How Your Files Are Encrypted
Part of the MountDev Ops Files documentation. Updated October 7, 2026
MountDev Ops Files documentation | Updated October 7, 2026
This page explains, in plain words, what happens to a file from the moment you upload it.
Your Company Has Its Own Key
Every company in MountDev Ops has its own files key. It is worked out, when it is needed, from a master secret that only the MountDev Ops service holds and from your company's account number, using a standard method for making keys (HKDF) with a label of its own. The same method makes the key for your saved API keys, with a different label, so the two keys are different. Another company's key is different again, and cannot open your files.
The key is never written down anywhere, never shown on any screen, and never put in any log.
Every File Gets Its Own Key Too
When you upload a file, it gets a random number of its own, kept with the file's details in your company's database. Your company's key and that number together make the file's own key. Two copies of the same file are stored completely differently.
Encrypted Before It Is Stored
Your file travels to MountDev Ops over HTTPS. Your company's own workspace then encrypts it, a piece at a time, before anything is stored. It uses AES-GCM, a standard, widely trusted way of encrypting that also detects any change.
- In pieces of 1 MB: each piece is encrypted on its own, with its place in the file and a mark on the last piece, so pieces cannot be swapped, reordered, mixed with another file's, or cut off without it being noticed. A file that was changed in storage is refused instead of being shown.
- Large files stream: because a file is handled a piece at a time, a large file such as a meeting recording never has to fit in memory, and a video can play from any point by opening only the pieces it needs.
Stored Without Names
Files are stored in Cloudflare R2, which encrypts everything it stores as well. The name a file is stored under is your account number and random letters. It never contains the file's name or your company's name. Names, types, sizes, and folders are kept in your company's own database.
Only Your Company Opens Your Files
- A file is opened only for someone signed in to your workspace who may see the record it belongs to.
- Every download and preview is written in your company's Activity Log.
- No Cascadia staff screen, Cascadia system, or AI agent can open your files. Cascadia can see only how much storage your company uses, for billing.
When You Delete a File
A deleted file disappears from every screen at once, and its stored copy is removed straight after. When you delete a record that holds files (a folder, or a company in CRM), its files are deleted with it.
