Does Fastio train AI models on my files? +
No. Your files, conversations, and metadata are never used to train AI models, ours or anyone else's. Our AI model providers, listed on the subprocessors page, don't train on customer data either.
Is my data encrypted? +
Yes. All customer data is encrypted at rest with AES-256, and all connections to Fastio are encrypted with TLS.
What is Fastio's SOC 2 status? +
We are actively preparing for a SOC 2 Type II audit and are in the process of engaging an auditor. Fastio is validated under Google CASA at Assurance Level 1 today, and our data center provider holds SOC 2 Type II.
What is CASA? +
The Cloud Application Security Assessment is the App Defense Alliance framework Google uses to vet apps that access sensitive user data. Built on the OWASP Application Security Verification Standard (ASVS), it assesses the application itself. Fastio is validated at Assurance Level 1 (AL1).
How does Fastio handle GDPR? +
Fastio is GDPR-aligned, with defined deletion windows, encryption, role-based access, legal holds, and self-service closure of accounts and organizations. Our standard Data Processing Agreement is published for review and is executed with Enterprise Plus customers and customers with a separately signed agreement on request, and our list of subprocessors is published on this site.
How long does Fastio keep deleted data? +
Deleted data is permanently purged after a grace period: 15 days for shares, 30 days for workspaces, 60 days for organizations, and 90 days for user accounts. An organization with a billing subscription history (including a trial) is kept for 180 days, and so are its shares and workspaces. An organization that Fast closes because a subscription was never started is purged after 7 days, along with its shares and workspaces. A user account that owns an organization still awaiting deletion is not purged until that organization is. That covers file storage, search indexes, AI indexes, and metadata. Some data is kept longer: data under a legal hold, until the hold is released; e-signature envelopes and their records, for up to seven years; billing and tax records, as the law requires; usage records, for up to 120 days; activity history and audit records, as needed for security, audit, and legal purposes; backups, which contain account and file metadata but not file contents, for no longer than one year and restored only for disaster recovery; and copies held by Sub-processors, which are deleted on their own schedules. Our Data Deletion Policy has the details.
Does Fastio support single sign-on? +
Yes, on Enterprise plans: SAML 2.0 or OpenID Connect, with SCIM 2.0 provisioning, DNS-verified domains, and optional SSO enforcement. Two-factor authentication with an authenticator app is available on every plan.
What security alerts does Fastio send? +
On Enterprise plans, Fastio alerts you to sign-ins from new countries, unusual download or deletion activity, and newly created credentials. Each alert is emailed to your owner and admins, and by default to your compliance auditors, and is written to the audit log.
How do I report a security issue? +
Email security@fast.io. For a walkthrough of workspaces, permissions, and the audit log, book a demo with our team.
Can you share more detail under NDA? +
Yes, further detail on our controls and architecture is available under NDA for your security review. Tell us what your review needs at fast.io/contact, or email security@fast.io.