Security Information
PowerFolder is an in-house developed enterprise file sync, share and collaboration solution with comprehensive security, compliance, logging and monitoring capabilities. This page combines the public security information with additional security questionnaire details for audit, customer and compliance use.
- 1 1. Security Overview
- 2 2. Encryption and Data Protection
- 3 3. Identity, Access and Tenant Separation
- 4 4. File Sharing, Client Control and Data-Loss Protection
- 5 5. Secure Development and OWASP Top 10 Coverage
- 6 6. Security Logging, Audit Trails and SIEM Integration
- 7 7. Monitoring and Operations
- 8 8. Penetration Testing and Vulnerability Handling
- 9 9. Malware Protection and Online Editing
- 10 10. Privacy, Jurisdiction and Server Location
- 11 11. Certifications, Memberships and Supporting Documents
- 12 12. Summary for Audits and Customers
- 13 13. Web Session Cookies
- 14 Overview
- 15 Cookies
- 16 JSESSIONID
- 17 lastUsername
- 18 token ("Remember Me")
- 19 Security Mechanisms
- 20 Privacy
- 21 Recommendations
1. Security Overview
Core Security Features
Industrial-standard AES/RSA encrypted transfers between servers and clients.
RSA-based device authentication and verification.
SSL/TLS support for mobile apps, web access and WebDAV.
Built-in at-rest encryption based on Cryptomator technology.
Central user management.
Multi-tenant architecture to keep organisations separated on the same system.
Built-in granular permission system.
Password-protected and centrally controlled access to client preferences.
Password protection for file links.
Expiry dates for file links.
Maximum download limits for file links.
Admin-controlled remote deletion / remote wipe.
Built-in file versioning for overwritten and deleted files.
Protection against data loss caused by human error.
Protection against Cross-Site Scripting (XSS) attacks.
Protection against man-in-the-middle attacks.
Optional cloud malware protection through direct integration of antivirus solutions with the server.
Online document editing service hosted on the customer's own infrastructure.
The solution is under continuous security review internally and by partners. dal33t GmbH is a dedicated member of the TeleTrusT initiative IT Security made in Germany and IT Security made in EU.
Architecture Diagram
2. Encryption and Data Protection
Encrypted Communication and Transfers
Data transfers between desktop clients and the server are encrypted using AES/RSA encryption standards.
Data transfers between mobile apps or browsers and the server are encrypted using SSL/TLS. A valid certificate must be installed on the server side.
Web and WebDAV access are protected via SSL/TLS.
Device authentication and verification use RSA-based mechanisms.
Encrypted Storage
In PowerFolder Cloud, data is stored encrypted at rest using AES.
The built-in at-rest encryption uses Cryptomator technology.
End-to-End Encryption Options
For end-to-end encryption of stored data using PowerFolder clients and PowerFolder server-side storage, the following third-party tools can be used:
Important: When using VeraCrypt, uncheck Preserve modification timestamp of file containers in the VeraCrypt settings / preferences.
3. Identity, Access and Tenant Separation
User, Role and Permission Model
PowerFolder uses a multi-tenant rights and permission model.
Separation is enforced through user accounts, groups, organisations / tenants, workspaces and file / folder permissions.
Users can access only content for which explicit permissions have been granted.
Cross-tenant visibility is systemically excluded by design.
Permissions can be assigned granularly at file and folder level.
Authentication and Login Protection
Multi-factor authentication (MFA).
Password policies.
IP blocking after repeated failed login attempts.
SSO integration via SAML, OpenID Connect and LDAP / Active Directory.
Secure password storage using modern hash mechanisms.
Encrypted communication via TLS.
Protection Against Automated Attacks
Limitation of login attempts.
IP blocking after repeated failed attempts.
Integration with upstream reverse proxies or web application firewalls.
Optional IP-based access control.
Protection mechanisms against brute-force attacks.
4. File Sharing, Client Control and Data-Loss Protection
Password-protected file links.
Expiry dates for shared links.
Maximum number of downloads for file links.
Granular file and folder permissions.
Versioning for overwritten and deleted files.
Restoration options for deleted files.
Protection against accidental data loss caused by users.
Central control of client preferences.
Password protection for client preference access.
Admin-controlled remote wipe / remote deletion.
5. Secure Development and OWASP Top 10 Coverage
PowerFolder considers the OWASP Top 10 recommendations during development, quality assurance and security testing.
OWASP Risk Area | Implemented Controls |
|---|---|
Broken Access Control | Role-based access control and validation of the permission model. |
Cryptographic Failures | TLS encryption, AES/RSA transfer encryption and secure password hashes. |
Injection | Input validation and parameterised database access. |
Security Misconfiguration | Secure default configurations and regular security review. |
Cross-Site Scripting (XSS) | Context-aware output encoding and dedicated XSS protections. |
Cross-Site Request Forgery (CSRF) | CSRF protection mechanisms. |
Vulnerable or Outdated Components | Regular security updates and dependency management. |
Security Logging and Monitoring | Extensive logging and monitoring of security-relevant events. |
6. Security Logging, Audit Trails and SIEM Integration
Logged Security Events
PowerFolder logs security-relevant events centrally in audit and server logs. Logged events include:
Login and logout events.
Failed login attempts.
Password changes and password resets.
User account changes.
Changes to group and role memberships.
File and folder shares.
File uploads, downloads, deletions and restorations.
Permission changes.
Administrative actions.
API access and authentication events.
Audit and Compliance Use
Logs can be stored in an audit-proof manner.
Logs can be evaluated for compliance and audit purposes.
Changes to users, groups, roles and file / folder permissions are logged.
SIEM Integration
PowerFolder supports integration with existing SIEM solutions via Syslog and standardised log formats.
Security events, errors and system events can be forwarded to central monitoring and SIEM systems.
Typical integrations include Splunk, Elastic and Graylog.
7. Monitoring and Operations
PowerFolder provides operational monitoring and system supervision capabilities, including:
Audit logs and server logs.
Syslog integration.
SIEM integration.
SNMP monitoring.
REST API for monitoring systems.
Monitoring of server state and services.
Storage capacity monitoring.
Database monitoring.
Cluster and replication monitoring.
Alerting for errors or critical system states.
Integration into existing monitoring solutions such as PRTG, Zabbix, Nagios, Icinga or comparable systems is possible.
8. Penetration Testing and Vulnerability Handling
External Security Testing
PowerFolder is regularly subject to external security reviews and penetration tests.
The tests are performed by qualified external security experts.
If required for a specific project, appropriately certified penetration testers can be commissioned.
Typical Test Scope
Web portal.
REST API.
Authentication mechanisms.
Administration interface.
Sharing functions.
File operations.
Mobile apps.
Desktop clients.
Integrations such as WebDAV, SAML and OnlyOffice.
Specific Test Areas
The role and permission model is tested with a focus on preventing privilege escalation.
Upload, download and sharing functions are tested, including misuse scenarios.
The PDF preview function has been tested as part of penetration tests. No security-relevant vulnerabilities were found in that context.
Before each software release, automated web tests are performed, including tests of the PDF preview functionality to ensure stability and quality.
Vulnerability Remediation and Re-Testing
Identified vulnerabilities are assessed according to criticality, prioritised and resolved through the established development and release process.
Critical security vulnerabilities are addressed quickly through hotfixes or out-of-cycle security updates.
After remediation, a re-test is performed to verify the effectiveness of the measures and to confirm successful closure of the vulnerability.
Reports and Confirmations
Depending on scope and confidentiality, management summaries, test confirmations or suitable extracts from test reports can be provided.
A penetration test certificate exists for PowerFolder licence penetration testing.
9. Malware Protection and Online Editing
Optional cloud malware protection is available through integration of antivirus solutions directly with the server.
Online document editing can be hosted on the customer's own infrastructure.
The connected anti-malware and online editing solution, including ONLYOFFICE in the PowerFolder Cloud context, is hosted together with the cloud infrastructure in Falkenstein.
10. Privacy, Jurisdiction and Server Location
Privacy Laws and Jurisdiction
PowerFolder / dal33t GmbH and all departments are located in Germany.
The company has no branches outside the Federal Republic of Germany.
PowerFolder / dal33t GmbH has no investors that may be bound by laws outside Germany or the European Union.
Therefore, only the privacy laws of Germany and the European Union apply.
The Privacy Statement is available here: PowerFolder Privacy Statement.
Server Location
The servers of PowerFolder Cloud and the connected anti-malware and online editing solution ONLYOFFICE are hosted in Falkenstein, Germany.
The high-security data centre is ISO/IEC 27001:2013 certified and operated by Hetzner Online GmbH.
Data centre certificate: DIN ISO/IEC 27001 certificate of the data centre / FOX certificate.
11. Certifications, Memberships and Supporting Documents
Item | Information | Link / Reference |
|---|---|---|
IT Security made in Germany | dal33t GmbH is a dedicated member of the TeleTrusT initiative. | |
IT Security made in EU | TeleTrusT trust seal for European IT security. | |
Data centre certification | ISO/IEC 27001:2013 certified data centre operated by Hetzner Online GmbH. | |
Penetration test certificate | Certificate / confirmation for PowerFolder licence penetration testing. | Attach certificate document in Confluence, if publication is permitted. |
12. Summary for Audits and Customers
PowerFolder combines encrypted communication, encrypted storage, central identity and permission management, tenant separation, audit logging, SIEM integration, operational monitoring, secure development practices and regular penetration testing. Security-relevant findings are assessed, prioritised, remediated and verified through re-testing. The platform is operated under German and European privacy law, with PowerFolder Cloud infrastructure hosted in an ISO/IEC 27001-certified data centre in Germany.
13. Web Session Cookies
Overview
PowerFolder uses only technically required cookies for authentication and session management. No analytics, tracking, or marketing cookies are used.
Authentication and authorization are performed exclusively on the server. Cookies contain only identifiers or cryptographic tokens and never store passwords, permissions, or file contents.
Cookies
Cookie | Purpose | Lifetime | Risk |
|---|---|---|---|
JSESSIONID | Session management | Browser session | Low |
lastUsername | Username prefill and MFA support | 10 days | Low |
token | Optional "Remember Me" login | 30 days (configurable) | Medium |
JSESSIONID
Used to associate HTTP requests with an authenticated user session.
Contains only a unique session identifier and no:
Passwords
User permissions
Personal data
File contents
The session expires on logout, browser closure, or timeout.
lastUsername
Stores the last used username or email address to improve usability and support MFA workflows.
Contains no authentication information.
token ("Remember Me")
Provides persistent login functionality when explicitly enabled by the user.
Contains only a cryptographic token. Passwords, session IDs, permissions, and file contents are never stored.
Tokens are validated server-side and removed immediately during logout.
Security Mechanisms
HttpOnly protection against JavaScript access and XSS attacks.
Secure flag for encrypted transmission over HTTPS.
Server-side authentication and authorization.
No password storage in cookies.
Automatic session termination during logout.
Privacy
Cookies are used solely for:
Authentication
Session management
MFA support
Optional persistent login
PowerFolder performs:
No tracking
No user profiling
No behavioral analytics
No third-party sharing
No marketing usage
Therefore, all cookies are classified as technically necessary.
Recommendations
Use HTTPS exclusively.
Enable MFA for privileged accounts.
Keep PowerFolder updated.
Use trusted endpoint devices.
Avoid "Remember Me" on shared systems.
Member of IT-Security made in Germany and EU
Pentest Certificate