Security controls you can understand.
TuckR89 Cloud combines secure account access, private storage, integrity checks, and recovery tooling without making absolute or unverified security claims.
Secure communication
The mobile app communicates with the TuckR89 Cloud API over HTTPS/TLS. File transfers may use short-lived, authorized storage URLs so large files can move directly between an authorized device and object storage without exposing permanent public file URLs.
Authentication and sessions
The service supports secure authentication sessions with access and refresh tokens. Mobile authentication tokens are stored using platform-appropriate secure storage. Signed-in device/session management allows users to review active sessions and revoke other sessions.
Email verification and account recovery
Email verification may be required by the service. Password recovery uses short-lived verification/reset codes. Account security activity is logged to support investigation and customer visibility.
Authenticator-based 2FA
Users can enable authenticator-app two-factor authentication and generate recovery codes. Recovery codes should be stored securely and treated as sensitive credentials.
Passkeys
Passkeys are supported on compatible devices and platforms. Biometric verification associated with a passkey may be performed by the user's device or credential provider. TuckR89 Cloud does not receive a user's fingerprint or facial scan merely because a passkey is used.
File integrity
Completed uploads can be associated with integrity information such as a SHA-256 checksum and a verification state. The app can display this status so users can distinguish between an available file and a file that is still being verified.
Secondary replication
Protected files may be copied to secondary storage for recoverability. Secondary replication is a separate protection state and is not described as encryption or as a guarantee against all data loss.
What we do not claim
TuckR89 Cloud does not claim zero-knowledge encryption, end-to-end encryption, client-side encryption, military-grade encryption, HIPAA compliance, SOC 2 certification, ISO certification, GDPR certification, absolute security, or that files can never be lost unless such a claim is separately verified and formally published.