Security and privacy
Encryption, where your data lives, single sign-on, and your privacy rights.
7 articles
How are my notes encrypted?
Every vault is encrypted at rest with its own 256-bit key (AES-256-GCM). Vault keys are wrapped by a key per workspace, which is wrapped by a master key that never enters the database or backups. Traffic uses TLS 1.2 or newer. Read the full security model.
Is Granite end-to-end encrypted?
Granite uses managed encryption, with a key per vault and per workspace. Managed keys are what make search, the AI knowledge base, live co-editing, and admin recovery possible.
Where is my data stored?
Notes and attachments are stored encrypted on Granite's dedicated server. Encrypted backups are kept in Amazon S3 in the United States for 35 days. The sub-processor list names every provider and location.
Does Granite support single sign-on and SCIM?
Yes, on Business. Workspaces support SAML 2.0 and OpenID Connect with providers such as Okta, Microsoft Entra ID, and Google Workspace, plus SCIM to add and remove members automatically.
Is Granite GDPR and CCPA compliant?
Granite is built to meet the GDPR, UK GDPR, and the California CCPA/CPRA. You can access, correct, export, and delete your data from the app, and Granite never sells or shares personal information. Business customers get a data processing agreement. See the privacy policy.
What happens to data when a workspace is deleted?
The workspace is purged 30 days after deletion: its files and database rows are removed and its key is destroyed, so nothing it held can be decrypted again. Encrypted backups age out within 35 days.
How do I report a security issue?
Email security@granite.md with the details. Please give us a chance to fix the issue before sharing it publicly; we reply within two business days. More on the security page.