Security & Encryption
Security is not an upsell at Filess; it is a fundamental guarantee across all plans, including the Free tier.
Encryption
- Encryption at Rest: All data volumes are encrypted using AES-256 industry-standard encryption. Physical disks are encrypted before any data is written.
- Encryption in Transit: All connections to your database are secured via SSL/TLS. We enforce
SSL Mode: REQUIREDby default on most engines to prevent accidental unencrypted data leakage.
Network Security
- DDoS Protection: All entry points are protected by automated DDoS mitigation systems.
- Firewall (Dedicated): On Dedicated plans, you can configure a strict Cloud Firewall to allow traffic only from specific IP addresses or subnets.
- Private Networking: Use Tailscale or SSH Tunneling to access your database without exposing it to the public internet.
Isolation
- Shared Mode: Uses container-based isolation and distinct storage namespaces to ensure no data bleeds between tenants.
- Dedicated Mode: Provides VM/Bare-metal level isolation for CPU, RAM, and Storage, ensuring complete physical separation of your workload.