How we keep it

Three mail paths, client sites on the UK platform, and client files in encrypted vaults.

Care

Live sites and the files we keep for clients are not the same place.

Client sites. WordPress and static sites run on a UK platform, separate from the CAOD server. Day-to-day business mail for those domains is handled there too. A problem on a live site stays on that site.

Secure mail. tidalux.io mail is Proton, on that custom domain. That is the channel for sensitive correspondence.

Infrastructure mail. caod.ch mail is Tuta. Those messages use an extra password where the note allows it, they expire, and they are deleted. When a note also needs PGP, we add that on top. Infrastructure mail is not the client inbox.

Client files. Anything that is not the live site sits in a Cryptomator vault. Cryptomator encrypts the file on the machine before it is uploaded: contents with AES-256-GCM, names with AES-SIV. The cloud provider stores ciphertext. We keep those vaults on Proton Drive and on offline encrypted drives, including a copy that is not on the network. Losing the vault password means the files stay unreadable. We cannot reset it.

Sign-in. Studio accounts use a hardware key (FIDO) and a time-based code. Everyday passwords sit in Proton Pass. Client logins that should not live in a cloud vault sit in KeePassDX.

The CAOD server. Public pages are served from Gravelines, in France. The name is Swiss (caod.ch), registered through Infomaniak, and the .ch registry does not publish the holder. Public SSH is closed. Administration is on a private network. Home machines are not on the public internet.

Tidalux Ltd is registered with the ICO, number ZC091301. Questions: con@caod.ch.