Built so your work stays yours
Security is not a page we wrote once. It is the shape of the product: private storage, database-enforced permissions, revocable links and keys, and no data resale — ever.
Encrypted end to end of the pipe
Every byte travels over TLS 1.3 and is written to encrypted storage at rest. Nothing is served from an unencrypted origin.
Row-level access control
Your files, chats, keys and receipts are locked to your account at the database layer, not just in the interface. A leaked link cannot read another account's rows.
Private by default
New uploads land in a private bucket. A file becomes reachable only when you explicitly create a share link, and you can revoke it instantly.
Hardened partner API
Partner requests are authenticated with a key id plus a hashed secret and a short-lived authorization code, scoped per key and rate limited per plan.
Auditable activity
Key usage, API requests, payments and account changes are logged so you can see exactly what happened and when.
Email privacy
We never expose one user's email address to another. Where an address must be shown it is masked, and administrator addresses are never displayed at all.
Account protection
What you control from inside your account.
- Strong password enforcement with breached-password checking
- Password reset links that expire and can only be used once
- Sign in with Google, or email and password — your choice
- Share links with expiry dates and optional passwords
- One-click revocation for any share link or API key
- Full export and permanent deletion of your data on request
Responsible disclosure
Found something? Tell us first.
Read how we handle personal data in the Privacy Policy.