FAQ
Security & Privacy
Last updated 13 October 2017

Is my data encrypted and secured?

The safety and security of our customer data are our highest priorities. Our API clients are using HTTPS (TLSv1, TLSv1.1, TLSv1.2) to send your data to our servers and you can choose to use TLS to query our indices as well.

By default, our JavaScript API client will use the same protocol as the page hosting it.

The backups are encrypted using GnuPG and the transfers between servers are encrypted via AES-256.

We put a lot of effort into having the best security. For instance, it took us only a few hours after the disclosure to fix the HeartBleed vulnerability.

We’re performing regular independent penetration testing and have public bug bounty program on HackerOne that helps us ensure ongoing security.

If you want your data to be encrypted at rest, we provide this using AES-256 encryption with per-server keys managed by Algolia and available as Algolia Vault in our Enterprise offer.