Security and privacy
Protecting your data and respecting your privacy
We use the most advanced security and privacy measures and tools to protect your information and put you in control of your data.
The highest level of online security and privacy
We use zero-knowledge encryption, also known as user-controlled end-to-end encryption, to protect your data online, even when sharing. This means that only you and those you share information with have the keys to see, read, or listen to that data on MEGA. For anyone else, including MEGA, the data would appear as gibberish, and they would find it impossible to read or understand.
Learn morePrivacy first
We believe that everyone should be able to store data and communicate securely and privately online.
That’s why we follow the European Union’s General Data Protection Regulation (GDPR)—the strongest privacy and security law in the world. All the GDPR protections and rights apply to all our users, wherever they may live.
Mega’s Terms of Service, Privacy and Data Policy, Takedown Guidance Policy and Contact Details provide all the disclosures and explanations required by the GDPR.
You control everything with your password
All your data on MEGA is encrypted with keys generated from your password. It’s your main encryption key. What makes this so secure is that no one has access to your password apart from you — not even us.
Some cloud storage providers hold the decryption keys, but with MEGA, you control the encryption. You hold the keys and you decide who can, and how they can, access your files.
Restore access to your account with a recovery key
Your recovery key further protects your account from cyber attacks.
Our no compromise approach to security means we can neither send you password reset links nor do anything on our end to let you in if you forget your password. The only way to regain access to your MEGA account is with your recovery key. No key, no access — so make sure you keep your recovery key somewhere safe.
Every item on MEGA has a unique decryption key. When you share a link, by default the decryption key is sent along with it. But for added security, you can also choose to export and send the decryption key separately. The person who receives the link needs to enter the key before they can open it. Learn more.
Set full, read and write, or read-only permissions to control how you’d like your contacts to access your shared folders.
You can create password-protected links to your shared files and folders stored on MEGA. Available for Pro and Business users.
You can make your shared data available for a limited time by putting an expiry date on shared links. Find out more information about sharing data on MEGA. Available for Pro and Business users.
Get an extra layer of security with 2FA
We support two-factor authentication (2FA) as an added layer of protection to your MEGA account. Once 2FA is enabled, whenever you log in or make changes to your account you will need to enter a 6-digit code from your authenticator app.
Learn moreRecover from ransomware attacks
Alongside our always-on security features, our robust file versioning and recovery features protect your data from ransomware attacks. In case of a ransomware infection, you may still be able to retrieve older versions of your files that have not yet been encrypted by the malware.
Learn moreFull transparency
Design and security processes
We publish MEGA’s design and security processes in a whitepaper. View whitepaper.
Source code
We make the complete source code for our client apps available to the public. This allows interested parties to independently examine the code for security, integrity, and correctness. View source code.
Help and support
Find answers to frequently asked questions in our Help Centre.
Passwords
Find out how to create secure passwords and why you should use a password manager.
Two-factor authentication (2FA)
Find out why we support 2FA and why you should enable it.