Skip to main content

How does ProBackup keep your data secure?

Written by ProBackup

This article provides an overview of the security measures ProBackup has in place to protect your data. For full details, visit our Security page.

Infrastructure security

ProBackup stores your backups in one of 9 AWS regions:

  • 🇦🇺 Oceania - Sydney, Australia

  • 🇨🇦 Canada - Montreal

  • 🇸🇬 Asia - Singapore

  • 🇮🇪 Europe - Dublin, Ireland

  • 🇩🇪 Germany - Frankfurt

  • 🇧🇷 Latin America - São Paulo, Brazil

  • 🇮🇱 Israel - Tel Aviv

  • 🇬🇧 United Kingdom - London

  • 🇺🇸 United States - North Virginia

Your region is assigned automatically based on your location (customers in Germany default to AWS Frankfurt, other European customers to AWS Dublin) and you can choose a different region in your account settings. All AWS data centres are certified to ISO 27001, SOC 1 & 2, and PCI Level 1. Your data never leaves your selected region.

ProBackup enforces strict access controls with multi-factor authentication for all production environments. Privileged access is limited to authorised personnel and promptly revoked when no longer required. Continuous monitoring covers intrusion detection, performance metrics, log management, and vulnerability assessments.

Product security

ProBackup protects your data at every stage:

  • At rest – all data is encrypted using AES-256, with keys managed by AWS Key Management Service.

  • In transit – all connections are secured via SSL (port 443) and enforced through HTTP Strict Transport Security (HSTS).

Annual penetration tests and control self-assessments are conducted, with vulnerabilities remediated promptly. Quarterly vulnerability scans identify risks, and critical issues are prioritised for immediate resolution.

Organisational security

All staff and contractors undergo background checks, sign confidentiality agreements, and complete security awareness training at onboarding and annually thereafter. Mobile devices are centrally managed via Mobile Device Management (MDM), and strict asset disposal policies are in place.

Internal processes

ProBackup maintains comprehensive Business Continuity and Disaster Recovery plans, holds cybersecurity insurance, and follows a formal Systems Development Life Cycle (SDLC) for all system changes.

Access controls are reviewed regularly with documented approvals. Security policies are reviewed annually, and incident response procedures are in place for swift resolution of any security or privacy events.

Data and privacy

ProBackup securely stores customer data and permanently deletes it upon service termination. Access to sensitive information is restricted to authorised personnel only.

ProBackup acts as a data processor when handling personal data on behalf of customers and as a data controller for data about its own customers. Both roles comply with GDPR and are formalised through our Data Processing Addendum (DPA).

You can download our DPA and other compliance documents from our Audit Reports page. For full details on how we handle your data, see our Privacy Policy.

Did this answer your question?