Security overview

A plain description of what Spaces does and what it does not do. We make no certification claims.

Server-managed encryption, not end-to-end. Files are encrypted in transit (TLS) and at rest using the storage provider's managed keys. Because our servers can read files in order to scan and preview them, this is not zero-knowledge or end-to-end encryption. End-to-end encrypted vaults would need a separate design and are not offered.

Access control

  • Files live in a private bucket under random, opaque names. A file name or path never grants access.
  • Every read, download, move, share and export is checked against your permissions in the database itself (row-level security), not only in the interface.
  • Sign-in uses verified email, optional authenticator-app MFA with single-use recovery codes, and rate-limited attempts with generic error messages.
  • Platform administrators need MFA and can see operational metadata, not your files.

Uploads and scanning

  • Each upload is held in quarantine until a malware scan reports it clean. If the scanner is unavailable the file stays quarantined. We never release unscanned files.
  • File contents are checked against the file extension. Executables, scripts and active content such as HTML and SVG are refused.
  • Size limits and storage quotas are enforced on the server when the upload is reserved and again when it finishes.

Sharing links

  • Links contain a 256-bit random secret. We store only a hash of it, so we cannot show you an existing link again. You can rotate it to get a new one.
  • Passwords are stored with scrypt. A wrong-password limit protects each link.
  • Download links are short-lived (up to 60 seconds). Revoking a link stops new downloads immediately, but a download link already issued can still be used until it expires, and a transfer already in progress can finish. A download limit counts authorisations issued, not confirmed saves.
  • Once someone has downloaded a file, we cannot take back their copy.

Retention and deletion

  • Access ends at the exact expiry time, independent of background jobs. Physical deletion normally follows within 24 hours.
  • Trash and old versions count toward your storage until they are physically removed.
  • We do not keep separate backups of file contents in the initial deployment. Database backups are encrypted by the database provider.

Where data is processed

Deployment in a UK region is preferred, but each provider's actual data location and terms must be checked; we do not claim UK-only residency. Providers used: hosting (Vercel), database, authentication and file storage (Supabase), payments (Stripe), email delivery (Brevo) and malware scanning (self-hosted ClamAV).

Report a problem

Found a vulnerability? Write to the address in security.txt. Please give us reasonable time to fix it before disclosing it.