Trust Center

Fastio Trust Center

Fastio's assessments and frameworks, and every security measure in place today, in one place. For how these controls work day to day, see Security. Questions for your review go to security@fast.io.

  • Google CASA validated (AL1)
  • Microsoft verified publisher
  • GDPR-aligned
  • CCPA service provider
Compliance

Assessments and frameworks

What independent parties have assessed and verified, and the laws and frameworks our security program follows.

Google CASA

Independently validated under Google's Cloud Application Security Assessment (CASA), at Assurance Level 1 (AL1).

CASA is the App Defense Alliance framework Google uses to vet apps that access sensitive user data. It is built on the OWASP Application Security Verification Standard (ASVS) and assesses the application itself.

Microsoft verified publisher

Fastio's Microsoft 365 integration is published under a Microsoft verified publisher identity.

Publisher verification means Microsoft has confirmed the identity of the organization that publishes the app.

  • OWASP ASVS and Top 10

    Application security validated against the OWASP Application Security Verification Standard through Google CASA.

  • GDPR and UK GDPR

    Fastio is GDPR-aligned, with defined deletion windows, encryption, role-based access, legal holds, and self-service closure of accounts and organizations.

    DPA Subprocessors

  • CCPA and CPRA

    For customer data, Fastio acts as a service provider and does not sell or share personal information. Our marketing website uses advertising cookies, which visitors can opt out of. Personal information is deleted on verified request, subject to legal exceptions.

  • PCI DSS

    Payments are processed by Stripe, a PCI DSS Level 1 service provider, on a Stripe-hosted checkout. Fastio never stores, processes, or transmits card data.

  • NIST CSF 2.0

    Our security program is mapped to the NIST Cybersecurity Framework 2.0.

  • Responsible AI

    NIST AI RMF and EU AI Act transparency

    AI governance aligned with the NIST AI Risk Management Framework. AI features are clearly disclosed.

  • E-signatures

    ESIGN, UETA, and eIDAS

    Fastio e-signatures are designed to meet ESIGN and UETA requirements, and are Simple Electronic Signatures under eIDAS. Each signing keeps an audit trail.

Infrastructure

Built to be secure from top to bottom

Security depends on the whole stack, not just our code. Here is where your data is stored, what stands in front of it, and where AI runs.

  • Our own servers

    Fastio owns and operates its own servers and network, in long-term leased space at a data center provider that holds SOC 2 Type II, ISO/IEC 27001, and PCI DSS certifications.

  • A global edge in front

    A global edge network with a web application firewall and DDoS mitigation sits in front of every request.

  • AI providers

    AI processing and search embeddings run with the AI providers listed on the subprocessors page, and none of them trains on customer data.

Privacy

Your data is yours.

These commitments are not settings you have to find and switch on. They are how Fastio works.

  • We don't train AI on your data.

    Your files, conversations, and metadata are never used to train AI models, ours or anyone else's. Our AI model providers don't train on customer data either.

  • We don't sell your data.

    Your files and account data are never sold to advertisers, data brokers, or anyone else. We protect them from those who would, and keep it simple for you to download and share your files.

  • We don't share your content with partners.

    Your content is never handed to third parties for their own use. The subprocessors on our published list process data only to operate Fastio for you.

  • AI works within your permissions.

    Fastio's AI reaches only the files the person or agent using it can already open.

Security measures

How Fastio protects your data

The controls in place today, by area. Those marked Enterprise come with the Enterprise plan; the rest are on every plan.

Encryption

  • All customer data is encrypted at rest with AES-256.
  • All connections to Fastio are encrypted with TLS.
  • Encryption keys are held in a dedicated key management system with least-privilege access.

Network and application security

  • A global edge network with a web application firewall and DDoS mitigation sits in front of every request.
  • Production systems are never exposed directly to the internet, and administrative access is identity-verified.

Identity and access

  • Two-factor authentication with an authenticator app, on every plan.
  • Admins can require two-factor authentication for the whole organization or for specific roles. Enterprise
  • Single sign-on over SAML 2.0 and OpenID Connect, with optional SSO enforcement. Enterprise
  • SCIM 2.0 automates user provisioning and deprovisioning. Enterprise
  • Access is role-based at the organization, workspace, and share level, and every request is checked against current permissions.
  • Third-party apps and AI agents connect with OAuth 2.0 and PKCE, with consent to specific scopes.
  • API keys are scoped and revocable, and agent sessions can be reviewed and revoked.
  • Sessions can be revoked, and users can sign out everywhere.
  • Share links support passwords and expiration.

Monitoring and threat protection

  • Infrastructure is monitored 24/7, and on-call engineers are paged for critical events.
  • Uploaded files are scanned for malware, and files found to be infected are blocked from download through shares. Very large files and some binary or data formats may not be scanned.
  • Security alerts for sign-ins from new countries, unusual download or deletion activity, and newly created credentials. Enterprise
  • Member sign-in history, with the time, method, IP address, and country of each sign-in. Enterprise
  • A credential inventory to review and revoke API keys and OAuth grants. Enterprise
  • Force sign-out, which also revokes a person's API keys and OAuth grants. Enterprise

Governance and audit

  • Every action by people and agents is recorded in a detailed activity log, retained according to your plan.
  • Export the audit log as CSV or JSONL. Enterprise
  • Stream signed audit events to your SIEM via webhook. Enterprise
  • Admin policies for sharing, external invitations, location and IP access, API keys, OAuth apps, and AI usage. Enterprise
  • Legal holds preserve a workspace's or a person's data until you release them. Enterprise
  • A compliance auditor role for the audit log, reports, legal holds, and alerts. Enterprise
  • Member activity and sharing exposure reports. Enterprise
  • Offboarding hands a departing member's access and ownership to a teammate.

AI

  • Fastio's AI works within the permissions of the person or agent using it, so it only reaches files they can already open.
  • An organization AI policy can turn off any AI feature, allow AI only in the workspaces you choose, and allow or deny MCP access for AI agents. Enterprise
  • AI processing and document embeddings for search run with the AI providers listed on the subprocessors page.
  • None of our AI model providers trains on customer data, and Fastio never uses customer files, conversations, or metadata to train AI models.

Data lifecycle and resilience

  • Customer data is replicated, with automated failover.
  • Deleted data is permanently purged after a grace period, from file storage, search indexes, AI indexes, and metadata (metadata backups expire within one year).
  • Users can close their account or organization themselves.

Grace period before deleted data is purged

Shares
15 days
Workspaces
30 days
Organizations
60 days
An organization with a billing subscription history (including a trial) is kept for 180 days, and so are its shares and workspaces. An organization that Fast closes because a subscription was never started is purged after 7 days, along with its shares and workspaces.
User accounts
90 days
A user account that owns an organization still awaiting deletion is not purged until that organization is.

Secure development

  • Code changes are reviewed by automated security analysis before they are committed, and static analysis runs in CI.
  • Dependencies are continuously monitored for known vulnerabilities, with written remediation targets.
  • Application security is validated against OWASP ASVS through Google CASA.
20 Years in cloud storage

20 years in cloud storage and security

The team behind Fastio has spent 20 years building, operating, and securing cloud storage, and Fastio's security model is built on that experience.

  • Parent company VividEngine Founded 2006, The Woodlands, Texas
    • MediaFire Cloud storage and file sharing, since 2006 More than 100 million registered MediaFire users
    • Fastio AI project workspaces 2024 launched

VividEngine products are used by teams at companies like these

Common security questions

Does Fastio train AI models on my files?

No. Your files, conversations, and metadata are never used to train AI models, ours or anyone else's. Our AI model providers, listed on the subprocessors page, don't train on customer data either.

Is my data encrypted?

Yes. All customer data is encrypted at rest with AES-256, and all connections to Fastio are encrypted with TLS.

What is Fastio's SOC 2 status?

We are actively preparing for a SOC 2 Type II audit and are in the process of engaging an auditor. Fastio is validated under Google CASA at Assurance Level 1 today, and our data center provider holds SOC 2 Type II.

What is CASA?

The Cloud Application Security Assessment is the App Defense Alliance framework Google uses to vet apps that access sensitive user data. Built on the OWASP Application Security Verification Standard (ASVS), it assesses the application itself. Fastio is validated at Assurance Level 1 (AL1).

How does Fastio handle GDPR?

Fastio is GDPR-aligned, with defined deletion windows, encryption, role-based access, legal holds, and self-service closure of accounts and organizations. Our standard Data Processing Agreement is published for review and is executed with Enterprise Plus customers and customers with a separately signed agreement on request, and our list of subprocessors is published on this site.

How long does Fastio keep deleted data?

Deleted data is permanently purged after a grace period: 15 days for shares, 30 days for workspaces, 60 days for organizations, and 90 days for user accounts. An organization with a billing subscription history (including a trial) is kept for 180 days, and so are its shares and workspaces. An organization that Fast closes because a subscription was never started is purged after 7 days, along with its shares and workspaces. A user account that owns an organization still awaiting deletion is not purged until that organization is. That covers file storage, search indexes, AI indexes, and metadata. Some data is kept longer: data under a legal hold, until the hold is released; e-signature envelopes and their records, for up to seven years; billing and tax records, as the law requires; usage records, for up to 120 days; activity history and audit records, as needed for security, audit, and legal purposes; backups, which contain account and file metadata but not file contents, for no longer than one year and restored only for disaster recovery; and copies held by Sub-processors, which are deleted on their own schedules. Our Data Deletion Policy has the details.

Does Fastio support single sign-on?

Yes, on Enterprise plans: SAML 2.0 or OpenID Connect, with SCIM 2.0 provisioning, DNS-verified domains, and optional SSO enforcement. Two-factor authentication with an authenticator app is available on every plan.

What security alerts does Fastio send?

On Enterprise plans, Fastio alerts you to sign-ins from new countries, unusual download or deletion activity, and newly created credentials. Each alert is emailed to your owner and admins, and by default to your compliance auditors, and is written to the audit log.

How do I report a security issue?

Email security@fast.io. For a walkthrough of workspaces, permissions, and the audit log, book a demo with our team.

Can you share more detail under NDA?

Yes, further detail on our controls and architecture is available under NDA for your security review. Tell us what your review needs at fast.io/contact, or email security@fast.io.

Need something for your security review?

Email security@fast.io with your questions, or book a demo to walk through workspaces, permissions, and the audit log with our team.