{"id":13,"date":"2026-07-24T04:35:59","date_gmt":"2026-07-24T04:35:59","guid":{"rendered":"https:\/\/zorvaro.de\/?page_id=13"},"modified":"2026-08-15T20:36:03","modified_gmt":"2026-08-15T18:36:03","slug":"sicherheit","status":"publish","type":"page","link":"https:\/\/zorvaro.de\/en\/sicherheit\/","title":{"rendered":"Security and Privacy"},"content":{"rendered":"<div class=\"wp-block-group alignwide zv-docs-hero is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"zv-docs-hero__eyebrow wp-block-paragraph\">Security &amp; Privacy<\/p>\n\n\n<h1 class=\"wp-block-heading zv-docs-hero__title\">Protection on multiple levels.<\/h1>\n\n\n<p class=\"zv-docs-hero__text wp-block-paragraph\">zorVaro protects personal content not only through encrypted connections and separate user areas. Sensitive account data and files are also encrypted at the application level.<\/p>\n\n\n<p class=\"zv-docs-hero__text wp-block-paragraph\">Even so, the application remains able to automatically carry out the messages and actions you have scheduled.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group zv-content-card is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"zv-content-card__eyebrow wp-block-paragraph\">SEPARATE USER AREAS<\/p>\n\n\n<h2 class=\"wp-block-heading\">Your account forms its own data boundary.<\/h2>\n\n\n<p class=\"wp-block-paragraph\">Contacts, files, check-ins, prepared actions, shares and logs are assigned to your personal user account. Other users cannot access this content.<\/p>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n<div class=\"wp-block-group zv-content-card is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"zv-content-card__eyebrow wp-block-paragraph\">PER-ACCOUNT ENCRYPTION<\/p>\n\n\n<h2 class=\"wp-block-heading\">Every account has its own data key.<\/h2>\n\n\n<p class=\"wp-block-paragraph\">For each account, zorVaro generates a separate random 256-bit data key. Keys for different accounts are generated independently.<\/p>\n\n\n<p class=\"wp-block-paragraph\">The actual account key is not stored in plaintext in the database. It is stored there only in encrypted form. The higher-level key required to protect it is kept separately from the account data itself.<\/p>\n\n\n<p class=\"wp-block-paragraph\">This also reduces the potential impact if data from a single account \u2014 or a database copy on its own \u2014 were to fall into the wrong hands.<\/p>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n<div class=\"wp-block-group zv-content-card is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"zv-content-card__eyebrow wp-block-paragraph\">ENCRYPTED ACCOUNT DATA<\/p>\n\n\n<h2 class=\"wp-block-heading\">Sensitive content is additionally encrypted at the application level.<\/h2>\n\n\n<p class=\"wp-block-paragraph\">Encrypted content includes personal account and sender details, contact information and addresses, subject lines and message text, file names and file descriptions, as well as sharing and delivery information.<\/p>\n\n\n<p class=\"wp-block-paragraph\">zorVaro uses authenticated AES-256-GCM encryption with fresh random values for each encrypted item. This helps ensure that tampered or incorrectly associated ciphertext is detected rather than silently processed.<\/p>\n\n\n<p class=\"wp-block-paragraph\">Technical IDs, timestamps, status values and other information required for scheduling and operation sometimes need to remain machine-readable. Passwords are stored separately as cryptographic hashes.<\/p>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n<div class=\"wp-block-group zv-content-card is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"zv-content-card__eyebrow wp-block-paragraph\">ENCRYPTED FILES<\/p>\n\n\n<h2 class=\"wp-block-heading\">Files are not stored unencrypted in file storage.<\/h2>\n\n\n<p class=\"wp-block-paragraph\">New files are also stored encrypted with the respective account key using AES-256-GCM. A stolen file store therefore does not automatically contain readable documents.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>zorVaro treats files exclusively as file objects.<\/strong> No automatic content analysis, document recognition, text recognition, indexing or preview generation takes place.<\/p>\n\n\n<p class=\"wp-block-paragraph\">For an authorized download or for sending a file as an email attachment, the application can technically remove the outer server-side encryption. The file is then passed on only in the form you specified; zorVaro does not analyze its content.<\/p>\n\n\n<p class=\"wp-block-paragraph\">Files have no publicly accessible storage address. Downloads are handled through the application and only after the intended authorization check.<\/p>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n<div class=\"wp-block-group zv-content-card is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"zv-content-card__eyebrow wp-block-paragraph\">EXTRA PROTECTED<\/p>\n\n\n<h2 class=\"wp-block-heading\">An additional personal layer of protection for highly sensitive files.<\/h2>\n\n\n<p class=\"wp-block-paragraph\">For especially sensitive content, you can store a file that you have already encrypted yourself as \u201cExtra Protected\u201d. zorVaro does not know the personal password or recovery key for this inner layer of encryption.<\/p>\n\n\n<p class=\"wp-block-paragraph\">The file still receives the standard outer account encryption. When it is later downloaded or sent, zorVaro removes only this outer layer \u2014 the personal encryption remains intact.<\/p>\n\n\n<p class=\"wp-block-paragraph\">zorVaro cannot recover a lost personal password in this mode. No content analysis or preview generation takes place for Extra Protected files either. zorVaro provides the file only for download or delivery in the form you specified.<\/p>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n<div class=\"wp-block-group zv-content-card is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"zv-content-card__eyebrow wp-block-paragraph\">PROTECTED ACCESS<\/p>\n\n\n<h2 class=\"wp-block-heading\">Not every login has access to everything.<\/h2>\n\n\n<p class=\"wp-block-paragraph\">Regular users cannot access administrative areas or central system settings. Administrative access is protected by additional safeguards, and security-relevant login attempts are limited.<\/p>\n\n\n<p class=\"wp-block-paragraph\">Personal app keys are not stored in plaintext on the server. When a new key is generated, the previous key becomes invalid.<\/p>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n<div class=\"wp-block-group zv-content-card is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"zv-content-card__eyebrow wp-block-paragraph\">ENCRYPTED TRANSMISSION<\/p>\n\n<h2 class=\"wp-block-heading\"><\/h2>\n\n<p class=\"wp-block-paragraph\">Communication with zorVaro uses encrypted HTTPS connections. This protects information between your device and zorVaro while it is being transmitted.<\/p>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n<div class=\"wp-block-group zv-content-card is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"zv-content-card__eyebrow wp-block-paragraph\">BACKUP AND FAILOVER PROTECTION<\/p>\n\n\n<h2 class=\"wp-block-heading\">Encryption alone is not enough.<\/h2>\n\n\n<p class=\"wp-block-paragraph\">Account data and files encrypted at the application level remain encrypted in backups as well. Backups, the active system and the failover system serve different purposes and are therefore treated as separate layers of protection.<\/p>\n\n\n<p class=\"wp-block-paragraph\">In addition, a geographically and organizationally separate mirror system within the European Union is available. During normal operation it remains passive and is activated only as part of the defined failover procedure.<\/p>\n\n\n<p class=\"wp-block-paragraph\">Recovery and encryption are not only documented, but also technically verified. A wrong or missing key should result in a detectable error rather than silently producing unreadable or incorrectly processed data.<\/p>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Where are the technical limits?<\/h2>\n\n\n<p class=\"wp-block-paragraph\">A system that is designed to execute messages and actions automatically must be able to decrypt normal account data when needed during operation. A fully compromised production server with the highest system privileges therefore cannot be considered a completely separate cryptographic security boundary.<\/p>\n\n\n<p class=\"wp-block-paragraph\">zorVaro addresses this risk with protected administrative access, two-factor authentication, access restrictions, separated keys and systems, logging, backups and a defined recovery process. For files where even the running server should not know the plaintext, the \u201cExtra Protected\u201d mode provides an additional layer.<\/p>\n\n\n\n<div class=\"wp-block-group zv-info-box is-layout-flow wp-block-group-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Security at zorVaro is not a single feature. User separation, application-level encryption, protected files, restrictive access controls, logging, backups and failover protection work together.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Do you have a specific question about security or privacy?<\/strong><br><a>info@zorvaro.de<\/a><\/p>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"excerpt":{"rendered":"<p>Account-level encryption, protected files, clear data boundaries and failover protection.<\/p>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"templates\/landing.php","meta":{"_surecart_dashboard_logo_width":"180px","_surecart_dashboard_show_logo":true,"_surecart_dashboard_navigation_orders":true,"_surecart_dashboard_navigation_invoices":true,"_surecart_dashboard_navigation_subscriptions":true,"_surecart_dashboard_navigation_downloads":true,"_surecart_dashboard_navigation_billing":true,"_surecart_dashboard_navigation_account":true,"footnotes":""},"class_list":["post-13","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/zorvaro.de\/en\/wp-json\/wp\/v2\/pages\/13","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zorvaro.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/zorvaro.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/zorvaro.de\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zorvaro.de\/en\/wp-json\/wp\/v2\/comments?post=13"}],"version-history":[{"count":12,"href":"https:\/\/zorvaro.de\/en\/wp-json\/wp\/v2\/pages\/13\/revisions"}],"predecessor-version":[{"id":577,"href":"https:\/\/zorvaro.de\/en\/wp-json\/wp\/v2\/pages\/13\/revisions\/577"}],"wp:attachment":[{"href":"https:\/\/zorvaro.de\/en\/wp-json\/wp\/v2\/media?parent=13"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}