time replica to a WORM-locked (Object Lock) bucket
  • Deleted files recoverable within 30 days, via our support team
Pentesting & external audits

Security verified by independent third parties.

Securoo's security isn't based on self-claims. We submit the platform to periodic external audits by independent third parties.

Penetration Testing — Cyberglobal

Periodic tests performed by Cyberglobal, a CREST-aligned cybersecurity firm. They validate the platform's resilience under real-world attack scenarios.

Technical whitepaper

Detailed document on zero-knowledge architecture, encryption flow, RSA-2048 key management, and recovery mechanisms. Available on request.

Avoid fines up to €20M for non-compliance with GDPR Article 32. Securoo's end-to-end encryption minimises the impact of security breaches and insider threats, placing you above the required compliance threshold.
Want to review the technical whitepaper? Our team sends it within 24 hours.
Request the whitepaper

More specific technical questions?

Our technical team and DPO are available to answer in detail. You can also start protecting your firm today — no credit card required.