Security Overview: Encryption, Hosting, Audit Logs
How Peony handles encryption, hosting, access control, audit logs, backups, and incident response.
Last updated July 22, 2026
How Peony handles encryption, hosting, access control, audit logs, backups, and incident response. For formal compliance status (SOC 2, GDPR), see Compliance and Certifications.
Encryption
- At rest: AES-256 for all files, metadata, and database contents — including primary, backup, and archived storage.
- In transit: TLS 1.2 or higher, enforced at the edge. Older versions rejected.
- Passwords and tokens: no plaintext passwords stored. Authentication is OTP-based; SSO tokens are hashed with bcrypt and salted.
- Backups: same AES-256 encryption as primary storage.
Hosting
AWS US region (US-West) today. AWS EU region is in the process of being set up. Peony is GDPR-compliant on the existing US infrastructure today regardless of where the customer is located — see Compliance and Certifications for the formal compliance posture.
- Files stay on Peony's infrastructure. Viewers read documents in-browser from Peony's servers. Files are never sent to recipients unless you explicitly enable downloads on a link.
- Minimized third-party processing. Core file storage, rendering, and access control all run on Peony's infrastructure.
- AI uses vetted LLM providers. Auto-indexing, Q&A, and extraction call enterprise-tier LLM APIs under data-handling agreements that prohibit training on customer content.
EU-region hosting: see Compliance and Certifications.
Access Control
- Authentication. Admins sign in with email OTP or Google. No password fallback. See Can't Sign In: OTP Not Arriving.
- 2FA. OTP-first sign-in is already a second-factor challenge. TOTP-based 2FA is on the roadmap.
- SSO. Google Workspace SSO on all paid plans. SAML/Okta/Azure AD on Enterprise.
- Sessions. Admin sessions time out after inactivity.
- Remote access revocation. Admins can instantly revoke a viewer's link or data-room access — the recipient loses access immediately, even mid-session (Business tier and above). This applies to viewer links, not to your own admin device session.
- Per-link controls. Email verification, NDA signing, IP allowlist, device-type gating, link expiry. See NDA Gates and Dynamic Watermarks.
- Internal access. Production data access limited to a small on-call rotation. All access logged.
Audit Logs
Every viewer session logs:
- Timestamp (start/end)
- Viewer email (if email verification is on)
- IP address
- Device and browser fingerprint
- Pages opened, order, duration
- Download events (if allowed)
- NDA acceptance events
- E-signature events
Inside a data room, the sidebar has two separate surfaces for this data:
- Analytics — page-by-page analytics and engagement summaries. Available on all paid plans.
- Audit trail — a per-viewer timeline that reviews visitor activity across the data room (views, downloads, NDA acceptance, and e-signature events with full event payloads). This is its own tab, distinct from Analytics. The full Audit trail requires the Data Room plan and above.
Basic exportable session and analytics logs remain available on all paid plans; only the full Audit trail (link, permission, NDA, and team changes with event payloads) requires the Data Room plan.
Logs are retained for the life of the data room, then purged with the room after the soft-delete window.
Data Retention and Deletion
- Retained until you delete. No automatic purge based on age.
- 30-day soft-delete window for both whole data rooms and individual folders. After deletion they enter a grace period and can be restored on request.
- After soft-delete: data purged from primary storage. Backups age out on the normal retention schedule.
GDPR / CCPA deletion requests: deqian@peony.ink.
Backup and Disaster Recovery
- Cadence: automated snapshots every 4 hours.
- Retention: 30 days rolling.
- Restore scope: individual rooms, folders, or files — email support with the workspace name and item to restore.
Accidentally deleted something? Email sean@peony.ink or deqian@peony.ink with the workspace name and the item name. See Contact Support.
Incident Response
- Triage. Production systems monitored for anomalies. Confirmed incidents triaged within business hours.
- Notification. Incidents affecting customer data disclosed to affected customers within 72 hours of confirmation (GDPR Article 33).
- Post-incident reports. Available for Enterprise customers on request.
- Bug disclosures. Peony discloses product bugs directly to affected customers in plain English. Transparency over obfuscation.
Common Questions
Can Peony staff see, move, or edit the documents in my room? No. Peony has no access to your room content. Support cannot open, move, or edit your documents. If something goes wrong with a document or upload, send a screenshot and the exact error code to sean@peony.ink so the team can help without needing access to your files.
How is my data encrypted, and what industry standards do you follow? Files, metadata, and database contents are encrypted at rest with AES-256, and everything is encrypted in transit with TLS 1.2 or higher. Peony follows standard industry security practices and is SOC 2-ready. See Compliance and Certifications.
Which region is my data hosted in? Sub-Enterprise plans are hosted on AWS in the US (US-West). An AWS EU region is being set up. Peony is GDPR-compliant on the existing US infrastructure today regardless of where you are located.
Where do I see who viewed a document and when? Open the data room, then use the Audit trail tab in the sidebar for a per-viewer timeline of views, downloads, NDA acceptance, and e-signature events. Use the Analytics tab for page-by-page engagement. The full Audit trail is on the Data Room plan and above.
Can I revoke someone's access after I've shared a link? Yes. Admins can instantly revoke a viewer's link or data-room access, and the recipient loses access immediately (Business tier and above). This revokes viewer access, not your own admin sign-in session.
