Skip to content
AirtableBackup

Security

What is encrypted, who can read what, and what we do not claim.

A backup service holds a copy of your data and a way into your Airtable. This page says exactly how both are protected, in the words of what the code does today, and names the things it does not yet have.

Encryption

In transit, at rest, and the keys

In transit
Every connection, to the console, to Airtable, to AWS and to Paddle, uses TLS. The console is served only over HTTPS.
At rest
Backups are stored in Amazon S3 with server-side encryption. The working database on the server holds no secrets; a nightly copy of it goes to a second bucket, also encrypted.
Airtable tokens
The OAuth tokens that let the service read your base are encrypted field by field with AES-GCM under a data key generated for that one record, and the data key is wrapped by a key in AWS KMS. The server may only generate and unwrap such keys; it cannot administer the key. No component decrypts a token except the one about to call Airtable. Losing the KMS key would lose every token and no backup data: each customer would reconnect once.

Access

Who can read what

Your people. An account’s members are invited by email by an owner, and sign in with Airtable. A member sees a base only if they are a collaborator on it in Airtable, at edit or better, checked against Airtable, so removing someone from the base in Airtable removes their access to its backup. Owners and admins manage people, connections, alerts, settings and bases; members read.

Writes to your Airtable. Backing up needs read access only. A restore asks you to sign in with Airtable yourself, in a small window, for write access that lives at most an hour and is never stored; the refresh token is discarded. The optional nightly restore test is the one standing write consent, given once under Settings, scoped to a scratch workspace you name, and removable at once.

Between customers. Each base’s backup lives under its own storage prefix, is backed up by its own process, and the service answers “not found” for any base that is not the signed-in account’s. Alerts and the nightly report are built per account from that account’s data only.

Us. Operators do not browse customer bases. Operational alerts carry an account id and plain-words summaries (“bulk deletion in base X”), not data. The service’s own credentials cannot delete backups, cannot administer encryption keys, and can send email only from @airtablebackup.com.

Deletion

Denied by policy, allowed only through a door with two locks

The storage bucket keeps every version of every object. Its bucket policy denies deletion, and changes to its lifecycle rules, to every identity in the account, the running service included, except one separate break-glass role. That role cannot be assumed by the service at all; a person must assume it, with multi-factor authentication, and every assumption is recorded in CloudTrail. The same role is the only path for the deletion that follows an account’s end (90 days after a lapse, see the retention policy), and that step is run by a person with a record kept.

Object Lock was considered and not used: lawful deletion requests must remain possible. Deny-by-policy plus versioning gives the same protection against a mistaken or malicious delete while keeping a lawful one possible.

What is not claimed

Plainly

  • No SOC 2. AirtableBackup does not hold SOC 2 or any third-party security certification at this time and does not claim one. ProBackup does; if a report is what your policy requires, that matters, and the comparison says so.
  • No uptime or recovery figure. The service is run with care and without a service-level agreement in this version. Backups depend on Airtable’s API being available and on the request limits Airtable sets for your base.
  • No customer count. None is published.
  • One region. Data is stored in the United States only, in AWS us-west-1. There is no EU storage option today.

Report a vulnerability

Write to a person

If you believe you have found a security problem in AirtableBackup, email support@airtablebackup.com with “Security” in the subject. Include what you found, how to reproduce it, and how to reach you. A person replies within one business day, and you will hear what was done about it. Please do not access, change or delete data that is not yours while demonstrating a problem.

Subprocessors

Who else touches your data

ProviderLocationPurpose
Amazon Web Services, Inc.us-west-1 (Northern California, USA)Compute (EC2), storage (S3), key management (KMS)
Amazon Web Services, Inc. (Amazon SES)us-west-1 (USA)Sending alert, report and billing emails
Paddle[PADDLE LOCATION: UK/USA]Checkout, payment, tax, invoicing and subscription management, as merchant of record
Airtable, Inc.USAThe source system your data comes from and is restored to; receives API calls on your behalf under the access you granted

No analytics, advertising or tracking service runs on this site or in the console. The full list and the terms under which each provider works are in the privacy policy; a data processing addendum is available on request.