Trust & safety

Security at Archivo

Archivo is designed to help protect your account, workspaces, documents, and encrypted content through layered authentication, access controls, encryption options, abuse prevention, and account recovery features.

Last updated: July 11, 2026

Security concerns or vulnerability reports: security@archiv-o.com

1. Our security approach

Archivo uses multiple layers of protection rather than relying on a single security control. These layers may include account authentication, workspace permissions, database and storage access rules, request validation, rate limiting, encrypted connections, client-side encryption features, recovery tools, and security activity records.

Security features and encryption options may vary by subscription plan, platform, configuration, and type of content.

2. Account authentication

Protected Archivo services require a valid authenticated account. Server requests to protected endpoints are checked using signed authentication tokens, and missing, invalid, or expired tokens are rejected.

Accounts may also be restricted, suspended, quarantined, or prevented from using selected features when suspicious activity, incomplete verification, abuse, or a policy violation is detected.

You are responsible for protecting access to your email account, password, device, and any third-party sign-in provider connected to Archivo.

3. Signup and abuse protection

Archivo uses automated safeguards intended to reduce fraudulent registrations, automated abuse, temporary-email accounts, excessive requests, and attempts to bypass account restrictions.

These safeguards may include application verification, email-domain screening, account verification, request limits, device and network risk signals, and temporary or permanent feature restrictions.

To protect these controls, Archivo does not publicly disclose every detection rule, threshold, or risk signal.

4. Personal document protection

Personal documents, folders, attachments, preferences, and related account records are separated by user account.

Archivo’s access rules are designed so that authenticated users can access their own personal content but cannot directly access another user’s private document area.

Certain authorized Archivo administrators or service components may access information where reasonably necessary to operate the service, investigate abuse, provide support, comply with law, or protect Archivo and its users.

5. Workspace access controls

Workspace content is protected through role-based access controls.

Depending on the workspace configuration, members may be assigned roles such as:

  • Owner
  • Administrator
  • Editor
  • Viewer

Owners and administrators can manage members, invitations, roles, and selected permissions. Editors can create or modify permitted workspace content, while viewers generally receive read-only access.

Additional permissions may be required for sensitive actions such as permanently deleting content or emptying a recycle bin.

Workspace owners and administrators are responsible for regularly reviewing members, invitations, roles, and access permissions.

6. Encryption

Archivo uses encrypted connections for supported communication between your device and Archivo’s hosted services.

Eligible plans may also provide application-level encryption for supported personal or workspace content. Archivo’s encryption features use established cryptographic technologies, including AES-256-GCM authenticated encryption.

Encryption protects supported content from unauthorized access, but it does not protect against every possible risk. Content may still be exposed when a device, account, browser session, recovery code, or authorized workspace member is compromised.

7. Personal Vault

Eligible plans may include a passphrase-protected Personal Vault.

Vault encryption is performed using a key derived from the user’s passphrase. The raw vault encryption key is not intentionally stored as plain text. Each encryption operation uses authenticated encryption and a newly generated initialization value.

Archivo cannot guarantee recovery of encrypted content when the vault passphrase and all recovery information have been lost. Users should store recovery information securely and separately from their primary device.

8. Workspace encryption

Eligible business plans may provide additional encryption for supported workspace content.

A workspace data key may be used to encrypt supported content and may be separately wrapped for authorized workspace members. Removing a member or changing workspace access may require key revocation or rotation to fully remove future access.

Workspace encryption coverage depends on the feature, content type, application version, and workspace configuration. Not every record, preview, activity entry, or operational field should be assumed to receive the same application-level encryption.

Archivo does not describe this feature as an absolute guarantee against all forms of access or compromise.

9. Recovery and key rotation

Depending on the plan, Archivo may provide recovery options such as:

  • A one-time recovery phrase
  • Multiple recovery shares requiring a minimum number of shares
  • Vault passphrase changes
  • Encryption-key rotation
  • Workspace recovery controls

Recovery phrases and recovery shares may be displayed only during creation and may not be stored by Archivo in their original form.

Anyone who obtains sufficient recovery information may be able to recover protected content. Recovery materials should never be sent through unsecured messages or stored beside the encrypted files they protect.

10. Security activity records

Eligible plans may provide security activity records for Personal Vault actions such as vault setup, unlocking, locking, recovery, passphrase changes, or encryption setting changes.

These records are intended to contain event information rather than document contents, passwords, passphrases, or encryption keys.

Security records are not guaranteed to capture every account, file, workspace, device, or network event and should not be treated as a complete forensic record.

11. File uploads and processing

Uploaded files are subject to authentication, workspace permissions, account restrictions, file-size controls, storage limits, and other validation rules.

Users must not upload malware, unlawful content, stolen information, unauthorized personal data, or files they do not have permission to process.

Archivo may restrict, quarantine, reject, or remove files or accounts when necessary to protect the service or comply with legal obligations.

12. AI-assisted features

When you intentionally use an AI-assisted feature, Archivo may process the prompts, files, extracted text, document context, or instructions required to perform your request.

Relevant information may be transmitted to configured infrastructure or AI service providers as described in Archivo’s Privacy Policy.

Do not submit confidential, regulated, or third-party information to an AI feature unless you are authorized to process that information and have confirmed that the feature is appropriate for your use case.

AI-generated output should be reviewed before being relied upon.

13. Deletion, version history, and backups

Archivo may provide recycle-bin, history, synchronization, or restoration features for certain types of content. Availability and retention periods may vary.

These features do not guarantee that every deleted, overwritten, corrupted, or encrypted file can be recovered. Content may become permanently unrecoverable after deletion, expiration, key loss, account closure, or removal from available recovery systems.

Users should maintain independent backups of important business, legal, financial, engineering, and personal records.

14. Security incidents

When Archivo becomes aware of a suspected security incident, we may take reasonable steps to investigate, contain, remediate, and document the issue.

Affected users or relevant authorities will be notified where notification is required by applicable law. Information may be temporarily restricted, isolated, or removed while an investigation is in progress.

15. Responsible vulnerability disclosure

Security researchers who believe they have found a vulnerability should report it privately to security@archiv-o.com.

Reports should include:

  • A clear description of the issue
  • The affected page, application, endpoint, or feature
  • Reproduction steps
  • Potential impact
  • Screenshots or proof-of-concept details that do not expose user data

Researchers must avoid accessing, downloading, changing, or deleting information that does not belong to them. Testing must not disrupt Archivo, degrade service availability, send spam, impersonate users, or involve social engineering.

Please allow reasonable time for investigation and remediation before publicly disclosing a vulnerability. Submission of a report does not automatically qualify for payment or a bug bounty unless Archivo has separately published a bounty program.

16. Your security responsibilities

You can help protect your Archivo account by:

  • Using a strong and unique password
  • Protecting your email and sign-in provider
  • Signing out of shared devices
  • Keeping your device, browser, and Archivo application updated
  • Reviewing workspace members and invitations regularly
  • Giving users only the permissions they require
  • Protecting vault passphrases and recovery materials
  • Maintaining independent backups of critical files
  • Reporting unexpected activity promptly

17. Security limitations

No application, cloud service, storage platform, encryption system, or internet transmission can be guaranteed to be completely secure.

Archivo’s safeguards are designed to reduce risk, but they cannot eliminate every possibility of unauthorized access, malware, device compromise, human error, third-party failure, service interruption, or data loss.

18. Changes to these practices

Archivo may update this page as its features, infrastructure, service providers, security controls, or legal obligations change.

Material updates may be communicated through the Archivo website, application, account notice, or email.

19. Contact

For vulnerability reports and technical security concerns:

security@archiv-o.com

For questions concerning personal information and privacy rights:

privacy@archiv-o.com