Legal
Security overview
AgooCloud's security model, shared responsibilities and vulnerability reporting.
Effective date: 9 September 2026Security architecture
The Windows agent authenticates only with AgooCloud. Cloud jobs create chunk identifiers, optionally encrypt data locally and relay payloads through the AgooCloud API. Local jobs write only to the customer-selected Windows destination and do not create upload sessions. The server verifies checksums and ownership before storing cloud objects through server-held object-storage credentials.
Encryption choices
Client-side AES-256-GCM is recommended for cloud backups. Unencrypted cloud mode is available by explicit customer choice. Password-derived encryption keys are not transmitted to AgooCloud; encrypted backups cannot be recovered without the password.
Access control
Customer and administrator routes are separated by server-side role checks. API backup resources are scoped to the authenticated account, including within business workspaces; the shared workspace applies to quota accounting and does not expose one member's files to another. Browser forms use anti-forgery tokens and authentication cookies are HTTP-only.
Operational controls
Production deployment should add centralised logs, alerting, regular dependency updates, least-privilege object-storage policies, isolated production secrets, database backups, restore drills and an incident-response process.
Responsible disclosure
Report suspected vulnerabilities privately to contact@rvlworks.com with enough detail to reproduce the issue. We ask researchers to avoid privacy violations, disruption and destructive testing.