🚀 First Month FREE 1 TB Storage - Sign Up with the NGDS Android App!
Cloud storage security features illustration
Security & PrivacySecure Cloud StorageData PrivacyEncrypted StorageFile Sharing Protection

"Secure cloud storage" is on nearly every provider's homepage, which makes the phrase almost meaningless on its own. What matters is which specific mechanisms are actually behind that claim. Here are six worth checking for any provider you're considering, including NGDS.

1. Encryption for data in transit and at rest

Files should be encrypted while they're being uploaded or downloaded (in transit) and while they're sitting on the provider's storage (at rest). NGDS applies encryption to protect files during storage and transfer - if a provider's marketing only mentions one of the two, it's worth asking which.

2. File integrity checks through hashing

NGDS uses SHA-256 hashing to identify files by their content, which serves a dual purpose: it powers duplicate detection, and it means a file's fingerprint changes if its contents are altered, which can help verify a file hasn't been corrupted or tampered with in storage.

3. Granular sharing permissions

Being able to set view-only versus edit access on a per-share basis limits how much damage a single mis-sent link can do. Broad, all-or-nothing sharing is a common way sensitive files end up more exposed than intended.

4. Password-protected and expiring links

A share link without a password or an expiry date is effectively public to anyone who gets the URL, indefinitely. NGDS supports adding a password and an expiry date to share links, which meaningfully narrows the window and audience for a shared file.

5. Account verification during sign-up and sign-in

One-time password (OTP) verification during account creation and sensitive account actions helps confirm that the person signing up or signing in is actually who they claim to be, reducing the risk of accounts being created or accessed with someone else's email address.

6. Version history as a recovery mechanism

Security isn't only about keeping people out - it's also about recovering when something goes wrong, whether that's an accidental deletion, a bad overwrite, or a file affected by malware. Version history turns a potentially permanent loss into a recoverable one.

Encryption terms, explained plainly

Providers use several encryption phrases that sound similar but mean different things. Understanding the difference makes it easier to read a security page critically.

TermWhat it meansWhat it means for you
Encryption in transitData is encrypted while travelling between your device and the provider (typically HTTPS/TLS)Someone on the same Wi-Fi network cannot read your upload
Encryption at restData is encrypted while sitting on the provider's storageA stolen disk or misconfigured backup does not expose readable files
Client-side / end-to-end encryptionFiles are encrypted on your device and the provider does not hold the keysStrongest privacy, but the provider cannot preview, deduplicate or recover files for you

Most mainstream services encrypt in transit and at rest but manage the keys themselves, which allows features like thumbnails, search, deduplication and account recovery. True end-to-end encryption trades those conveniences for stronger privacy. Neither is wrong - the important thing is knowing which model a provider actually uses, and asking if it is not stated clearly.

What you should do on your side

Provider-side security only goes so far. Most real-world account compromises come from weak passwords, reused credentials and phishing rather than from breaking encryption.

  • Use a unique, long password for your storage account and keep it in a password manager.
  • Turn on any additional verification the service offers.
  • Review your active share links every month and revoke the ones you no longer need.
  • Lock your phone and computer, and sign out on shared or public devices.
  • Treat unexpected emails asking you to "verify" or "restore" your storage account with suspicion, and go to the site directly instead of clicking the link.

Red flags in security marketing

  • Vague phrases such as "military-grade" or "bank-level" with no description of the actual mechanism.
  • Certification badges with no named standard or way to verify them.
  • No clear explanation of what happens to your data if you delete it or close your account.
  • No visible way to contact the company about a security concern.

When you're comparing providers, ask for the specific mechanism behind each security claim rather than taking "bank-level encryption" or "enterprise-grade security" at face value - those phrases don't have a fixed technical meaning, but the six items above do.

See NGDS security features