Security at WFC Drive
We host your files on hardware we own and operate — no public cloud, no third-party storage subprocessors. Here is how we protect them.
Encryption in transit
All connections are encrypted: HTTPS (TLS 1.2+) for web and WebDAV, SSH (SFTP) for file transfer with modern ciphers only — including post-quantum hybrid key exchange (ML-KEM + X25519). Plain FTP is not offered.
Account isolation
Every customer operates in an isolated, chrooted storage area with enforced quotas. Web sessions use your existing company sign-in (Google, Microsoft or your own provider) (inheriting your Google account's two-factor protection); SFTP credentials are unique per account and can be replaced with SSH keys. You can additionally restrict logins to your own IP ranges.
Malware scanning
Every uploaded file is automatically scanned with ClamAV. Infected files are removed on detection.
Brute-force protection
Repeated failed logins result in automatic, escalating IP bans. Web endpoints are rate-limited.
Backups
Account data and files are backed up daily to separate storage, with backup completion independently monitored. Deleted files remain in your Trash until you empty it.
Monitoring & patching
All services are monitored 24/7 with automated alerting. We track upstream security advisories and apply security patches promptly.
SSH host key fingerprints
On your first SFTP connection your client will show the server's host-key fingerprint and ask you to confirm it. If you would like to verify it against a value from us rather than simply accepting it, ask us and we will send it to you over a channel you already trust.
Reporting a vulnerability
Please report security issues to security@wfclogistic.com. We commit to acknowledging reports within 48 hours. See security.txt.
Data residency
All customer data is stored exclusively in our own US facility and never leaves it, except as you direct (downloads, shares).