Security Architecture & Trust

SaveInDrive is architected around data minimization, ephemeral in-memory streaming, and standard TLS 1.3 transport security. This page details how user data, authentication credentials, and file streams are handled across our infrastructure.

🛡️ Zero Local Disk Storage

The file payload streams through cloud servers directly into your Google Drive without being saved to your local device. Incoming chunks pass through temporary memory buffers and are immediately released after Google confirms write acknowledgment.

🔒 Transport Layer Security

All ingress connections from origin URLs and all egress connections to Google's official REST API endpoints operate over TLS 1.3 or TLS 1.2 with standard certificate validation. Unencrypted HTTP is never used for Google API transactions.

🔑 Google OAuth 2.0 Scopes

SaveInDrive utilizes official Google OAuth 2.0 authorization. By default, the application requests the narrow drive.file scope (access only to files created or opened by this app). You can inspect our full Google API Disclosure or revoke access at any time.

🚫 SSRF & Network Filtering

The transfer pipeline strictly validates all remote URLs before initiation. Requests targeting private IP subnets (RFC 1918), localhost loopbacks (127.0.0.1, ::1), cloud metadata endpoints (169.254.169.254), or non-HTTP protocols are rejected.

⚡ Rate Limiting & Abuse Prevention

Sliding-window and token-bucket algorithms protect against denial-of-service, automated link harvesting, and resource exhaustion, ensuring steady operational capacity for all users.

🔏 Session Token Security

Session cookies are signed cryptographically with HMAC-SHA256, set with HttpOnly, SameSite=Lax, and Secure flags to prevent cross-site scripting (XSS) extraction and cross-site request forgery (CSRF).

How OAuth Credentials Are Handled

When you connect your Google account, Google issues a scoped OAuth access and refresh token. These credentials allow SaveInDrive to negotiate resumable upload sessions with Google Drive on your behalf.

  • No Password Access: SaveInDrive never sees, asks for, or stores your Google account password. Authentication occurs entirely on Google's hosted login dialog.
  • Revocation Anytime: You can disconnect directly within the SaveInDrive interface, or globally via Google Account Security Permissions. Once revoked, all access terminates immediately.
  • No Secondary Use: User tokens are used strictly to complete transfers requested by the user. Tokens are never used for analytics, marketing, or machine learning training.

Vulnerability Reporting

We take the security of our platform seriously. If you believe you have discovered a security vulnerability or potential exposure in SaveInDrive:

Please send details to security@saveindrive.com or inspect our published RFC 9116 security policy at /.well-known/security.txt. We review reports promptly and coordinate responsible disclosures.