Security

Secure workspaces for people and AI agents.

Fastio is validated under Google CASA at Assurance Level 1. All customer data is encrypted at rest with AES-256, all connections to Fastio use TLS, and your data is never used to train AI or sold.

VividEngine products are used by teams at companies like these

Samsung
Amazon
Walmart
Target
Autodesk
Logitech
GoPro
The workspace model

Security starts with how your files are organized

AI agents now read, write, and share files alongside your team, so how those files are organized matters for security. In Fastio, every file belongs to a workspace your organization owns, not to anyone's personal account, and access is granted one workspace at a time. Fewer scattered files and forgotten shares leave fewer ways for data to leak, and less for admins to track.

  • Files belong to your organization Every file lives in a workspace your organization owns, so it stays there when someone leaves.
  • Access one workspace at a time Workspaces are isolated from one another. People and agents get a role only in the workspaces they work in.
  • One place to administer Admins manage the organization's members from one place, and one action hands a departing member's access and ownership to a teammate.

Access controls

Two-factor authentication with an authenticator app is on every plan, and access is role-based at the organization, workspace, and share level. Agents and apps connect with OAuth 2.0 and PKCE or with scoped, revocable API keys. Enterprise adds single sign-on over SAML 2.0 or OpenID Connect, with SCIM provisioning.

Data leak protection and threat detection

Uploaded files are scanned for malware, and files found to be infected are blocked from download through shares. Very large files and some binary or data formats may not be scanned. Share links take passwords and expiration dates. Enterprise adds sharing policies, a sharing exposure report, and security alerts for sign-ins from new countries, unusual download or deletion activity, and newly created credentials.

Simplified governance

Content lifecycle management that reduces risk and keeps teams productive: legal holds preserve content for discovery, defined deletion grace periods and permanent purging govern what leaves, and offboarding hands a departing member's access and ownership to a teammate. Legal holds and the compliance auditor role come with Enterprise.

Privacy and compliance

Fastio is independently validated under Google CASA at Assurance Level 1, publishes its Microsoft 365 integration under a Microsoft verified publisher identity, is GDPR-aligned, and acts as a CCPA service provider. Every assessment, framework, and security measure is listed in the Trust Center.

AI security and governance

Fastio's AI works within the permissions of the person or agent using it, so it only reaches files they can already open, and it never trains on your data. Our AI model providers are listed on the subprocessors page, and none of them trains on customer data. On Enterprise, admins can turn off any AI feature, allow AI only in the workspaces they choose, and allow or deny MCP access for AI agents.

Privacy

Your data is yours.

These commitments are not settings you have to find and switch on. They are how Fastio works.

  • We don't train AI on your data.

    Your files, conversations, and metadata are never used to train AI models, ours or anyone else's. Our AI model providers don't train on customer data either.

  • We don't sell your data.

    Your files and account data are never sold to advertisers, data brokers, or anyone else. We protect them from those who would, and keep it simple for you to download and share your files.

  • We don't share your content with partners.

    Your content is never handed to third parties for their own use. The subprocessors on our published list process data only to operate Fastio for you.

  • AI works within your permissions.

    Fastio's AI reaches only the files the person or agent using it can already open.

Security and compliance at a glance

  • Access control

    Two-factor with an authenticator app on every plan, role-based access, and scoped tokens for agents, with single sign-on and SCIM on Enterprise.

  • Leak protection and threat detection

    Workspace-owned files, malware scanning, and share controls, with sharing policies and security alerts on Enterprise.

  • Content lifecycle management

    Built-in information governance for deletion grace periods and audit retention, with legal holds on Enterprise.

  • Compliance

    Google CASA validated (Assurance Level 1), GDPR-aligned, and a CCPA service provider.

  • Encryption

    AES-256 at rest, and TLS for all connections to Fastio.

  • AI security and governance

    AI that stays within each person's or agent's permissions and never trains on your data.

  • Monitoring

    Monitored 24/7 with on-call alerting for critical events. Uploaded files are scanned for malware, and files found to be infected are blocked from download through shares. Very large files and some binary or data formats may not be scanned.

  • Visibility and reporting

    A detailed activity log of actions by people and agents, retained per plan, with export, signed audit events to your SIEM via webhook, and reports on Enterprise.

Every measure in full, in the Trust Center

Further detail on our controls and architecture is available under NDA for your security review. Tell us what your review needs, and we will follow up. Talk to our team

20 Years in cloud storage

20 years in cloud storage and security

The team behind Fastio has spent 20 years building, operating, and securing cloud storage, and Fastio's security model is built on that experience.

Fastio co-founder Derek Labian is the named inventor on two U.S. patents for indexing data across storage providers. See the patents
  • Parent company VividEngine Founded 2006, The Woodlands, Texas
    • MediaFire Cloud storage and file sharing, since 2006 More than 100 million registered MediaFire users
    • Fastio AI project workspaces 2024 launched

Bring your security questions.

Book a demo to walk through workspaces, permissions, and the audit log with our team. Every assessment and security measure is in the Trust Center, and security issues go to security@fast.io.