Security Overview: Encryption, Hosting, Audit Logs
How Peony handles encryption, hosting, access control, audit logs, backups, and incident response.
Last updated October 3, 2026
How Peony handles encryption, hosting, access control, audit logs, backups, and incident response. For formal compliance status (SOC 2, GDPR), see Compliance and Certifications.
Encryption
- At rest: AES-256 for all files, metadata, and database contents — including primary, backup, and archived storage.
- In transit: TLS 1.2 or higher, enforced at the edge. Older versions rejected.
- Passwords and tokens: no plaintext passwords stored. Authentication is OTP-based; SSO tokens are hashed with bcrypt and salted.
- Backups: same AES-256 encryption as primary storage.
Hosting
AWS US region (us-east-1). EU-region hosting can be arranged on the Enterprise plan. Peony's practices are aligned with GDPR on the existing US infrastructure, wherever the customer is located — see Compliance and Certifications for the formal compliance posture.
- Files stay on Peony's infrastructure. Viewers read documents in-browser from Peony's servers. Files are never sent to recipients unless you explicitly enable downloads on a link.
- Minimized third-party processing. File storage and access control run on Peony's infrastructure, and third-party processing is kept to what the service needs.
- AI uses vetted LLM providers. Auto-indexing, Q&A, and extraction call enterprise-tier LLM APIs under data-handling agreements that prohibit training on customer content.
EU-region hosting: see Compliance and Certifications.
Access Control
- Authentication. Admins sign in with email OTP or Google. No password fallback. See Can't Sign In: OTP Not Arriving.
- 2FA. OTP-first sign-in is already a second-factor challenge. TOTP-based 2FA is on the roadmap.
- SSO. Google and Microsoft sign-in (OAuth SSO) on Deal Team and Enterprise. SAML/Okta/Azure AD on Enterprise.
- Sessions. Admin sessions time out after inactivity.
- Remote access revocation. Admins can instantly revoke a viewer's link or data-room access — the recipient loses access right away (Business tier and above). A page they already have open can stay on screen until they reload or move to another page. This applies to viewer links, not to your own admin device session. See Revoking access.
- Per-link controls. Email verification, NDA signing, IP allowlist, device-type gating, link expiry. See NDA Gates and Dynamic Watermarks.
- Internal access. Peony staff can't open, move or edit the documents in your room. They see account-level information only, such as usernames, NDA signing status and account status.
Audit Logs
Every viewer session logs:
- Timestamp (start/end)
- Viewer email (if email verification is on)
- IP address
- Device and browser fingerprint
- Pages opened, order, duration
- Download events (if allowed)
- NDA acceptance events
- E-signature events
Inside a data room, the sidebar has two separate surfaces for this data:
| Surface | Shows | Plan |
|---|---|---|
| Analytics tab | Page-by-page analytics per document, plus the room-wide engagement dashboard. | Page analytics All plans, room dashboard Data Room+ |
| Audit trail tab | A per-viewer timeline that reviews visitor activity across the data room (views, downloads, NDA acceptance, and e-signature events with full event payloads). This is its own tab, distinct from Analytics. | Data Room+ |
Basic exportable session and analytics logs remain available on all paid plans; only the full Audit trail (link, permission, NDA, and team changes with event payloads) requires the Data Room plan. The full audit trail isn't self-serve exportable; for a copy after a deal closes, email sean@peony.ink.
Retention follows your plan: 30 days on Free, 1 year on Business, 2 years on Data Room, and no time limit on Deal Team and Enterprise. Logs are deleted with the data room.
Data Retention and Deletion
- Retained while your account is active. No automatic purge based on age while you're on a plan.
- After a paid subscription ends, shared links and data-room access stop working. Rooms and files are kept for 30 days by default (longer on request), and resubscribing within that window restores closed rooms in full.
- Deletion is permanent. Deleting a data room, folder or file removes it immediately, and it can't be restored by you or by Peony support. See Delete a file or folder.
GDPR / CCPA deletion requests: deqian@peony.ink.
Backup and Disaster Recovery
- Backups: database backups are encrypted and managed by our hosting provider.
- Scope: these backups protect the service as a whole, not individual rooms, folders or files.
Incident Response
- Triage. Production systems monitored for anomalies. Confirmed incidents triaged within business hours.
- Notification. Incidents affecting customer data disclosed to affected customers within 72 hours of confirmation (GDPR Article 33).
- Post-incident reports. Available for Enterprise customers on request.
- Bug disclosures. Peony discloses product bugs directly to affected customers in plain English. Transparency over obfuscation.
Common Questions
Can Peony staff see, move, or edit the documents in my room?
No. Peony has no access to your room content. Support cannot open, move, or edit your documents. If something goes wrong with a document or upload, send a screenshot and the exact error code to sean@peony.ink so the team can help without needing access to your files.
How is my data encrypted, and what industry standards do you follow?
Files, metadata, and database contents are encrypted at rest with AES-256, and everything is encrypted in transit with TLS 1.2 or higher. Peony follows standard industry security practices and is SOC 2-ready. See Compliance and Certifications.
Where do I see who viewed a document and when?
Open the data room, then use the Audit trail tab in the sidebar for a per-viewer timeline of views, downloads, NDA acceptance, and e-signature events. Use the Analytics tab for page-by-page engagement. The full Audit trail is on the Data Room plan and above.
