Penetration Testing — Cyberglobal
Periodic tests performed by Cyberglobal, a CREST-aligned cybersecurity firm. They validate the platform's resilience under real-world attack scenarios.
This page is built for CISOs, DPOs, compliance officers and professionals evaluating Securoo with the rigour it deserves. No vague claims: real architecture, signed decisions, and the reasoning behind every technical choice.
Encryption happens directly in your browser or mobile app, before any data leaves your device. Securoo cannot decrypt or read your files — not under court order, not in case of a security breach.
When you activate Securoo, a hash+salt login and a unique RSA-OAEP 2048-bit keypair are generated. Data stays cryptographically tied to the rightful owner. No one else can access it — not even Securoo.
When you activate Securoo Business, a mnemonic Recovery Key is generated. It allows recovering access without weakening encryption or surrendering control to third parties. Your data sovereignty stays intact.
The file is split into chunks encrypted locally with random AES-256 keys.
Each AES key is encrypted and signed with your private RSA-OAEP 2048-bit key.
Only encrypted chunks and encrypted keys reach our servers — never plaintext.
To decrypt, your device uses your private key. Securoo doesn't have it.
European infrastructure. Servers and storage are hosted at OVH in France; the immutable backup copy is in Germany. Transactional email runs on our own mail server. Two processors are outside the EU and we name them: Stripe (payments) and Twilio (WhatsApp import, only if you enable it). Neither of them can read your documents — nobody can.
Every operation on a document is recorded with the user, the IP address, the device and the exact time. Signature cases go further: each event is chained to the previous one with a SHA-256 hash, so no record can be altered or removed without breaking the chain — and the chain is recomputed every time it is displayed.
| File | User | Action |
|---|---|---|
| Contract-Fernandez-2024.pdf | [email protected] today, 09:14 | View |
| POA-Herrero-Lopez.pdf | [email protected] today, 08:52 | Sign |
| Defense-Memo-Q1-2025.docx | [email protected] yesterday, 17:38 | Share |
| KYC-Martinez-Holdings.zip | [email protected] yesterday, 14:05 | Download |
| NDA-Tecnova-SL.pdf | [email protected] Mon, 11:20 | Sign |
Each event chained to the previous with SHA-256 · Tamper-evident log, re-verified on every view
Your data lives on high-availability S3 storage in a 3-AZ configuration (99.9999% data resilience). In real time the S3 bucket is replicated to a second bucket with Object Lock (WORM) enabled — the protected copy cannot be altered or deleted, guaranteeing a redundant, tamper-proof backup.
Securoo's security isn't based on self-claims. We submit the platform to periodic external audits by independent third parties.
Periodic tests performed by Cyberglobal, a CREST-aligned cybersecurity firm. They validate the platform's resilience under real-world attack scenarios.
Detailed document on zero-knowledge architecture, encryption flow, RSA-2048 key management, and recovery mechanisms. Available on request.
Our technical team and DPO are available to answer in detail. You can also start protecting your firm today — no credit card required.