QuixiCloud Security Policy
Last Updated: July 10, 2026
Effective Date: May 1, 2026
1. Security Overview
At QuixiCloud, safeguarding your data is the foundational principle of our business. Our security philosophy is built upon a defense-in-depth approach, meaning we employ multiple, overlapping layers of security controls throughout our infrastructure, software, and operational processes. We are committed to continuous improvement, regularly reviewing and enhancing our security posture to stay ahead of emerging threats.
2. Infrastructure Security
Our data storage infrastructure is designed for high availability, resilience, and physical security.
- Main Infrastructure: Our primary managed data centers are located in India.
- Regional Storage Nodes: To optimize latency and ensure redundancy, we maintain regional storage nodes in Singapore, Europe, and the United States.
- Dedicated Servers: QuixiCloud operates on dedicated managed storage servers to prevent cross-tenant virtualization risks.
- Multi-Region Replication: User data is actively replicated across multiple geographic regions to ensure resilience against localized outages or disasters.
3. Encryption Architecture
We employ robust encryption algorithms to ensure your files remain secure against unauthorized access. We support two primary encryption workflows depending on your client platform and configurations:
- Client-Side Encryption (Where Supported): Files are encrypted natively on your device before upload using industry-standard AES-256-CTR. Each file is encrypted with a unique encryption key, and those individual file keys are protected using a master encryption key.
- Upload Replay Mode: For platforms where client-side encryption is not feasible, QuixiCloud temporarily processes plaintext data in memory during the upload process to perform highly secure streaming encryption before writing the data to disk.
In both workflows, our underlying storage providers ultimately store and host only encrypted ciphertext data.
4. Key Management
Cryptographic key management is critical to our security model:
- Master Encryption Key: User data is secured by a hierarchical key structure anchored by a master encryption key.
- Secure Storage: Master keys and sensitive cryptographic materials are stored in secure, highly restricted key management systems.
- Separation of Concerns: Where possible within our architecture, we maintain strict separation between the storage of encrypted file data and the cryptographic keys required to decrypt them.
- Key Rotation: We maintain automated internal key rotation procedures for infrastructure and administrative credentials.
5. Data in Transit
All communications between your devices, our APIs, and our storage nodes are secured using strong Transport Layer Security (TLS). We enforce strict certificate validation and utilize modern cipher suites to protect against eavesdropping, interception, or man-in-the-middle attacks during data transmission.
6. Storage Security
Once your data reaches our servers, it remains protected by multiple safeguards:
- Encrypted File Storage: Data is strictly stored in its encrypted state.
- Replication: Data is mirrored across multiple storage arrays to protect against hardware degradation (such as disk failure or bit-rot).
- Disaster Recovery: We maintain isolated disaster recovery infrastructure to restore service in the event of catastrophic failures.
7. Identity and Access Management (IAM)
We strictly control who can access QuixiCloud internal systems:
- Least-Privilege Principle: Employees and automated systems are granted only the absolute minimum permissions required to perform their specific duties.
- Role-Based Access Control (RBAC): Administrative access is segmented by technical role.
- Multi-Factor Authentication (MFA): MFA is strictly mandated for all administrative and operational staff accessing QuixiCloud infrastructure. (We also highly recommend that Users enable MFA on their own QuixiCloud accounts).
8. Monitoring & Incident Response
We operate continuous surveillance over our infrastructure to detect and respond to anomalies:
- System Monitoring: 24/7 monitoring of network traffic, API endpoints, and storage node health.
- Security Event Logging: Critical infrastructure events are logged and audited to detect potential security breaches.
- Abuse Detection: Automated systems monitor for signs of platform abuse, malicious uploads, or unauthorized automated scraping.
- Incident Investigation: In the event of a security incident, our dedicated response team will conduct a thorough investigation, mitigate the threat, and provide necessary notifications to affected users and regulatory bodies as required by applicable law.
9. Backup & Disaster Recovery
It is important to distinguish between the types of data redundancy we employ:
- Replication (Service Continuity): We replicate data across regions to ensure immediate continuity if a single server fails.
- Disaster Recovery Backups: We maintain encrypted system-wide backups solely for the purpose of restoring QuixiCloud infrastructure. These are not individual file backups and cannot be used to restore a single file that a user accidentally deleted.
- Customer-Managed Backups: Users are responsible for utilizing QuixiCloud’s version history features (where applicable based on free vs. paid plans) to recover accidentally deleted or overwritten files.
10. Vulnerability Management
We actively manage potential vulnerabilities in our software stack:
- Security Updates & Patching: Operating systems, dependencies, and core software are subject to regular, timely security patching.
- Internal Testing: We conduct regular internal security testing and code reviews before deploying updates to production.
- Responsible Disclosure: We welcome reports from security researchers. If you discover a vulnerability, please report it via our dedicated security contact.
11. Physical & Operational Security
While we do not disclose sensitive operational specifics, our infrastructure is hosted in premier, highly secure managed data center environments featuring:
- Strict Access Controls: Biometric scanners, security guards, and logged physical access points.
- Environmental Protections: Advanced climate control, fire suppression, and redundant backup power generators.
- Hardware Lifecycle Management: Secure wiping and physical destruction of decommissioned hard drives.
12. Shared Security Responsibilities
Securing your data is a partnership. We operate under a shared responsibility model.
QuixiCloud is responsible for:
- Infrastructure and physical security.
- Implementing and maintaining encryption systems.
- Platform, API, and network security.
- Ensuring high availability and disaster recovery of the platform.
Users are responsible for:
- Utilizing strong, unique master passwords.
- Protecting their personal devices from malware.
- Enabling Multi-Factor Authentication (MFA) on their QuixiCloud account.
- Carefully managing file-sharing permissions and generated links.
- Keeping independent local backups of critical files where appropriate.
13. Reporting Security Issues
If you believe you have discovered a security vulnerability in the QuixiCloud platform, applications, or infrastructure, please report it immediately. We take all reports seriously and will investigate promptly.
Security Contact: security@quixicloud.com