Table of contents
Start for free
Gilbert Zhang / 2.26.2023Home / Cloud storage
Secure cloud storage—a buying guide and five providers reviewed
Among numerous allegedly secure cloud storage solutions, only a handful check all the necessary boxes. Discover the best option for storing your files.When entrusting your files to a third-party service, you must make sure the provider can guard them properly. Many cloud solutions promise safety and privacy, but not all of them deliver it.To help you avoid choosing a subpar platform, this guide will show you what to look for in secure cloud storage. You’ll also see the pros and cons of some popular options, so you can make an informed decision and choose the provider that suits your needs.
Choose a reliable and easy-to-use storageSkiff Drive provides top-notch security with end-to-end encryption and a modern design
Sign up
Key features of secure cloud solutions
When comparing secure cloud services, you should check if they offer the following crucial security layers and features:- Secure login
- Storage monitoring
- Threat protection
- Data encryption and privacy
Get a secure and practical storage solutionWith its automatic E2EE, Skiff Drive seamlessly integrates with Skiff Mail, Skiff Pages, and Skiff Calendar
Sign up
Secure and confidential login
Most cloud services let you log in with your email and password. To take account security to the next level, choose a provider offering two-factor authentication (2FA). It’s an additional security layer involving a one-time passcode sent to your trusted device. This passcode is necessary for accessing the account, even if the credentials are correct.Two-factor authentication is the best way to protect yourself from various cyberattacks, such as brute-force or dictionary attacks. It can also protect you from the more elaborate attempts to steal your credentials, like phishing. Even if someone has your password, logging in from another location will be considered suspicious activity and require a second passcode.Enabling two-factor authentication doesn’t lower the importance of setting strong passwords. Regardless of your cloud provider’s security measures, you must do your part and secure your account with complex login credentials.Besides two-factor authentication, your provider will ideally support zero-knowledge login. This means they don’t store your login data to minimize the risk of leaking in case of a breach. A handful of solutions, like Skiff, offer this option that gives you more confidentiality and peace of mind.Continuous storage monitoring
Your cloud provider should stay vigilant and monitor the traffic on their service to alert you of:- Unusual activity
- Logins from new devices or locations
- Data and file shares
Advanced threat protection
Managing users’ files and data is a great responsibility, so your cloud provider should have numerous security layers in place, such as:- Strong firewalls to control and filter traffic
- Intrusion detection systems to spot cyberattacks and ensure a swift response
- Outstanding redundancy, ensuring users don’t suffer downtime during server maintenance or possible malfunction
- Physical security of servers, preventing unauthorized access
Data encryption and privacy
Encryption is a crucial security and privacy measure that every cloud provider must offer. It’s a way of concealing your private data by scrambling it using an encryption key. Only the person with the decryption key should be able to decipher the data.The problem is this isn’t the case with most cloud services. They use standard encryption protocols like SSL or TLS, which offer basic protection while leaving your data visible to the service provider.This is because encryption happens on the provider’s servers. They create and own the decryption keys, which gives them unrestricted access to your files and data, so you don’t get much privacy.The best way to ensure confidentiality is client-side encryption, which is only possible with end-to-end encryption (E2EE).If your chosen service supports E2EE, files are encrypted on your device and stored in such a form on the server. The provider doesn’t have access to unencrypted copies or the decryption key, which is only available to an authorized recipient.E2EE is the gold standard for secure file storage and sharing, but it’s still not offered by most Big Tech cloud solutions. You must go with a privacy-first provider to enjoy its benefits.Best secure cloud storage—reviews of popular solutions
In recent years, several cloud providers have gained popularity thanks to their security measures and useful features:- MEGA
- Sync
- pCloud
- Tresorit
- Skiff Drive
MEGA
Source: MEGAMEGA is a solid end-to-end encrypted cloud solution offering robust security. It’s quite generous in terms of free storage and features, but the user experience and value for money you get with paid tiers could be better.
Pricing
MEGA offers a free plan and five paid tiers:- Pro Lite—$5.34/month
- Pro I—$10.86/month
- Pro II—$21.73/month
- Pro III—$32.60/month
- Business—Custom pricing based on storage, number of users, and transfer quota
Pros and cons
MEGA was founded by Kim Dotcom, an infamous entrepreneur involved in a major scandal that took the world by storm in 2012. Despite its founder’s past, MEGA is a reliable, reputable cloud solution featuring zero-knowledge encryption to give users comprehensive privacy and security.The best thing about the platform is ample free storage—you get 20 GB with the free plan, which is quite impressive. You also get most of MEGA’s features, barring some handy tools like password-secured sharing links.With servers in the EU, New Zealand, and Canada, MEGA is fully compliant with the GDPR (General Data Protection Regulation). It extends this protection to all users regardless of their location, which contributes to solid privacy.The platform’s main drawback is the user interface and overall experience. The design is slightly outdated compared to the sleek style you get with most providers, and the interface is quite cluttered.Collaboration features are also limited—you get a chat client but no integration with third-party apps or collaborative file editing.Another potential problem is a vulnerability discovered by cryptographers in 2022. Researchers uncovered a possibility of an internal attacker retrieving users’ encryption keys to access their files and install malicious code. While such attacks haven’t been reported, and MEGA has since released security patches, the vulnerability hasn’t been fully resolved.Pros | Cons |
Client-side E2EE | Outdated user interface |
20 GB with the free plan | Limited collaboration features |
GDPR compliance and extended user protection | Potentially dangerous vulnerabilities |
Sync
Source: SyncSync is a cloud storage solution that’s quite popular among individuals and business clients. It’s reasonably priced and offers decent value for money, though the free plan might not be generous enough for anyone but casual users.
Pricing
Sync offers several tiers besides the free plan, all involving an annual commitment:- Individual plans:
- Solo Basic—$8/month
- Solo Professional—$20/month
- Business plans:
- Teams Standard—$6/user per month
- Teams Unlimited—$15/user per month
- Enterprise—Custom pricing available upon inquiry
Pros and cons
Sync is another E2EE cloud storage with zero-knowledge encryption. Its servers are stored in Canada, so the platform is compliant with the country’s PIPEDA guidelines. This means that Sync can’t disclose any personal data to governments or third parties without the user’s explicit consent.The service is also HIPAA-compliant, which makes it a great option for businesses that need to store sensitive info like health information.Sync’s security extends to link sharing, ensuring safe file transfer. Links are protected by SSL encryption by default, but you can opt for end-to-end link encryption with advanced sharing features available in paid tiers.Besides the lack of end-to-end link encryption, the free plan is quite limited in terms of storage. You only get 5 GB, which isn’t enough even for an average user. You can upgrade to 2 TB with Solo Basic, which might be unnecessary. While the plan is affordable, it would be preferable to have an option between these two storage sizes.Pros | Cons |
High-level privacy | Only 5 GB with the free plan |
HIPAA compliance | E2E link encryption only available to paid users |
Link protection | . |
pCloud
Source: pCloudBased in Switzerland, pCloud offers excellent privacy and security measures. It’s affordable and sufficiently feature-rich for most users, though it reserves some of its main selling points for paid clients.
Pricing
pCloud’s pricing structure isn’t as straightforward as its main competitors’, with varying plans and billing periods for different categories:- Individual plans:
- Premium—$53.49 per year/$212.88 lifetime
- Premium Plus—$106.98 per year/$426.90 lifetime
- Family plans (storage based):
- 2 TB—$636.87 lifetime
- 10 TB—$1604.50 lifetime
- Business plans:
- Business—$10.69 per user per month/$8.55 per month billed annually
- Business Pro—$21.38 per user per month/$17.10 per month billed annually
Pros and cons
Switzerland is known for its strict data protection laws, so it’s no surprise that pCloud comes with numerous security measures. The platform is so confident that it offered a $100,000 reward to anyone who could penetrate its security layers. Thousands of users participated in the challenge that lasted six months, and none of them succeeded.Another standout feature is pCloud’s Linux compatibility. Most platforms stick to the most widely-used platforms (Android, iOS, Windows, macOS), but pCloud went the extra mile to expand its reach.The service is GDPR-compliant, and you can choose whether you want your data stored on U.S. or Luxembourg servers. Your choice can impact the way your data is treated, so Luxembourg might be a safer choice if you want to protect yourself from some invasive U.S. regulations.pCloud offers a free plan, but it doesn’t offer much storage out of the box. You start with only 2 GB and have to unlock the rest by performing different actions suggested by the platform. You can unlock up to 10 GB, which many providers offer without unnecessary steps.A bigger concern is the lack of strong encryption as a standard. Regardless of your chosen plan, you must pay for client-side encryption and zero-knowledge privacy, which costs $53.52 annually or $160.58 for lifetime access. Most services don’t keep such a vital feature behind a separate paywall, so this is certainly a major downside for users on a budget.Pros | Cons |
Strong security | Limited free plan |
GDPR compliance | Client-side encryption and zero-knowledge privacy charged separately, even with paid plans |
Option to choose server location | . |
Tresorit
Source: TresoritTresorit is another Swiss cloud provider offering advanced security, and it’s mainly focused on business users. It’s a decent option for personal use, though the cost might make it unappealing to individual users.
Pricing
Tresorit offers a modest free plan alongside several tiers for individual and business users:- Individual plans:
- Personal—$12.83 per month/$10.69 per month billed annually
- Professional—$32.08 per month/$25.66 per month billed annually
- Business plans:
- Business Standard—$16.05/user per month/$12.84 per month billed annually
- Business Plus—$21.39/user per month/$17.12 per month billed annually
- Enterprise—$26.74/user per month/$21.39 per month billed annually
Pros and cons
Tresorit provides zero-knowledge E2EE to secure user data and offer high levels of privacy. Unlike many of its competitors, it has a well-designed user interface without unnecessary clutter while still being packed with useful features.Robust link sharing is among the most notable features. Every link is end-to-end encrypted, and you can set:- Password protection
- Expiration date
- Open count limits
- Detailed access logs
- Recipient email verification requirements
Pros | Cons |
Zero-knowledge E2EE | Only 3 GB with the free plan |
Robust link security | Pricey paid tiers |
Clear and transparent privacy policy | . |
Skiff Drive
Source: SkiffSkiff Drive is an end-to-end encrypted cloud storage that uses advanced cryptography to keep user data safe from prying eyes or unauthorized access. It offers a generous free plan without placing important features behind a paywall, letting every user enjoy complete privacy and confidentiality.
Pricing
Besides the robust free plan, Skiff offers three paid tiers:- Essential—$4 per month/$3 per month billed annually
- Pro—$10 per month/$8 per month billed annually
- Business—$15/user per month/$12 per month billed annually
Pros and cons
Skiff Drive offers zero-knowledge encryption and provides privacy from the moment you sign up. You don’t need to leave any personal information, and the platform uses the Secure Remote Password algorithm to ensure login credentials aren’t stored on the servers.Files and data are encrypted on the user’s device, so nobody—including Skiff—has access to them. Decryption keys are safely stored on the user’s device, ensuring ultimate data protection.The free plan gets you 10 GB of end-to-end encrypted storage and various features:- Support for all file types
- One-click migration from Google Drive, Dropbox, or other cloud solutions
- Two-factor authentication
- Optional integration with the InterPlanetary File System (IPFS), the largest decentralized storage network
- Compatibility with browsers and macOS, iOS, and Android devices
- Integration with various crypto wallets, such as MetaMask, Coinbase, and Keplr, for achieving complete anonymity when sharing files
- Skiff Mail for sending end-to-end encrypted emails and attachments
- Skiff Pages for easy collaboration and file sharing in a secure environment
- Skiff Calendar for staying organized, scheduling events, and hosting video conferences
Pros | Cons |
Advanced end-to-end encryption with zero-knowledge authentication | Can’t protect the data of a fully compromised device |
Crypto integrations | . |
Additional E2EE platforms for streamlined collaborations | . |
Get started with Skiff Drive in three steps
Securing your files with Skiff Drive is quick and simple. All you have to do is:- Visit the signup page
- Choose your account name and password
- Upload your files to Skiff Drive