Data Encryption
As part of the backup process, and before your data is transmitted to our servers it is encrypted. DanVault offers you the choice of several different encryption algorithms including DES, TDES (triple DES), AES 128, AES 192, AES 256 and Blowfish with a variable length key of up to 448 bits.
By using state-of-the-art encryption, we ensure that it will be virtually impossible for unauthorized individuals to access your data. So, in the event someone actually intercepts the data transmitted, they would not be able to decipher it.
Also, unlike some other services, we do not have access to your encryption key. This means that while your data is stores on our servers, we cannot read it either!
When you first setup your DanVault software, you will be creating an encryption key. You should store this key in a safe place. You are responsible for securing and keeping your key private. If for any reason you need to reinstall the backup client software to recover data, you will need this key.
Without the encryption key, nobody can access your information - not even the employees of DanVault. This provides you with assurance that your data cannot be read by unauthorized personnel.
Network Protection
The DanVault are special purpose-built servers, which has only one function: Store large volumes of encrypted and compresses data SECURELY. All data volumes and operating system volumes are utilizing Hot-Swap RAID-5 drive arrays. Operating system and data storage are separated, and no end-user accounts have access any other part of the system than their own data volume.
Critical system components - including the power supply - are all spared onsite.
We utilize sophisticated network port blocking and packet filtering techniques to prevent unauthorized access to the network and servers. We employ state-of-the-art anti-virus and spam filtering.
How it works: The facilities
Our 13500 sq.ft. data center is located approximately 30 miles north of New York City. The center is located in a subterranean structure, 2 stories below ground, and is incased entirely in concrete. The facility, originally designed in the 1970’s, was used as a safe location for the mainframe systems for a major international corporation.
The facility shares its main power substation with a major regional hospital and a county jail. Proximity to those facilities helps ensure power availability under PUC regulations in the event of a prolonged area power outage. However, our power system also includes full UPS and diesel backup with automatic transfer switches.
Redundant connectivity to the Internet is provided through two OC-48s, one OC-12 and one OC-3, all from different providers.
The data center is protected by motion detectors, temperature, current, smoke and humidity sensors. In addition, it features video surveillance and an on-site security staff protecting the facility 24/7/365. All access is restricted and logged for security.
All servers are redundant and backed up to tape daily.
In addition, we have a smaller secondary backup site, located in northwestern New Jersey.