Advanced Security Features

Security & Compliance

File validation, audit trails, and security monitoring

12 min read
Intermediate
Updated 3 September 2025
Back to Guides
Advanced Security Features

Advanced Security Features

Explore FileSeal's security architecture including file validation, audit trails, and account-level monitoring.

What This Means for Your Practice

Think of FileSeal as having a security team working 24/7 to protect your documents:

  • File Validation: Every upload is checked by type and signature, so a renamed executable cannot pose as a document
  • Audit Trails: Like CCTV for your documents - you can see exactly who accessed what and when
  • Activity Notifications: You're emailed the moment a client uploads documents
  • Professional Controls: Like having different security clearance levels for different areas of your building

Bottom line: You get enterprise-level security that normally costs thousands, included automatically with every FileSeal request.

Multi-Layer Security Architecture

Layer 1: Client-Side Protection

File Validation Before Encryption

What this protects you from:

  • A client accidentally uploading the wrong file type
  • A renamed executable disguised as a document

How it works:

  • Type Allow-list: Only PDF, JPG, PNG, DOC, and DOCX are accepted
  • Signature Verification: The real file type is confirmed from its header, not its extension
  • Size Limits: Oversized uploads are rejected before processing

FileSeal does not run antivirus scanning. Files are encrypted in your browser before they reach our servers, so we never handle or execute their contents; one-time download and automatic deletion keep the exposure window small. Recipients should still open documents with their own up-to-date security software.

File Validation Systems

  • File Signature Verification: Prevents file spoofing
  • Content Type Validation: Ensures files match extensions
  • Size Limit Enforcement: Prevents oversized uploads
  • Format Compliance: Validates document structures

Layer 2: Transmission Security

Encryption During Transit

  • TLS 1.3: Modern transport security on every connection
  • Perfect Forward Secrecy: Each session uses unique keys
  • No intermediate decryption: Files are already encrypted client-side, so nothing in transit can read them

Network Security

  • DDoS Protection: Automatic attack mitigation (Vercel platform)
  • Rate Limiting: Per-IP and per-action throttling to deter abuse

Layer 3: Server-Side Security

Zero-Trust Architecture

  • No Plaintext Storage: The server only ever holds ciphertext
  • Encrypted at Rest: Stored blobs are encrypted
  • Key handling: In zero-knowledge mode the encryption key never reaches the server (it stays in the link fragment); in email mode it is stored separately from the ciphertext

Infrastructure

  • SOC 2-certified hosting: Runs on Vercel and Neon, both SOC 2 Type II certified
  • Managed platform updates: Security patches applied at the hosting-platform level

How FileSeal Handles Malicious Files

FileSeal does not run antivirus or malware scanning, and its protection model is deliberately different:

  • Encryption-first: Files are encrypted in your browser before upload, so FileSeal's servers only ever hold ciphertext they cannot read or execute.
  • Validation, not scanning: Uploads are checked by type, size, and file signature, so a renamed executable cannot pose as an accepted document.
  • Minimal exposure: One-time download and automatic deletion mean a file exists on our servers only briefly.

Because file contents are never inspected, recipients should always open downloaded documents with their own up-to-date antivirus and treat macros or embedded scripts with normal caution.

Comprehensive Audit Trails - Your Digital CCTV

Why This Matters

Like having a security camera system for your documents - you can prove exactly what happened and when, protecting you from disputes and demonstrating compliance to regulators.

What Gets Recorded (Everything!)

Professional Activities:

  • When you create document requests (like recording when you open a safe)
  • Email delivery confirmations to clients (proof the invitation was sent)
  • Client upload attempts and successes (recording who entered the building and when)
  • Your download activities (when you accessed the documents)
  • Automatic cleanup and deletion (when the security footage was archived)

Security Events:

  • Failed login attempts (recording attempted break-ins)
  • Suspicious upload behaviors (unusual activity patterns)
  • Uploads blocked for failing validation (wrong type or signature)
  • Unauthorised access attempts (failed security breaches)

Real Audit Trail Example

What you see:

15 Jan 2025, 2:30 PM: Document request created for Sarah Client
15 Jan 2025, 2:31 PM: Secure email sent to sarah.client@email.com
15 Jan 2025, 4:45 PM: Client uploaded 3 documents (validated and encrypted) 16 Jan 2025, 9:15 AM: You downloaded documents (1 ZIP file)
16 Jan 2025, 9:16 AM: All documents automatically deleted from servers

Technical details (for compliance): Request ID: req_abc123 | IP: 192.168.1.100 | Browser: Chrome 120.0.0.0 | Security: High

Retention Policies

  • Active Requests: Full logging during lifecycle
  • Completed Requests: Extended retention for compliance
  • Security Events: Long-term security monitoring
  • Professional Records: Regulatory compliance periods

Security Monitoring & Alerts

Real-Time Monitoring Dashboard

Professional Security Insights

  • Active request security status
  • Recent validation and access summary
  • Client access patterns analysis
  • System security health indicators

Alert Categories

  • Immediate Alerts: Critical security events
  • Daily Summaries: Regular activity reports
  • Weekly Reviews: Trend analysis and insights
  • Monthly Reports: Compliance documentation

Automated Security Responses

Threat Response Automation

  1. Detection: Security threat identified
  2. Classification: Threat severity assessment
  3. Response: Automatic protective measures
  4. Notification: Professional and client alerts
  5. Documentation: Audit trail creation

Professional Notifications

  • Email alerts for critical events
  • Dashboard security indicators
  • Mobile push notifications (if configured)
  • SMS alerts for highest-priority threats

Professional Security Controls

Access Control Management

Authentication Security

  • Multi-Factor Authentication: Available for high-security accounts
  • Session Management: Automatic timeout protections
  • Device Recognition: Trusted device identification
  • Geographic Monitoring: Unusual location alerts

Authorisation Controls

  • Professional-only access to sensitive features
  • Client access limited to specific requests
  • Time-based access controls
  • IP address restrictions (enterprise feature)

Data Loss Prevention

Upload Restrictions

  • File type limitations for security
  • Size restrictions prevent abuse
  • Content scanning for sensitive data
  • Professional approval workflows

Download Protection

  • One-time download enforcement
  • Time-limited access windows
  • Download attempt monitoring
  • Unauthorized access prevention

Compliance & Regulatory Support

Professional Standards Compliance

Legal Profession Requirements

  • SRA Compliance: Solicitors Regulation Authority
  • Law Society Standards: Professional conduct rules
  • GDPR Compliance: Data protection regulations
  • Client Confidentiality: Professional privilege protection

Financial Services Compliance

  • FCA Requirements: Helps meet Financial Conduct Authority obligations
  • Payments: Processed by Stripe (PCI DSS Level 1) — FileSeal never handles card data
  • SOC 2 Type II: Hosted on SOC 2 Type II-certified infrastructure (Vercel, Neon)

Regulatory Reporting

Compliance Documentation

  • Security incident reports
  • Data processing records
  • Client consent documentation
  • Professional obligation compliance

Audit Support

  • Complete audit trail provision
  • Regulatory inquiry assistance
  • Professional standard verification
  • Compliance certificate provision

Enterprise Security Features

Advanced Protection Options

Professional Tier Security

  • Configurable expiry and access controls
  • Extended audit trail retention
  • Priority security support
  • Custom security configurations

Enterprise Integration

  • Single Sign-On (SSO) support
  • Active Directory integration
  • Custom security policies
  • Dedicated security contact

Next Level: Explore GDPR Compliance or learn about Professional Customization.

Guide Stats

12 min read
Intermediate Level
Visual Guide
Need More Help?

Can't find what you're looking for in this guide?

Contact Support →