Knowledge base

Where your data lives and who can see it

Encryption

  • Backups are compressed and encrypted before they leave our server, with AES-256-GCM and a key that belongs to your account. The account keys are themselves encrypted with a master key kept outside the database.
  • Database connection strings, Storage keys and bucket secrets are encrypted the same way and are never shown again after you save them.
  • Free scan results are deleted after 30 days; deleted accounts are removed with their backups within 24 hours (except records we must keep by law).

Where

Managed backups are stored in object storage from the provider named in the privacy policy, which also lists every other service that processes data for us. With your own bucket the encrypted backups go to your storage instead.

Who can see what

  • You and the people on your account.
  • Vigavo staff do not open backups. Support agents see your plan, project names and backup status, never connection details; every staff access is logged.
  • Decrypted exports and restores into your source database require your two-factor code.

See also Scan safety and opt-out for what the scanner does and never does.

Last reviewed Oct 7, 2026, 12:00:00 AM

Still stuck? Send a ticket

Feedback
Type