Before transit
AES-256-GCM protects chunk confidentiality and integrity. Password-based keys use a memory-hard derivation function and are not sent to the server.
Security model
AgooCloud recommends client-side encryption. The agent derives a key from the password, encrypts each changed chunk and sends only encrypted bytes through the managed API.
AES-256-GCM protects chunk confidentiality and integrity. Password-based keys use a memory-hard derivation function and are not sent to the server.
Production traffic is expected over TLS. Authenticated endpoints apply ownership checks to devices, backup sets, sessions, manifests and restore chunks.
Wasabi credentials remain server-side. AgooCloud stores encrypted payloads under per-customer object keys and tracks metadata separately.
If you lose a client-side encryption password, AgooCloud cannot recover it. Keep a protected password record and regularly test restores.
Please send a responsible disclosure to contact@rvlworks.com. Do not access or alter data that is not yours.