Trust Center
Data map
| Data | Where | Kept | Backups / copies |
|---|---|---|---|
| Uploaded files and form answers (incl. the answers PDF) | Amazon S3, Montréal (ca-central-1), encrypted with a dedicated key that no person can use — only the app and the malware scanner | Until filed, a set time after download, or 30 days unclaimed — 35 days at most | Never backed up; versioning off, no replication |
| Request records (name, contact details, note, file names) | Amazon DynamoDB, Montréal, encrypted with our own key | 90 days after the files | Point-in-time backups in Montréal, rolling 35 days |
| Audit log (IDs, actions, IP address, time — no names or documents) | DynamoDB, Montréal | 2 years | Same backups |
| Staff and operator logins | Amazon Cognito, Montréal | While the account exists | Managed by AWS in the same region |
| Record of every file read and write | AWS CloudTrail → S3, Montréal | 1 year | — |
| Application logs (IDs only) | Amazon CloudWatch Logs, Montréal | 30 days | — |
| Encryption key | AWS KMS, Montréal | — | — |
| Malware scanning | Amazon GuardDuty, Montréal — scans files in place | — | No copies made |
| Staff invitations and password resets (staff email, temporary password) | Amazon Cognito’s built-in email sender | — | Moving to our Montréal sender (Amazon SES); no client data in these |
| Emails and texts to your clients | Sent from Montréal (Amazon SES / End User Messaging) | — | Delivered through the recipient’s own email or phone provider — so they carry no sensitive information |
| Website and app code (no personal information) | Amazon CloudFront, worldwide edge | — | Uploads and downloads go straight to Montréal, not through the edge |
| Web certificate (domain names only) | AWS Certificate Manager, US East | — | Required by CloudFront |
How you can verify it
- Automated inventory, published: the latest residency report (October 4, 2026) lists, for every AWS region, the services that could hold data. Outside Montréal: nothing.
- Region lock in the code: the infrastructure refuses to build for any region other than ca-central-1, and an automated test checks it on every release.
- Access records on request: AWS CloudTrail records every read and write of every file; ask and we'll give you the records for your organization's files.
- Your own audit log: your admins can export who sent, opened, uploaded, downloaded and deleted what.
- Live walkthrough: during a demo we can show the AWS console for the production account, region by region.
- Check our website yourself: SSL Labs, Security Headers.
Questions vendor reviews ask
Do you have SOC 2, ISO 27001 or an independent penetration test?
Not of our own yet — SealDrop is a young company and we won't imply otherwise. We run entirely on AWS, whose ISO 27001 and SOC 2 reports for these services are available to AWS customers through AWS Artifact. If your review requires an independent assessment, tell us; it shapes our roadmap.
Is encryption done in the browser (end to end)?
No — a deliberate trade-off. Files travel over TLS and are encrypted at rest in Montréal with a dedicated AWS KMS key. Inside AWS Montréal they are decrypted by machines only, for two things: the malware scan and your signed-in staff’s downloads. No person at SealDrop can use the key. End-to-end encryption would make malware scanning impossible, and we chose scanning.
Can anyone at SealDrop see our clients’ documents?
No person at SealDrop can open uploaded files or answers. They are encrypted with a dedicated AWS KMS key whose rules let only SealDrop’s app functions (for your staff’s downloads) and the malware scanner use it — our own administrator is refused, which we test on every release. Giving anyone access would mean changing the key’s rules or adding a grant: AWS logs that permanently and it emails us an alert at once, as does any direct read or write of a file by a person. The only other route is deploying new app code, which goes through our recorded deployment history. Our operator console shows settings and counts only. Request records (names, contact details) use a separate key our administrator can use for maintenance, with access logged; every file read and write is recorded by AWS CloudTrail for a year, and we can share the records for your files.
Exactly where is our data — including backups, logs and disaster recovery?
In AWS Montréal (ca-central-1): files, records, backups, logs, logins, keys and malware scanning. The service is configured so it cannot be deployed to another region, and an automated inventory of every region in our production account confirms it — latest run October 4, 2026 (see the report).
Does anything leave Canada?
Three things, none of them your clients’ documents: emails and texts pass through the recipient’s own provider (they contain your organization’s name, the link and its expiry — the first name only if you turn that on); the web certificate (domain names only) is issued in AWS US East; and AWS itself is a US-headquartered company operating data centres in Canada.
Do subprocessors outside Canada have access to our data or keys?
No. Our only subprocessor for customer data is Amazon Web Services, in its Canadian region; the encryption key is in AWS KMS in Montréal. Our own email (connect@sealdrop.ca) is hosted separately and is for questions — please never email documents to it; send a SealDrop link instead.
Are files versioned, replicated or backed up?
No. Versioning is off so a delete really deletes, nothing is replicated to another region, and files are never backed up. A storage rule removes anything left after 35 days regardless of settings. Database records have point-in-time backups in Montréal that age out after 35 days.
How fast will you tell us about a breach?
Our data processing agreement commits us to tell your privacy contact without undue delay and within 24 hours of confirming a breach involving your data, and to help you assess and notify.
Do you have an incident response plan and test your security?
Yes, a written incident response plan, and a database restore drill has been run (in our test environment; a production drill is scheduled before onboarding regulated customers). Every release runs automated tests for the security rules: organizations can’t see each other’s data, upload links can only upload, and nothing deploys outside Montréal. Alarms watch for errors, failed deletions, stuck malware scans and abuse.
Is two-step sign-in enforced?
Yes, for every staff and operator account: a password plus an authenticator-app code. Staff sign-ins also block known breached passwords and risky sign-ins.
Can we get your data processing agreement before uploading anything?
Yes. Email connect@sealdrop.ca — every customer signs one before real client data is used.
What do your logs contain?
Application logs and the audit log contain IDs, actions, IP addresses and times — never names, file names, answers or tokens. The website and app use no cookies for tracking and no analytics.
Report a security issue
Email connect@sealdrop.ca with "Security" in the subject (also in our security.txt). We reply within one business day.
More: security and privacy · privacy policy · what “stored in Canada” really means.