Document security and the activity log
How uploads are stored, served and audited.
Last updated August 3, 2026
Storage
Documents live in private storage. There is no public URL. Files are stored under randomized paths so a path cannot be guessed from a company or user identifier.
Access
Every download is served through a short-lived signed link generated only after your permission to that specific document is checked server-side. Links expire in minutes, not days.
Auditing
Views and downloads are recorded in the room activity log with the actor, the document and the timestamp. Founders can see exactly which materials each participant opened.
What we cannot control
Once a permitted user downloads a file, the copy is theirs. Restrict per-document access for anything you would not want redistributed, and stage sensitive material later in the process.
Was this article helpful?