How your data is protected

Encrypted, and locked against change

Your files are encrypted in storage and while they travel. Files within a retention period are immutable — they cannot be changed or deleted, and a copy of a protected file is protected too. If the lock cannot be applied, the upload fails rather than being stored unprotected.

Deleting early takes two people

Deleting protected data before its retention period ends needs a request from an authorised user and approval from two different administrators. Nobody can approve their own request, and every request, approval and rejection is recorded.

Every download is recorded

Each download is recorded against the person who requested it, with the file and the time. If that record cannot be written, the download is refused. Sign-ins, role changes and searches of the records themselves are recorded too.

We do not read your files

There is no preview feature. Seeing a file's contents means downloading it, so there is no way to read a file without leaving a record. DataFrugal works with metadata only — names, sizes, dates and labels.

Who can reach your data

Roles, not blanket access

Each person gets the permissions their role needs. Every role change is recorded with the permissions before and after. Automation uses its own identities with secret keys, so no human password sits in a script.

Sharing stays inside your organisation

Only a file's owner can share it, only with people in your organisation, and recipients cannot pass it on. Every share is recorded, so the list of people who could see a file is always known.

Download links expire

Download links are valid for a limited time. On team plans you can restrict storage access to approved IP addresses, so a forwarded link will not work outside your network. This restricts storage access, not sign-in.

Where it runs, and how long records are kept

  • The DataFrugal service runs on Amazon Web Services in Mumbai, India.
  • Your files are stored on Amazon Web Services or Wasabi, depending on your plan. DataFrugal provisions and manages storage dedicated to your organisation; individual accounts use shared, private storage.
  • On AWS plans you can bring your own encryption key.

Activity records: a minimum of 100 days of live, searchable history of downloads, sign-ins and role changes. Older history is retained rather than deleted, and can be restored for search on request.

If your contract ends: you can download your data, after which it is deleted, except where the law requires it to be kept. Data still inside a retention period is deleted when that period ends.

What we do not claim

A short list is more useful to you than a long one that falls apart during a security review.

No certifications yet

DataFrugal does not hold an ISO 27001 certificate or a SOC 2 report today. The controls on this page support your own programme, but they are not a substitute for our own audit, and we will not pretend otherwise.

Retention can be overridden — by two people

Our retention lock is designed so that early deletion is possible with two administrators' approval, and recorded. It is not a mode that nobody at all can override. If you need that, talk to us before you buy.

Browsing names is not recorded

Opening a file's contents is always recorded. Listing a folder or searching file names is not. Since only the owner can share, and every share is recorded, the set of people who could see a file is still always known.

Frequently Asked Questions

The questions security reviewers ask us most often.

Can DataFrugal staff read our files?

DataFrugal does not read customer file contents, and there is no preview feature in the product. Support staff access data only as needed to provide support or when you ask them to.

Who holds the encryption keys?

Data is encrypted using keys DataFrugal manages. On AWS plans you can supply your own key material, which is imported into a key dedicated to your organisation, and every key event is recorded. DataFrugal holds a copy of that material so the service can read and write your data on your behalf — so this is shared custody, not a model where only you can decrypt.

Can an administrator delete our data on their own?

Not while it is within a retention period. Early deletion needs a request from an authorised user and approval from two different administrators, and nobody can approve their own request. Every step is recorded.

How quickly are we told about a security incident?

If a breach affects your data, we notify you promptly and take reasonable steps to limit the impact, as set out in our terms of service.

Will you complete our security questionnaire?

Yes. Send it to us through the contact form and we will work through it with you.

Reporting a security concern

If you believe you have found a security problem in DataFrugal, tell us through our support ticket page or email legal@celeritio.com. Please give us enough detail to reproduce it, and time to fix it before making it public.

Contact us