Security & data protection

Your designs are protected at every step

Encryption, verified access, complete audit logging, and instant revocation are built into how every file is handled. Here is exactly what protects your data.

How we protect your files

Every file, protected at every step

Encrypted in transit and at rest

Every file is served over TLS and stored encrypted at rest with AES-256. Files are never written to disk unencrypted.

Private storage, no public links

Design files live in private object storage with randomized, unguessable paths. There are no public URLs — every request is streamed through our own authorization gate.

Verified recipient identity

Before any file is shown, the recipient must prove control of their email with a one-time code. Guessing a link is not enough to see your data.

Least-privilege access

Recipients can only reach the specific order shared with them. Your staff can only see files belonging to your own organization — enforced on every single request.

Your workspace stays yours

Files live inside your organization's private workspace. No other customer can reach them, and our own team does not browse or open your documents.

Your own access log

Every time a file is opened, the who, when, and device is captured in your order's activity log — a record that belongs to your organization and is visible only to your team.

Instant revocation & expiry

Cut off access to any recipient immediately, and every share link expires automatically. Superseded revisions invalidate their old links so stale files can't be opened.

Controls checklist

The protections you expect from a file-sharing tool

  • Encryption in transit (TLS)
    Included
  • Encryption at rest (AES-256)
    Included
  • Private, non-public file access
    Included
  • Identity verification before access
    Email one-time code
  • Per-recipient access control
    Included
  • Full access & activity audit log
    Included
  • Instant revocation of access
    Included
  • Automatic link expiry
    Included

How your data is handled

Protected by design, not by policy alone

Technical safeguards

Files are transmitted over TLS and stored encrypted at rest with AES-256 in private storage with randomized, unguessable paths. Every request is authorized server-side before a byte is served, and access is scoped to a single order and verified recipient. Each retrieval is recorded in your organization's own activity log — a record only your team can see. Our operations team does not browse or open the documents you store.

Straight talk on certifications: OrderApproval is not independently certified yet, and we will never claim otherwise. If your procurement team needs a security questionnaire completed or documentation of these controls, we are glad to provide it.

Need to complete a security review?

We are happy to walk your IT or procurement team through our controls and complete a vendor security questionnaire before you send a single file.