ArchiviosArchivios
SecurityPricing
Savings CalculatorFAQBlogFeaturesHow it works
Sign UpDownload

How Archivios Protects Your Account Against Takeover Attempts

Published 2026-09-14

We've spent the last few posts on how attackers get into cloud accounts — SIM swaps, reused passwords, weak recovery habits. This one is about what happens on our side once you're a step past all that: what actually protects your account and your photos while they're sitting with us.

Layer one: your photos are unreadable without your device

With end-to-end encryption turned on, your photos and videos are encrypted on your device before they're ever uploaded. The key that unlocks them is generated and stored only on your device — we never receive it, never derive it, and never hold a copy anywhere in our systems. What sits in our storage is ciphertext and an encrypted key blob, not a viewable photo.

That means if our storage or database were somehow fully exposed, an attacker would get exactly what we have: unreadable data. There's no "we tried our best" caveat here — the architecture itself doesn't hold a readable copy of your photos anywhere. We go through this in more depth in why we can't read your photos or videos.

Layer two: your originals live somewhere a live breach can't reach

Your files aren't sitting in a fast, always-online database — they're stored in Glacier Deep Archive, a cold-storage tier that isn't queryable the way a live system is. Pulling a file back out requires an explicit, logged restore request, not a live read. That's a meaningful difference from storage designed for instant access: it removes an entire class of "attacker gets in and silently exfiltrates everything" scenarios, because there's no live path to silently exfiltrate through.

Layer three: recovery is designed so one mistake doesn't lock you out — or let someone else in

Account takeover attempts often succeed by abusing account recovery flows, not by breaking encryption. We deliberately split recovery into three independent paths — your recovery code, an already-signed-in device, or a trusted recovery contact — so that no single leaked piece of information is enough on its own to take over an encrypted account. We detail exactly how each path works, and what happens if all three are lost, on the encryption and recovery page.

Layer four: two-factor login, hidden secrets, and tamper checks

Beyond encryption and storage design, a few smaller details do real work day to day:

  • Two-factor authentication on new devices. When a new device signs in for the first time, we challenge it with a second factor — either a TOTP authenticator app code or a one-time email code, plus backup codes for when neither is available. This is app-based 2FA, not SMS, so it isn't exposed to the SIM swap risk described earlier.
  • Sensitive screens are hidden from the App Switcher. Recovery codes, device-transfer QR codes, and recovery-contact setup screens are covered with a lock icon the instant the app leaves the foreground, so they never sit in iOS's cached app-switcher snapshot. Worth being precise here: this covers the cached snapshot, not an active screen recording — iOS has no API to block that outright.
  • Jailbreak and tampering checks. The app checks for jailbreak indicators and known instrumentation tools (like Frida or Cycript) that are commonly used to bypass an app's own security logic, and adjusts its trust accordingly on a compromised device.

What this doesn't replace

None of this removes your side of the equation. If your Archivios password is reused elsewhere and leaked, or your phone number is SIM-swapped and used to intercept a login code, an attacker can still attempt to sign into your account through the normal front door — encryption protects the photos themselves, not a compromised login. That's exactly why the earlier posts on password reuse and SIM swapping aren't just general security advice — they're the other half of the same protection this post describes.

Security here isn't one feature. It's encryption you control, storage that isn't casually reachable, and recovery paths built so that losing one thing doesn't cost you everything.

Download on the App Store

See also: Why we can't read your photos · 2FA & recovery key habits · Encryption & recovery, in full

Tags: account recovery, encryption, security, privacy, data breach

Archivios

Your photos, preserved forever, encrypted.

Product

SecurityPricingSavings CalculatorFAQBlogFeaturesHow it works

Compare

vs Google Photosvs iCloudvs Dropboxvs Backblazevs Amazon Photos

Legal

Privacy PolicyTerms of Service

Contact

hello@archivios.uk

© 2026 Archivios. All rights reserved.

We use privacy-friendly analytics (Google Analytics) to understand site traffic. No data is sold or used for ads. Learn more.