Secure data management: five pillars instead of promises
WebDisk Blog · category: About us · reading time: ~5 minutes
In brief:- Instead of assuring you that we are "secure", we show five verifiable pillars: encryption of your choice, backups locked against deletion, round-the-clock monitoring, support in Polish and data processed in Poland.- Each pillar links to material in which we describe it in more depth – this text is a map, not an advertising brochure.- We also say honestly what we do not promise – and which part of security always stays on your side.
"Secure cloud" is the cheapest declaration in the industry – every provider writes it, so the word alone no longer means anything. If you entrust someone with your company's data, you have the right to ask: what exactly stands behind that adjective? Which mechanisms, which backups, who watches the monitoring – and what happens when something does go wrong after all?
This article is our answer: a map of the five pillars that make up secure data management at WebDisk. There are deliberately no superlatives here – only mechanisms, their limits and pointers to the texts in which we describe each pillar in detail. If you are comparing cloud providers right now, treat this list as a set of checklist questions and put them to every provider, not just to us.
Pillar 1. Encryption – as a choice, not an advertising slogan
Communication with our services – the panel, the API, the applications – is encrypted with TLS, the same technology that stands behind the padlock in your browser. That layer is mandatory and not up for discussion. More interesting is what happens to the data sitting on the disks: here we put the decision in your hands. In our file platform, when you create a storage space you can choose permanent – irreversible – encryption of everything at rest, and an organization can additionally cover selected files and folders with encryption using a separate organization key – managed by the platform and stored separately, so that the object storage layer never persists the key next to the data. We describe in detail the encryption options in the S3 world, and who holds the key in each of them, in the article on encryption in S3 – SSE-S3, SSE-KMS and SSE-C.
An honest limit: encryption at rest protects the media and the backups – it does not protect the account. A stolen password is a different class of problem. That is precisely why there are five pillars, not one.
Pillar 2. Backups that not even an administrator can delete
A disk failure, human error and ransomware share a common denominator: a backup saves you from them – but only one that an attacker can neither overwrite nor delete. That is why – alongside the classic backup, which is worth making anyway in line with the 3-2-1 rule (three copies, two different media, one off-site – more in the article on backup as the foundation of IT security) – our file platform offers file versioning and an Anty-Ransomware mode based on S3 Object Lock: a copy that nobody can remove by any operation on the storage before the agreed retention period expires – neither an intruder with stolen keys nor the account administrator. This is a property of the design, enforced by the object storage layer itself, not a promise in the terms of service. We take this mechanism apart in the article on S3 Object Lock and WORM mode.
Pillar 3. Monitoring that works when nobody is watching
Behind our services stands a layered detection system built from proven open source projects – among others the open-appsec application firewall, the Suricata network probe, Falco sensors running inside the systems and the Wazuh SIEM (a system that collects events from across the platform and assembles individual signals into a picture of an attack). Alerting runs automatically at any hour of the day and night, and the monitoring itself is supervised by an independent watchdog from outside our infrastructure – because "who watches the watchdog?" is a question you have to ask yourself as well.
We pass part of that visibility on to you: the public status.webdisk.io page shows the availability of our services live – measured by probes from the internet, that is from the customer's perspective, with no embellishment. And in the article on Watchdog we show how to monitor the state of your own virtual machines in the cloud yourself.
Pillar 4. Support in Polish – from the people who maintain this platform
When something does not work, the last thing you need is to explain the problem in a global helpdesk form. With us a ticket goes to the team that builds and maintains this platform day to day – in Polish, without intermediaries and without scripted replies. You are not buying a "support level" from a price list; you are talking to an engineer who knows the answer or knows who does. We described what this looks like in practice in a separate text about WebDisk support.
Pillar 5. Data in Poland, under the EU legal regime
Your data is processed in Poland, on infrastructure that we build and control ourselves – under the legal regime of the European Union. In practice this means GDPR as the default processing standard, Polish jurisdiction instead of guessing whose law reaches your files, and a partner with whom you will discuss the data processing agreement in your own language. In our article on Polish cloud computing we write more broadly about why data location and technological sovereignty mean more than a logo on an invoice.
What can a cloud provider not promise you?
You will not find the phrases "completely secure" or "unhackable" in anything we write. In security you assume that safeguards will fail, not that they are perfect – each of the pillars exists precisely because another one may one day fail. Encryption will not stop ransomware, a backup will not detect a break-in, monitoring will not bring back deleted files. Security is the sum of layers and the process of tuning them, not a state that you reach once and announce in a brochure.
A second honest note: part of the responsibility always stays on your side. Strong passwords, granting co-workers permissions with care, good access-key hygiene – no provider will do that for you, and neither will we. This is the shared responsibility model: we answer for the platform and its layers of protection, you – for access to your account and for who you grant it to. A provider who promises to take that part off you as well is promising too much.
Frequently asked questions
Does encrypting data in the cloud protect against an account takeover?
No. Encryption at rest protects the media and the copies of your data – it does not protect the account itself. A stolen password is a different class of problem, which is why security has to consist of many layers, and some of them – strong passwords, permissions granted with care, good access-key hygiene – always stay on the user's side.
Can an administrator or an intruder delete a backup protected by S3 Object Lock?
No. A copy saved in Anty-Ransomware mode, based on S3 Object Lock, cannot be removed by any operation on the storage before the agreed retention period expires – neither by an intruder with stolen keys nor by the account administrator. This lock is enforced by the object storage layer itself, not by a clause in the terms of service.
What is the 3-2-1 backup rule?
It is the classic principle of backup planning: keep three copies of your data, on two different media, one of them off-site. Alongside it, it is worth having a copy that an attacker can neither overwrite nor delete – and that is exactly the role of the Anty-Ransomware mode in our file platform.
Where is WebDisk customers' data processed and what law covers it?
The data is processed in Poland, on infrastructure that we build and control ourselves, under the legal regime of the European Union. In practice this means GDPR as the default processing standard, Polish jurisdiction and a data processing agreement that you can discuss in your own language.
What is the cloud provider responsible for, and what is the customer responsible for?
This is the shared responsibility model: the provider answers for the platform and its layers of protection, the customer – for access to their account and for who they grant it to. No provider will ensure strong passwords, careful granting of permissions and good access-key hygiene for you.
What does "partner in secure data management" really mean?
"Partner in secure data management" is not a title you can simply award yourself. It is the sum of verifiable mechanisms, clearly named limits and people on the other side of a ticket. The five pillars in this text are our version of the answer – and the articles in the security series, linked at each pillar, take them apart piece by piece.
Are you choosing a cloud provider for your company? Ask them these five questions. And if you want to talk about them with us – write to us.