To support GDPR’s data protection requirements, Tresorit minimizes access to personal data through its security model.
GDPR requires organizations to implement appropriate technical and organizational measures to protect personal data, including encryption. For the strongest protection, encryption keys should be fully controlled by the end user and must never be accessible to the service provider at any point during the encryption or decryption process. This means encryption is performed on the client side, not in the cloud.
Thanks to Tresorit’s zero-knowledge, end-to-end encryption, all files are encrypted on the user’s device before being uploaded to the cloud, with encryption keys remaining entirely under the customer’s control. This ensures that personal data is never accessible to Tresorit or any unauthorized party.
The reality is that all companies are vulnerable to cyberattacks. But in the event of a breach, you can rest assured the data protected by Tresorit remains fully encrypted and unintelligible.
By securing data at the source, Tresorit helps organizations protect personal data, reduce exposure, and meet GDPR's requirements for confidentiality and integrity.