Snapshot 34456
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security for Every File, From Upload to Delivery
Signed URLs, encrypted file upload and storage, malware scanning inside workflows, and infrastructure tested by third parties, behind one integration.
Request Security Package
Read the Docs
Security reviews and evidence requests reach the security team directly.
Trusted by teams at
Compliance and the Contract Layer
Five published documents govern how Filestack processes customer data. The data processing agreement takes effect through the terms of service.
SOC 2
report on request
GDPR
DPA and SCCs
CCPA
and US state laws
DailyVulnerability scanning
AnnualPenetration testing, by a third party
AnnualSOC 2 audit
AnnualInternal audit
Data Processing Agreement
universal, customer-facing
Data Processing Terms
filestack specific
Jurisdiction Specific Terms
by governing law
Privacy Notice
GDPR, CCPA, US states
Transfer Impact Assessment
2021 SCC safeguards
Audit reports and vendor security questionnaire responses are released under agreement, through contact us.
Where Your Data Is Stored and Processed
Data residency requirements are answered separately for storage and for processing.
Stored in the United States
Infrastructure runs on AWS us-east-1 with default storage in Northern Virginia. Point storage at your own S3 bucket in any region and the stored file moves with it.
Processing runs where the task runs, which is not always where the file is stored.
On GDPR file storage, transfers out of the EEA and the UK rely on the 2021 Standard Contractual Clauses, recorded in the Transfer Impact Assessment.
Processed in five countries
United Stateshosting, storage, delivery, scanning
Germanydocument transformations
Canadaimage enhancement
Australiaproject management, status page
New Zealandinvoicing
Security Across the File Lifecycle
Five stages between the browser and the CDN.
01
Upload
Signed, short-lived policy
02
Inspect
Virus, SFW, phishing
03
Process
Signed webhook back
04
Store
AES-256, your bucket
05
Deliver
Expiring, scoped reads
Signed Policies Control Every Request
A policy is Base64URL-encoded JSON carrying an HMAC-SHA256 signature. It needs an expiry; call limits the verbs, handle pins it to one file, path holds uploads inside your prefix, and maxSize moves file upload validation to the API.
API request signing turns that policy into a signed URL, the expiring download link a presigned URL gives you on S3. The secret stays on your server.
Uploads and delivery stay open until you enable security on the application in the Developer Portal. From then on every request carries a signature, which is the control that closes the unrestricted file upload vulnerability.
Read the Policy Docs
server.js
// Minutes, not months, and only the calls this client makes.
const policy = {
expiry: Math.floor(Date.now() / 1000) + 300,
call: ['pick', 'store'],
path: '/2026/invoices/',
maxSize: 10485760
};
const encoded = Buffer
.from(JSON.stringify(policy))
.toString('base64url');
const signature = crypto
.createHmac('sha256', APP_SECRET)
.update(encoded)
.digest('hex');
Controls Built Into the Platform
Encryption and storage
File transfer security on TLS 1.2 with 2,048-bit keys, file encryption at rest with AES-256, and AWS KMS key management holding the volume and field-level keys.
Read the Storage Docs →
Malware and content safety
The virus scanning API covers every file type, ZIP and TAR included, so a file upload virus scan clears a secure document upload before your app trusts it. Workflows quarantine and notify, alongside the phishing detection and SFW content moderation APIs.
Explore Filestack Workflows →
Access and delivery
Domain whitelists limit embedding by Origin and Referer, which is how you prevent hotlinking images. Custom CNAME puts secure file delivery on your own domain. Webhook signature verification runs off the FS-Signature header.
Explore Custom CNAME →
Tested, Monitored, and Recoverable
View the System Status
Secure development and access
Daily vulnerability scans and annual third-party penetration testing. Changes carry testing, approval and rollback. Access runs least privilege behind VPN and MFA.
Monitoring and response
Monitored around the clock, with alerts for error rates, abuse and anomalous activity. Intrusion detection on critical assets, and 180-day audit log retention.
Resilience and recovery
Redundancy across availability zones and VPC networks with N+1 servers. Daily backups on a seven-day window, and cross-region database replication.
Frequently Asked Questions
Are Filestack uploads and delivery authenticated by default?
Requests that modify an existing file or account settings are authenticated. Uploads and delivery stay open until security is enabled on the application, after which every request carries a policy and a signature.
How long should a Filestack security policy last?
A policy needs an expiry set in the future and nothing else. Generate it on your backend, scope it to the calls that client needs, and measure the lifetime in minutes.
What are the data residency requirements Filestack can meet?
Storage of customer personal data is in the United States, with processing in the United States, New Zealand, Australia, Canada and Germany. Your own S3 bucket puts the stored file in the region you choose.
Can Filestack be used with student education records under FERPA?
FERPA does not certify software, so no product is FERPA compliant on its own. The institution decides whether a vendor acts as a school official under its direct control. The Filestack data processing terms carry the obligations behind that decision: processing on documented instructions, confidentiality, equivalent terms for the vendors it uses, breach notice without undue delay, and deletion or return on termination.
Can Filestack scan uploaded files for malware?
Virus detection runs inside Workflows across every file type, including ZIP and TAR archives. A workflow can quarantine an infected file and notify your application as part of the same run.
How do I request a SOC 2 report or a vendor security questionnaire?
Security evidence is released by the Filestack security team. Send the request through by contacting us.
How do I report a security vulnerability in Filestack?
Good-faith research on Filestack domains and services is welcome. Send findings to [email protected], with PGP available on request.