Security
Secure workspaces for people and AI agents.
Fastio is validated under Google CASA at Assurance Level 1. All customer data is encrypted at rest with AES-256, all connections to Fastio use TLS, and your data is never used to train AI or sold.
VividEngine products are used by teams at companies like these
Security starts with how your files are organized
AI agents now read, write, and share files alongside your team, so how those files are organized matters for security. In Fastio, every file belongs to a workspace your organization owns, not to anyone's personal account, and access is granted one workspace at a time. Fewer scattered files and forgotten shares leave fewer ways for data to leak, and less for admins to track.
- Files belong to your organization Every file lives in a workspace your organization owns, so it stays there when someone leaves.
- Access one workspace at a time Workspaces are isolated from one another. People and agents get a role only in the workspaces they work in.
- One place to administer Admins manage the organization's members from one place, and one action hands a departing member's access and ownership to a teammate.
Access controls
Two-factor authentication with an authenticator app is on every plan, and access is role-based at the organization, workspace, and share level. Agents and apps connect with OAuth 2.0 and PKCE or with scoped, revocable API keys. Enterprise adds single sign-on over SAML 2.0 or OpenID Connect, with SCIM provisioning.
Data leak protection and threat detection
Uploaded files are scanned for malware, and files found to be infected are blocked from download through shares. Very large files and some binary or data formats may not be scanned. Share links take passwords and expiration dates. Enterprise adds sharing policies, a sharing exposure report, and security alerts for sign-ins from new countries, unusual download or deletion activity, and newly created credentials.
Simplified governance
Content lifecycle management that reduces risk and keeps teams productive: legal holds preserve content for discovery, defined deletion grace periods and permanent purging govern what leaves, and offboarding hands a departing member's access and ownership to a teammate. Legal holds and the compliance auditor role come with Enterprise.
Privacy and compliance
Fastio is independently validated under Google CASA at Assurance Level 1, publishes its Microsoft 365 integration under a Microsoft verified publisher identity, is GDPR-aligned, and acts as a CCPA service provider. Every assessment, framework, and security measure is listed in the Trust Center.
AI security and governance
Fastio's AI works within the permissions of the person or agent using it, so it only reaches files they can already open, and it never trains on your data. Our AI model providers are listed on the subprocessors page, and none of them trains on customer data. On Enterprise, admins can turn off any AI feature, allow AI only in the workspaces they choose, and allow or deny MCP access for AI agents.
Your data is yours.
These commitments are not settings you have to find and switch on. They are how Fastio works.
-
We don't train AI on your data.
Your files, conversations, and metadata are never used to train AI models, ours or anyone else's. Our AI model providers don't train on customer data either.
-
We don't sell your data.
Your files and account data are never sold to advertisers, data brokers, or anyone else. We protect them from those who would, and keep it simple for you to download and share your files.
-
We don't share your content with partners.
Your content is never handed to third parties for their own use. The subprocessors on our published list process data only to operate Fastio for you.
-
AI works within your permissions.
Fastio's AI reaches only the files the person or agent using it can already open.
Security and compliance at a glance
-
Access control
Two-factor with an authenticator app on every plan, role-based access, and scoped tokens for agents, with single sign-on and SCIM on Enterprise.
-
Leak protection and threat detection
Workspace-owned files, malware scanning, and share controls, with sharing policies and security alerts on Enterprise.
-
Content lifecycle management
Built-in information governance for deletion grace periods and audit retention, with legal holds on Enterprise.
-
Compliance
Google CASA validated (Assurance Level 1), GDPR-aligned, and a CCPA service provider.
-
Encryption
AES-256 at rest, and TLS for all connections to Fastio.
-
AI security and governance
AI that stays within each person's or agent's permissions and never trains on your data.
-
Monitoring
Monitored 24/7 with on-call alerting for critical events. Uploaded files are scanned for malware, and files found to be infected are blocked from download through shares. Very large files and some binary or data formats may not be scanned.
-
Visibility and reporting
A detailed activity log of actions by people and agents, retained per plan, with export, signed audit events to your SIEM via webhook, and reports on Enterprise.
Further detail on our controls and architecture is available under NDA for your security review. Tell us what your review needs, and we will follow up. Talk to our team
20 years in cloud storage and security
The team behind Fastio has spent 20 years building, operating, and securing cloud storage, and Fastio's security model is built on that experience.
Fastio co-founder Derek Labian is the named inventor on two U.S. patents for indexing data across storage providers. See the patentsBring your security questions.
Book a demo to walk through workspaces, permissions, and the audit log with our team. Every assessment and security measure is in the Trust Center, and security issues go to security@fast.io.