|
|
|
|
|
by joethei
1284 days ago
|
|
No, we do not use AWS.
The Sync and Publish servers are running in Digital Ocean datacenters in the US.
How sync encrypts the data is documented here: https://help.obsidian.md/Obsidian+Sync/Security+and+privacy As others have already pointed out, Sync is not the only option to synchronize notes, Obsidian sync is just a convenience option. For compliance, I am guessing you mean certs like SOC 2 / ISO 27001?, or what are you referencing?
As we are a tiny company (6 people, not all full time) we just can't expense the time needed to get such a certificate. |
|
> AES-256 is a military-grade encryption specification that's widely used in for example online banking.
The term “military grade” is meaningless and if anything raises a red flag (at least to me). What would be more useful is a detailed spec on the implementation.
Are the crypto routines implemented in house or has a well tested library been used? If in house, had there been an external code audit done? What were the results ?