Trust & security
How we protect the documents you put in Vaultline
This page describes the controls behind the platform, where your data lives, who can reach it, and how we evidence all of it. It is maintained by the security team and reviewed quarterly.
Last reviewed 2 July 2026 · Owner: Chief Information Security Officer · security@fileshare-portal.com
AES-256 / TLS 1.3
Encrypted at rest and in transit, with EU-managed keys.
EU-only residency
Content stays in Tallinn and Helsinki. No transfers outside the EEA.
ISO 27001 & SOC 2
Certified to ISO/IEC 27001:2022; SOC 2 Type II report available.
Evidence on request
Certificates, reports, DPA and pen-test summaries under NDA.
Encryption
In transit. All connections to Vaultline are served over TLS 1.3, with TLS 1.2 retained only for a small number of legacy enterprise proxies on a documented exception basis. We publish HSTS with a one-year max-age and preload, and we do not support TLS 1.0, TLS 1.1, or any cipher suite without forward secrecy. Certificates are issued by a publicly trusted CA and rotated automatically every 60 days.
At rest. Document content, metadata, database volumes and backups are encrypted with AES-256-GCM. Each document object is encrypted with a unique data encryption key; those keys are themselves encrypted by a per-tenant key encryption key held in an HSM-backed key management service operated within the EU. Key encryption keys are rotated annually, and on demand after any personnel change affecting privileged access.
Key custody. No Vaultline employee has access to plaintext key material. Key operations are performed by the KMS and logged. Enterprise customers may additionally hold their own key encryption key under a bring-your-own-key arrangement, in which case revoking the key renders the tenant's content permanently unreadable — including to us.
Data residency
Vaultline operates exclusively in the European Union. Primary processing and storage is in Tallinn, Estonia, with an asynchronous replica and backup region in Helsinki, Finland. Customer content is never processed or stored outside the EEA, and we do not operate regions in the United States or elsewhere.
This extends to our sub-processors. Every sub-processor with access to customer content is established in the EEA and processes that content within it — see the sub-processor list below. Where a support engineer needs to reach production to resolve a ticket, that session originates from within the EU and is recorded.
On onward transfers. Because we hold no data outside the EEA and use no non-EEA sub-processors for customer content, Chapter V transfer mechanisms (standard contractual clauses, transfer impact assessments) are not required for the content you store with us. Our DPA nonetheless includes SCCs to cover the limited corporate administrative data described in our privacy notice.
Certifications and assurance
Vaultline holds the following, and will provide the underlying evidence to customers and prospective customers under a mutual non-disclosure agreement:
| Standard | Scope | Assessor | Status |
|---|---|---|---|
| ISO/IEC 27001:2022 | Information security management system covering the Vaultline platform, supporting infrastructure and corporate functions | Nordaudit Certification AB | Certified — current cycle to March 2027 |
| ISO/IEC 27018:2019 | Protection of personally identifiable information in public cloud processing | Nordaudit Certification AB | Certified — aligned to the 27001 cycle |
| SOC 2 Type II | Security, Availability and Confidentiality trust services criteria | Kestrel Assurance LLP | Report issued annually — most recent covers 1 Apr 2025 to 31 Mar 2026 |
| ISO 22301:2019 | Business continuity management for the platform service | Nordaudit Certification AB | Certified — current cycle to November 2026 |
Certification scope statements and certificate numbers are included in the security pack. Request it from security@fileshare-portal.com or through your account manager.
GDPR posture
For customer content, Vaultline acts as a processor and the customer is the controller. We process content only on documented instructions, which are given through the platform's configuration and through the data processing agreement. For our own website visitors, prospects and employees we act as a controller; that processing is described in our privacy notice.
Our GDPR programme covers:
- A record of processing activities maintained under Article 30, reviewed twice yearly.
- Data protection impact assessments for changes that materially affect processing, with our DPO consulted under Article 35(2).
- Technical and organisational measures documented against Article 32 and appended to the DPA.
- Assistance with data subject rights under Articles 12–23, including export and deletion tooling that customers can operate themselves.
- Personal data breach notification to the customer without undue delay and in any event within 48 hours of confirmation, supporting the customer's own 72-hour obligation under Article 33.
- Sub-processor change notice with a right to object, as set out below.
Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Our Data Protection Officer can be reached at dpo@fileshare-portal.com or by post at the registered address on our contact page, marked for the attention of the DPO.
Data processing agreement
A data processing agreement is available to every customer on every plan, at no cost and without negotiation friction. It is offered in two ways:
- Pre-signed standard DPA. Countersigned and downloadable from your account settings. This is the fastest route and is accepted by most customers as-is.
- Negotiated DPA. For Enterprise agreements we will work through your own paper or mark up ours. Requests go to legal@fileshare-portal.com.
The DPA incorporates our technical and organisational measures, the sub-processor list and terms, breach notification commitments, audit rights, and deletion and return obligations on termination. Customers with an audit right may exercise it once per year, or after a personal data breach, by reviewing our certifications and reports; on-site audits are available to Enterprise customers on reasonable notice.
Sub-processors
We use a deliberately short list of sub-processors, all established and operating within the EEA. We notify customers at least 30 days before adding or replacing a sub-processor, by email to account administrators and by updating this page. Customers may object on reasonable data protection grounds during that period; if we cannot resolve the objection, the customer may terminate the affected service without penalty.
| Sub-processor | Purpose | Location | Customer content? |
|---|---|---|---|
| Kaljas Data Centres AS | Primary compute, storage and network infrastructure | Tallinn, Estonia | Yes |
| Fennecloud Oy | Encrypted backup and disaster recovery region | Helsinki, Finland | Yes (encrypted backups) |
| Relayworks B.V. | Transactional email — invitations, notifications, one-time codes | Amsterdam, Netherlands | Metadata only (names, email addresses, room titles) |
| Signavault SAS | E-signature handoff, where the customer enables it | Lyon, France | Yes, for documents sent to signature |
| Helpdeck GmbH | Support ticketing and customer correspondence | Berlin, Germany | Only what a customer includes in a ticket |
| Metrikly OÜ | Product usage analytics (self-hosted by Vaultline) | Tallinn, Estonia | No — pseudonymised event data only |
| Arvex Billing OÜ | Invoicing and payment processing | Tallinn, Estonia | No — billing contact and payment data only |
To subscribe to sub-processor change notices without being an account administrator, email dpo@fileshare-portal.com.
Penetration testing and vulnerability management
External penetration testing. An independent testing firm assesses the platform on a fixed cadence:
- Annually — full-scope grey-box test of the web application, API and supporting infrastructure, conducted by Silvergate Security OÜ.
- Quarterly — targeted retests of authentication, authorisation and tenant isolation, plus any component that changed materially in the period.
- On significant change — before a new externally reachable service or a material change to the permission model reaches general availability.
A summary letter for the most recent annual test is available to customers and prospects under NDA. We do not publish the full report, because it describes the architecture in a level of detail we are not willing to make public.
Internal practice. Static analysis and dependency scanning run on every pull request; container and host images are scanned continuously and rebuilt weekly. Findings are triaged against CVSS with fixed remediation targets — critical within 72 hours, high within 14 days, medium within 60 days, low at the next scheduled release. We track exceptions formally and review them monthly.
Internal access control
Access to production is granted on a least-privilege basis and reviewed quarterly. All staff authenticate through SSO with phishing-resistant MFA (hardware security keys); passwords alone are never sufficient. Administrative access requires a just-in-time elevation request with a stated reason, is time-boxed, and is recorded as a session.
No employee can read customer document content in the ordinary course of their work. Support staff see room and file metadata — titles, sizes, timestamps — not content. Access to content requires an explicit, logged, customer-authorised break-glass procedure which notifies the customer's account administrators at the time it is used.
Personnel undergo background verification appropriate to their role before joining, sign confidentiality undertakings, and complete security awareness training at induction and annually thereafter. Engineers additionally complete secure development training. Access is revoked within one hour of a leaver event.
Availability and resilience
The platform is deployed across three availability zones in the Tallinn region, with asynchronous replication to Helsinki. Backups are taken continuously, encrypted, and retained for 35 days; restoration is rehearsed quarterly against a documented runbook.
- Recovery point objective: 15 minutes.
- Recovery time objective: 4 hours.
- Service level commitment: 99.9% monthly availability on Business and Enterprise plans, with service credits set out in the terms.
- Rolling 12-month achieved availability: 99.98%.
Planned maintenance is announced at least five business days ahead and scheduled outside 07:00–19:00 CET on business days wherever possible.
Incident response
We operate a documented incident response plan with defined severities, a standing on-call rota and a named incident commander role. The plan is exercised at least twice a year, including one tabletop exercise involving a simulated personal data breach.
In the event of a personal data breach affecting customer content, we notify affected customers without undue delay and within 48 hours of confirming the breach, with the information required by Article 33(3) to the extent known, followed by updates as the investigation proceeds. We do not wait for the investigation to conclude before notifying.
Responsible disclosure
We welcome reports from security researchers and will not pursue legal action against anyone acting in good faith under this policy.
Report to:
security@fileshare-portal.com
PGP: fingerprint A41C 9E52 7B03 D8F1 6AA9 2C74 55BE 0D31 F9A6 47E8,
key available at /.well-known/security.txt
Acknowledgement: within 2 business days ·
Triage: within 5 business days
What we ask. Test only against accounts you own or have permission to use. Do not access, modify or exfiltrate other customers' data — if you encounter customer data, stop and tell us. Do not run denial-of-service, spam or social engineering against our staff or customers. Give us a reasonable period to remediate before publishing.
What we do. We acknowledge within two business days, keep you updated, credit you in our disclosure acknowledgements page if you would like to be named, and confirm when the issue is fixed. We do not currently operate a paid bug bounty, though we send a token of thanks for well-written reports of genuine issues.
Out of scope. Findings from automated scanners without a demonstrated impact, missing security headers on non-sensitive endpoints, rate limiting on unauthenticated marketing pages, and reports about email configuration of domains we do not use for sending.
Security questionnaires
We keep completed CAIQ and SIG Lite responses on file and can usually return a customer questionnaire within five business days. If your procurement team has a standard pack, send it over — we would rather answer it properly once than trade partial answers for a fortnight.
Bring your security team to the first call.
We would rather answer the hard questions early than discover a blocker at contract stage.