Built with paranoid-grade security
Your photos are your memories. We treat them with enterprise-grade security from day one — because you deserve nothing less.
Our seven security commitments
✓ End-to-end encryption
TLS 1.3 in transit. AES-256 at rest. Envelope encryption for sensitive data. Optional zero-knowledge mode on Pro tier.
✓ Read-only Google access
We only request photoslibrary.readonly scope. We cannot delete from your Google account. Ever. Period.
✓ Verify before delete
Every photo is checksum-verified (SHA-256) before we allow you to delete from Google. We show the match. You confirm the batch.
✓ Signed URLs only
Your photos never have public URLs. Every view uses a 5-minute, single-use signed link. Leaked links die in minutes.
✓ CSAM protection
Every upload scans through Microsoft PhotoDNA. Matches are quarantined and reported to authorities within one hour.
✓ Full audit log
Every action — login, upload, share, delete — is logged with IP and timestamp. You can download your own audit trail.
✓ DPDP Act compliant
India's Digital Personal Data Protection Act 2023. Granular consent, data export, right to erasure, grievance officer — all built-in.
✓ No AI training on your photos
In strict compliance with Google API Limited Use policy. Your photos never train any AI model — ours, or anyone else's.
12-Layer Defense in Depth
Every security layer assumes the previous one has failed. An attacker must defeat all twelve independently.
Questions about security?
We welcome security researchers. Contact security@shiftphotos.com for responsible disclosure.