Security architecture

Citadel's security architecture, in plain terms.

We would rather describe exactly what Citadel does than make an absolute claim no one can substantiate.

What protects the data?

Secured2's physics-based Quantum-Secure® technology: files are reduced, separated into meaningless fragments and distributed across separate environments.

What protects access?

Account authentication plus a private code bound to your identity, so a stolen password alone is not enough.

What proves integrity?

A checksum recorded at upload and verified on every retrieval, with object existence and size checks in storage.

What we claim, and what we do not.

We do not describe Citadel as unhackable. That is an absolute claim, and any serious security leader will rightly challenge it.

What we do claim is specific: no single storage location holds a whole, readable file; protection does not depend on a master key remaining secret; and every retrieval is verified against what you stored.

Reducing the surface deliberately.

There is no sharing, no public links, no guest access and no sync client. Data leaves the vault only through an authenticated retrieval by the account holder.

Credentials for storage environments are held server-side and never exposed to the browser, and activity history is private to the account.

Questions people ask

Is data verified on the way in as well as out?
Yes. Uploads are checksummed in chunks and verified once assembled; a mismatch removes the object rather than storing something unverified.
Can an administrator read my files?
Administrators manage accounts and plans. They do not have a route to reassemble another account's data.
What authentication methods are supported?
Email and password, plus Google, Microsoft and Apple sign-in, with a private code as the second step.

Keep reading

Citadel by Secured2

Protect what matters most.

Citadel is accepted by a limited number of organisations each quarter. See the plans and start with the data you cannot afford to lose.

See pricing