Reporting categories
- Government demands for account, payment, network, or other records
- Preservation demands, emergency requests, warrants, subpoenas, and court orders
- Demands received, rejected, narrowed, challenged, and fulfilled in whole or part
- Accounts and items affected, reported in ranges when exact counts would create risk
- Copyright, privacy, malware, CSAM, harassment, and other abuse reports
- Warnings, share restrictions, credential revocations, suspensions, terminations, and successful appeals
Legal-demand review
Cloak verifies the sender, authority, jurisdiction, scope, legal basis, and account specificity of each demand. We reject demands that are informal, defective, outside the issuing authority, or directed at data we do not control; seek to narrow overbroad demands; and disclose only records covered by valid process.
We notify an affected account before disclosure unless prohibited by law, delayed notice is required, or notice would create a credible safety risk. When notice is delayed, we provide it after the restriction expires when legally allowed.
What encryption changes
Cloak cannot disclose Private Drive plaintext or names that it cannot decrypt. It may still hold account identifiers, encrypted objects, storage and sharing metadata, request records, support messages, and payment references. Object plaintext passes through the gateway during ordinary S3 use unless the customer encrypts it first.
Warrant canary limits
Cloak does not use a warrant canary as a substitute for a transparency report. A canary can become ambiguous or legally constrained and cannot prove that no demand exists. We will instead publish dated aggregate reports and explain any reporting delay that we are legally permitted to explain.
Security evidence
Published audits and penetration tests identify the scope, assessor, date, material findings, remediation status, and excluded systems. Uptime claims identify the measurement window and monitoring source. A badge or score is never presented without its supporting evidence.
Publication schedule
Transparency reports are published every six months. Prior reports remain available in an archive, and corrections are dated rather than silently overwriting the original record.
Report contents
- Legal demands received, rejected, narrowed, and fulfilled
- Accounts or items affected
- Abuse reports and enforcement outcomes
- Appeals received and successful appeals
- Material security incidents and customer notifications
- Changes to retention, subprocessors, or legal jurisdiction