Security At Aprigo
Metadata only
Aprigo works without opening or reading the content of files on your network. Aprigo only collects metadata from your environment (like file creation time, file modification time, folder permissions, etc..).

Encryption
Metadata is encrypted on transfer using SSL and at rest using 256-bit AES
SAS70-II Data Center
Aprigo NINJA is Hosted on Amazon Web Services (AWS)
User Authentication
Application access is protected to ensure privacy of data using strong user authentication
Aprigo Security FAQ
Q: What type of data does Aprigo collect from my systems ?
A: Aprigo collects the following metadata from your file systems:
- File & Folder names (Paths of scanned shares can include server names)
- File & Folder modified time, last access time, created time, owner, size
Aprigo collects the following data from your Active Directory:
- User names
- Group names
- Group memberhsip information
Q: What data is sent to aprigo.com?
A: All data that is sent is fully encrypted. Aprigo does not send specific information about files, and the following metadata is sent to aprigo.com:
- Folder names (optional)
- Folder modified time, last access time, created time, owner, size
- Summary statistics (how many file of type pdf, how many files are older than 180 days, etc..)
- Active directory user and group names (optional)
Q: Is the data being sent safe ?
A: All data is encrypted on transfer. Aprigo uses very high encryption standards and all data is sent over a secured http conntection (https). In addition:
- All access to information is privileged and available to you only after authentication.
- Data is encrypted at rest when it is stored at aprigo.com
- Servers reside behind sophisticated firewalls, introduction detection systems and other access control mechanisms to ensure no unauthorized data access.
- Aprigo protects the collection services (Aprigo’s onsite software) by uniquely binding every Aprigo collection service to your aprigo account and requiring all access to be authenticated.
Q: Are my network credentials sent to aprigo.com ?
A: NO. The domain account you use to configure aprigo scans will always stay on premise and is encrypted. It will never be sent to aprigo.com
Q: Can I delete all collected metadata after it is sent to Aprigo’s secure data center?
A: YES. If at any time you chose to delete your metadata, contact Aprigo and we will remove it promptly. It’s your metadata.






