Security & Privacy
Protection on multiple levels.
zorVaro protects personal content not only through encrypted connections and separate user areas. Sensitive account data and files are also encrypted at the application level.
Even so, the application remains able to automatically carry out the messages and actions you have scheduled.
SEPARATE USER AREAS
Your account forms its own data boundary.
Contacts, files, check-ins, prepared actions, shares and logs are assigned to your personal user account. Other users cannot access this content.
PER-ACCOUNT ENCRYPTION
Every account has its own data key.
For each account, zorVaro generates a separate random 256-bit data key. Keys for different accounts are generated independently.
The actual account key is not stored in plaintext in the database. It is stored there only in encrypted form. The higher-level key required to protect it is kept separately from the account data itself.
This also reduces the potential impact if data from a single account — or a database copy on its own — were to fall into the wrong hands.
ENCRYPTED ACCOUNT DATA
Sensitive content is additionally encrypted at the application level.
Encrypted content includes personal account and sender details, contact information and addresses, subject lines and message text, file names and file descriptions, as well as sharing and delivery information.
zorVaro uses authenticated AES-256-GCM encryption with fresh random values for each encrypted item. This helps ensure that tampered or incorrectly associated ciphertext is detected rather than silently processed.
Technical IDs, timestamps, status values and other information required for scheduling and operation sometimes need to remain machine-readable. Passwords are stored separately as cryptographic hashes.
ENCRYPTED FILES
Files are not stored unencrypted in file storage.
New files are also stored encrypted with the respective account key using AES-256-GCM. A stolen file store therefore does not automatically contain readable documents.
zorVaro treats files exclusively as file objects. No automatic content analysis, document recognition, text recognition, indexing or preview generation takes place.
For an authorized download or for sending a file as an email attachment, the application can technically remove the outer server-side encryption. The file is then passed on only in the form you specified; zorVaro does not analyze its content.
Files have no publicly accessible storage address. Downloads are handled through the application and only after the intended authorization check.
EXTRA PROTECTED
An additional personal layer of protection for highly sensitive files.
For especially sensitive content, you can store a file that you have already encrypted yourself as “Extra Protected”. zorVaro does not know the personal password or recovery key for this inner layer of encryption.
The file still receives the standard outer account encryption. When it is later downloaded or sent, zorVaro removes only this outer layer — the personal encryption remains intact.
zorVaro cannot recover a lost personal password in this mode. No content analysis or preview generation takes place for Extra Protected files either. zorVaro provides the file only for download or delivery in the form you specified.
PROTECTED ACCESS
Not every login has access to everything.
Regular users cannot access administrative areas or central system settings. Administrative access is protected by additional safeguards, and security-relevant login attempts are limited.
Personal app keys are not stored in plaintext on the server. When a new key is generated, the previous key becomes invalid.
ENCRYPTED TRANSMISSION
Communication with zorVaro uses encrypted HTTPS connections. This protects information between your device and zorVaro while it is being transmitted.
BACKUP AND FAILOVER PROTECTION
Encryption alone is not enough.
Account data and files encrypted at the application level remain encrypted in backups as well. Backups, the active system and the failover system serve different purposes and are therefore treated as separate layers of protection.
In addition, a geographically and organizationally separate mirror system within the European Union is available. During normal operation it remains passive and is activated only as part of the defined failover procedure.
Recovery and encryption are not only documented, but also technically verified. A wrong or missing key should result in a detectable error rather than silently producing unreadable or incorrectly processed data.
Where are the technical limits?
A system that is designed to execute messages and actions automatically must be able to decrypt normal account data when needed during operation. A fully compromised production server with the highest system privileges therefore cannot be considered a completely separate cryptographic security boundary.
zorVaro addresses this risk with protected administrative access, two-factor authentication, access restrictions, separated keys and systems, logging, backups and a defined recovery process. For files where even the running server should not know the plaintext, the “Extra Protected” mode provides an additional layer.
Security at zorVaro is not a single feature. User separation, application-level encryption, protected files, restrictive access controls, logging, backups and failover protection work together.
Do you have a specific question about security or privacy?
info@zorvaro.de