SealDrop Book a demo

Trust Center

Short answer: your clients' data — files, form answers, records, backups, logs and encryption keys — and your team's logins are stored and processed in AWS Montréal (ca-central-1). We check every AWS region of our production account with an automated inventory and publish the result. Below: the full data map, honest answers to the questions vendor reviews ask, and how to verify.

Data map

DataWhereKeptBackups / copies
Uploaded files and form answers (incl. the answers PDF)Amazon S3, Montréal (ca-central-1), encrypted with a dedicated key that no person can use — only the app and the malware scannerUntil filed, a set time after download, or 30 days unclaimed — 35 days at mostNever backed up; versioning off, no replication
Request records (name, contact details, note, file names)Amazon DynamoDB, Montréal, encrypted with our own key90 days after the filesPoint-in-time backups in Montréal, rolling 35 days
Audit log (IDs, actions, IP address, time — no names or documents)DynamoDB, Montréal2 yearsSame backups
Staff and operator loginsAmazon Cognito, MontréalWhile the account existsManaged by AWS in the same region
Record of every file read and writeAWS CloudTrail → S3, Montréal1 year—
Application logs (IDs only)Amazon CloudWatch Logs, Montréal30 days—
Encryption keyAWS KMS, Montréal——
Malware scanningAmazon GuardDuty, Montréal — scans files in place—No copies made
Staff invitations and password resets (staff email, temporary password)Amazon Cognito’s built-in email sender—Moving to our Montréal sender (Amazon SES); no client data in these
Emails and texts to your clientsSent from Montréal (Amazon SES / End User Messaging)—Delivered through the recipient’s own email or phone provider — so they carry no sensitive information
Website and app code (no personal information)Amazon CloudFront, worldwide edge—Uploads and downloads go straight to Montréal, not through the edge
Web certificate (domain names only)AWS Certificate Manager, US East—Required by CloudFront

How you can verify it

  • Automated inventory, published: the latest residency report (October 4, 2026) lists, for every AWS region, the services that could hold data. Outside Montréal: nothing.
  • Region lock in the code: the infrastructure refuses to build for any region other than ca-central-1, and an automated test checks it on every release.
  • Access records on request: AWS CloudTrail records every read and write of every file; ask and we'll give you the records for your organization's files.
  • Your own audit log: your admins can export who sent, opened, uploaded, downloaded and deleted what.
  • Live walkthrough: during a demo we can show the AWS console for the production account, region by region.
  • Check our website yourself: SSL Labs, Security Headers.

Questions vendor reviews ask

Do you have SOC 2, ISO 27001 or an independent penetration test?

Not of our own yet — SealDrop is a young company and we won't imply otherwise. We run entirely on AWS, whose ISO 27001 and SOC 2 reports for these services are available to AWS customers through AWS Artifact. If your review requires an independent assessment, tell us; it shapes our roadmap.

Is encryption done in the browser (end to end)?

No — a deliberate trade-off. Files travel over TLS and are encrypted at rest in Montréal with a dedicated AWS KMS key. Inside AWS Montréal they are decrypted by machines only, for two things: the malware scan and your signed-in staff’s downloads. No person at SealDrop can use the key. End-to-end encryption would make malware scanning impossible, and we chose scanning.

Can anyone at SealDrop see our clients’ documents?

No person at SealDrop can open uploaded files or answers. They are encrypted with a dedicated AWS KMS key whose rules let only SealDrop’s app functions (for your staff’s downloads) and the malware scanner use it — our own administrator is refused, which we test on every release. Giving anyone access would mean changing the key’s rules or adding a grant: AWS logs that permanently and it emails us an alert at once, as does any direct read or write of a file by a person. The only other route is deploying new app code, which goes through our recorded deployment history. Our operator console shows settings and counts only. Request records (names, contact details) use a separate key our administrator can use for maintenance, with access logged; every file read and write is recorded by AWS CloudTrail for a year, and we can share the records for your files.

Exactly where is our data — including backups, logs and disaster recovery?

In AWS Montréal (ca-central-1): files, records, backups, logs, logins, keys and malware scanning. The service is configured so it cannot be deployed to another region, and an automated inventory of every region in our production account confirms it — latest run October 4, 2026 (see the report).

Does anything leave Canada?

Three things, none of them your clients’ documents: emails and texts pass through the recipient’s own provider (they contain your organization’s name, the link and its expiry — the first name only if you turn that on); the web certificate (domain names only) is issued in AWS US East; and AWS itself is a US-headquartered company operating data centres in Canada.

Do subprocessors outside Canada have access to our data or keys?

No. Our only subprocessor for customer data is Amazon Web Services, in its Canadian region; the encryption key is in AWS KMS in Montréal. Our own email (connect@sealdrop.ca) is hosted separately and is for questions — please never email documents to it; send a SealDrop link instead.

Are files versioned, replicated or backed up?

No. Versioning is off so a delete really deletes, nothing is replicated to another region, and files are never backed up. A storage rule removes anything left after 35 days regardless of settings. Database records have point-in-time backups in Montréal that age out after 35 days.

How fast will you tell us about a breach?

Our data processing agreement commits us to tell your privacy contact without undue delay and within 24 hours of confirming a breach involving your data, and to help you assess and notify.

Do you have an incident response plan and test your security?

Yes, a written incident response plan, and a database restore drill has been run (in our test environment; a production drill is scheduled before onboarding regulated customers). Every release runs automated tests for the security rules: organizations can’t see each other’s data, upload links can only upload, and nothing deploys outside Montréal. Alarms watch for errors, failed deletions, stuck malware scans and abuse.

Is two-step sign-in enforced?

Yes, for every staff and operator account: a password plus an authenticator-app code. Staff sign-ins also block known breached passwords and risky sign-ins.

Can we get your data processing agreement before uploading anything?

Yes. Email connect@sealdrop.ca — every customer signs one before real client data is used.

What do your logs contain?

Application logs and the audit log contain IDs, actions, IP addresses and times — never names, file names, answers or tokens. The website and app use no cookies for tracking and no analytics.

Report a security issue

Email connect@sealdrop.ca with "Security" in the subject (also in our security.txt). We reply within one business day.

More: security and privacy · privacy policy · what “stored in Canada” really means.