Security Information

Security Information

PowerFolder is an in-house developed enterprise file sync, share and collaboration solution with comprehensive security, compliance, logging and monitoring capabilities. This page combines the public security information with additional security questionnaire details for audit, customer and compliance use.


1. Security Overview

Core Security Features

  • Industrial-standard AES/RSA encrypted transfers between servers and clients.

  • RSA-based device authentication and verification.

  • SSL/TLS support for mobile apps, web access and WebDAV.

  • Built-in at-rest encryption based on Cryptomator technology.

  • Central user management.

  • Multi-tenant architecture to keep organisations separated on the same system.

  • Built-in granular permission system.

  • Password-protected and centrally controlled access to client preferences.

  • Password protection for file links.

  • Expiry dates for file links.

  • Maximum download limits for file links.

  • Admin-controlled remote deletion / remote wipe.

  • Built-in file versioning for overwritten and deleted files.

  • Protection against data loss caused by human error.

  • Protection against Cross-Site Scripting (XSS) attacks.

  • Protection against man-in-the-middle attacks.

  • Optional cloud malware protection through direct integration of antivirus solutions with the server.

  • Online document editing service hosted on the customer's own infrastructure.

The solution is under continuous security review internally and by partners. dal33t GmbH is a dedicated member of the TeleTrusT initiative IT Security made in Germany and IT Security made in EU.

Architecture Diagram

PowerFolder Security Architecture.png

2. Encryption and Data Protection

Encrypted Communication and Transfers

  • Data transfers between desktop clients and the server are encrypted using AES/RSA encryption standards.

  • Data transfers between mobile apps or browsers and the server are encrypted using SSL/TLS. A valid certificate must be installed on the server side.

  • Web and WebDAV access are protected via SSL/TLS.

  • Device authentication and verification use RSA-based mechanisms.

Encrypted Storage

  • In PowerFolder Cloud, data is stored encrypted at rest using AES.

  • The built-in at-rest encryption uses Cryptomator technology.

End-to-End Encryption Options

For end-to-end encryption of stored data using PowerFolder clients and PowerFolder server-side storage, the following third-party tools can be used:

Important: When using VeraCrypt, uncheck Preserve modification timestamp of file containers in the VeraCrypt settings / preferences.


3. Identity, Access and Tenant Separation

User, Role and Permission Model

  • PowerFolder uses a multi-tenant rights and permission model.

  • Separation is enforced through user accounts, groups, organisations / tenants, workspaces and file / folder permissions.

  • Users can access only content for which explicit permissions have been granted.

  • Cross-tenant visibility is systemically excluded by design.

  • Permissions can be assigned granularly at file and folder level.

Authentication and Login Protection

  • Multi-factor authentication (MFA).

  • Password policies.

  • IP blocking after repeated failed login attempts.

  • SSO integration via SAML, OpenID Connect and LDAP / Active Directory.

  • Secure password storage using modern hash mechanisms.

  • Encrypted communication via TLS.

Protection Against Automated Attacks

  • Limitation of login attempts.

  • IP blocking after repeated failed attempts.

  • Integration with upstream reverse proxies or web application firewalls.

  • Optional IP-based access control.

  • Protection mechanisms against brute-force attacks.


4. File Sharing, Client Control and Data-Loss Protection

  • Password-protected file links.

  • Expiry dates for shared links.

  • Maximum number of downloads for file links.

  • Granular file and folder permissions.

  • Versioning for overwritten and deleted files.

  • Restoration options for deleted files.

  • Protection against accidental data loss caused by users.

  • Central control of client preferences.

  • Password protection for client preference access.

  • Admin-controlled remote wipe / remote deletion.


5. Secure Development and OWASP Top 10 Coverage

PowerFolder considers the OWASP Top 10 recommendations during development, quality assurance and security testing.

OWASP Risk Area

Implemented Controls

OWASP Risk Area

Implemented Controls

Broken Access Control

Role-based access control and validation of the permission model.

Cryptographic Failures

TLS encryption, AES/RSA transfer encryption and secure password hashes.

Injection

Input validation and parameterised database access.

Security Misconfiguration

Secure default configurations and regular security review.

Cross-Site Scripting (XSS)

Context-aware output encoding and dedicated XSS protections.

Cross-Site Request Forgery (CSRF)

CSRF protection mechanisms.

Vulnerable or Outdated Components

Regular security updates and dependency management.

Security Logging and Monitoring

Extensive logging and monitoring of security-relevant events.


6. Security Logging, Audit Trails and SIEM Integration

Logged Security Events

PowerFolder logs security-relevant events centrally in audit and server logs. Logged events include:

  • Login and logout events.

  • Failed login attempts.

  • Password changes and password resets.

  • User account changes.

  • Changes to group and role memberships.

  • File and folder shares.

  • File uploads, downloads, deletions and restorations.

  • Permission changes.

  • Administrative actions.

  • API access and authentication events.

Audit and Compliance Use

  • Logs can be stored in an audit-proof manner.

  • Logs can be evaluated for compliance and audit purposes.

  • Changes to users, groups, roles and file / folder permissions are logged.

SIEM Integration

  • PowerFolder supports integration with existing SIEM solutions via Syslog and standardised log formats.

  • Security events, errors and system events can be forwarded to central monitoring and SIEM systems.

  • Typical integrations include Splunk, Elastic and Graylog.


7. Monitoring and Operations

PowerFolder provides operational monitoring and system supervision capabilities, including:

  • Audit logs and server logs.

  • Syslog integration.

  • SIEM integration.

  • SNMP monitoring.

  • REST API for monitoring systems.

  • Monitoring of server state and services.

  • Storage capacity monitoring.

  • Database monitoring.

  • Cluster and replication monitoring.

  • Alerting for errors or critical system states.

Integration into existing monitoring solutions such as PRTG, Zabbix, Nagios, Icinga or comparable systems is possible.


8. Penetration Testing and Vulnerability Handling

External Security Testing

  • PowerFolder is regularly subject to external security reviews and penetration tests.

  • The tests are performed by qualified external security experts.

  • If required for a specific project, appropriately certified penetration testers can be commissioned.

Typical Test Scope

  • Web portal.

  • REST API.

  • Authentication mechanisms.

  • Administration interface.

  • Sharing functions.

  • File operations.

  • Mobile apps.

  • Desktop clients.

  • Integrations such as WebDAV, SAML and OnlyOffice.

Specific Test Areas

  • The role and permission model is tested with a focus on preventing privilege escalation.

  • Upload, download and sharing functions are tested, including misuse scenarios.

  • The PDF preview function has been tested as part of penetration tests. No security-relevant vulnerabilities were found in that context.

  • Before each software release, automated web tests are performed, including tests of the PDF preview functionality to ensure stability and quality.

Vulnerability Remediation and Re-Testing

  • Identified vulnerabilities are assessed according to criticality, prioritised and resolved through the established development and release process.

  • Critical security vulnerabilities are addressed quickly through hotfixes or out-of-cycle security updates.

  • After remediation, a re-test is performed to verify the effectiveness of the measures and to confirm successful closure of the vulnerability.

Reports and Confirmations

  • Depending on scope and confidentiality, management summaries, test confirmations or suitable extracts from test reports can be provided.

  • A penetration test certificate exists for PowerFolder licence penetration testing.


9. Malware Protection and Online Editing

  • Optional cloud malware protection is available through integration of antivirus solutions directly with the server.

  • Online document editing can be hosted on the customer's own infrastructure.

  • The connected anti-malware and online editing solution, including ONLYOFFICE in the PowerFolder Cloud context, is hosted together with the cloud infrastructure in Falkenstein.


10. Privacy, Jurisdiction and Server Location

Privacy Laws and Jurisdiction

  • PowerFolder / dal33t GmbH and all departments are located in Germany.

  • The company has no branches outside the Federal Republic of Germany.

  • PowerFolder / dal33t GmbH has no investors that may be bound by laws outside Germany or the European Union.

  • Therefore, only the privacy laws of Germany and the European Union apply.

The Privacy Statement is available here: PowerFolder Privacy Statement.

Server Location

  • The servers of PowerFolder Cloud and the connected anti-malware and online editing solution ONLYOFFICE are hosted in Falkenstein, Germany.

  • The high-security data centre is ISO/IEC 27001:2013 certified and operated by Hetzner Online GmbH.

Data centre certificate: DIN ISO/IEC 27001 certificate of the data centre / FOX certificate.


11. Certifications, Memberships and Supporting Documents

Item

Information

Link / Reference

Item

Information

Link / Reference

IT Security made in Germany

dal33t GmbH is a dedicated member of the TeleTrusT initiative.

TeleTrusT ITSMIG

IT Security made in EU

TeleTrusT trust seal for European IT security.

TeleTrusT ITSMIE

Data centre certification

ISO/IEC 27001:2013 certified data centre operated by Hetzner Online GmbH.

FOX_Zertifikat_de.pdf

Penetration test certificate

Certificate / confirmation for PowerFolder licence penetration testing.

Attach certificate document in Confluence, if publication is permitted.


12. Summary for Audits and Customers

PowerFolder combines encrypted communication, encrypted storage, central identity and permission management, tenant separation, audit logging, SIEM integration, operational monitoring, secure development practices and regular penetration testing. Security-relevant findings are assessed, prioritised, remediated and verified through re-testing. The platform is operated under German and European privacy law, with PowerFolder Cloud infrastructure hosted in an ISO/IEC 27001-certified data centre in Germany.


13. Web Session Cookies

Overview

PowerFolder uses only technically required cookies for authentication and session management. No analytics, tracking, or marketing cookies are used.

Authentication and authorization are performed exclusively on the server. Cookies contain only identifiers or cryptographic tokens and never store passwords, permissions, or file contents.

Cookies

Cookie

Purpose

Lifetime

Risk

Cookie

Purpose

Lifetime

Risk

JSESSIONID

Session management

Browser session

Low

lastUsername

Username prefill and MFA support

10 days

Low

token

Optional "Remember Me" login

30 days (configurable)

Medium

JSESSIONID

Used to associate HTTP requests with an authenticated user session.

Contains only a unique session identifier and no:

  • Passwords

  • User permissions

  • Personal data

  • File contents

The session expires on logout, browser closure, or timeout.

lastUsername

Stores the last used username or email address to improve usability and support MFA workflows.

Contains no authentication information.

token ("Remember Me")

Provides persistent login functionality when explicitly enabled by the user.

Contains only a cryptographic token. Passwords, session IDs, permissions, and file contents are never stored.

Tokens are validated server-side and removed immediately during logout.

Security Mechanisms

  • HttpOnly protection against JavaScript access and XSS attacks.

  • Secure flag for encrypted transmission over HTTPS.

  • Server-side authentication and authorization.

  • No password storage in cookies.

  • Automatic session termination during logout.

Privacy

Cookies are used solely for:

  • Authentication

  • Session management

  • MFA support

  • Optional persistent login

PowerFolder performs:

  • No tracking

  • No user profiling

  • No behavioral analytics

  • No third-party sharing

  • No marketing usage

Therefore, all cookies are classified as technically necessary.

Recommendations

  • Use HTTPS exclusively.

  • Enable MFA for privileged accounts.

  • Keep PowerFolder updated.

  • Use trusted endpoint devices.

  • Avoid "Remember Me" on shared systems.


Member of IT-Security made in Germany and EU

 

 

DIN ISO/IEC 27001 of our datacenter

 

 

 

 

Pentest Certificate