Advanced Security Features
File validation, audit trails, and security monitoring

Advanced Security Features
Explore FileSeal's security architecture including file validation, audit trails, and account-level monitoring.
What This Means for Your Practice
Think of FileSeal as having a security team working 24/7 to protect your documents:
- File Validation: Every upload is checked by type and signature, so a renamed executable cannot pose as a document
- Audit Trails: Like CCTV for your documents - you can see exactly who accessed what and when
- Activity Notifications: You're emailed the moment a client uploads documents
- Professional Controls: Like having different security clearance levels for different areas of your building
Bottom line: You get enterprise-level security that normally costs thousands, included automatically with every FileSeal request.
Multi-Layer Security Architecture
Layer 1: Client-Side Protection
File Validation Before Encryption
What this protects you from:
- A client accidentally uploading the wrong file type
- A renamed executable disguised as a document
How it works:
- Type Allow-list: Only PDF, JPG, PNG, DOC, and DOCX are accepted
- Signature Verification: The real file type is confirmed from its header, not its extension
- Size Limits: Oversized uploads are rejected before processing
FileSeal does not run antivirus scanning. Files are encrypted in your browser before they reach our servers, so we never handle or execute their contents; one-time download and automatic deletion keep the exposure window small. Recipients should still open documents with their own up-to-date security software.
File Validation Systems
- File Signature Verification: Prevents file spoofing
- Content Type Validation: Ensures files match extensions
- Size Limit Enforcement: Prevents oversized uploads
- Format Compliance: Validates document structures
Layer 2: Transmission Security
Encryption During Transit
- TLS 1.3: Modern transport security on every connection
- Perfect Forward Secrecy: Each session uses unique keys
- No intermediate decryption: Files are already encrypted client-side, so nothing in transit can read them
Network Security
- DDoS Protection: Automatic attack mitigation (Vercel platform)
- Rate Limiting: Per-IP and per-action throttling to deter abuse
Layer 3: Server-Side Security
Zero-Trust Architecture
- No Plaintext Storage: The server only ever holds ciphertext
- Encrypted at Rest: Stored blobs are encrypted
- Key handling: In zero-knowledge mode the encryption key never reaches the server (it stays in the link fragment); in email mode it is stored separately from the ciphertext
Infrastructure
- SOC 2-certified hosting: Runs on Vercel and Neon, both SOC 2 Type II certified
- Managed platform updates: Security patches applied at the hosting-platform level
How FileSeal Handles Malicious Files
FileSeal does not run antivirus or malware scanning, and its protection model is deliberately different:
- Encryption-first: Files are encrypted in your browser before upload, so FileSeal's servers only ever hold ciphertext they cannot read or execute.
- Validation, not scanning: Uploads are checked by type, size, and file signature, so a renamed executable cannot pose as an accepted document.
- Minimal exposure: One-time download and automatic deletion mean a file exists on our servers only briefly.
Because file contents are never inspected, recipients should always open downloaded documents with their own up-to-date antivirus and treat macros or embedded scripts with normal caution.
Comprehensive Audit Trails - Your Digital CCTV
Why This Matters
Like having a security camera system for your documents - you can prove exactly what happened and when, protecting you from disputes and demonstrating compliance to regulators.
What Gets Recorded (Everything!)
Professional Activities:
- When you create document requests (like recording when you open a safe)
- Email delivery confirmations to clients (proof the invitation was sent)
- Client upload attempts and successes (recording who entered the building and when)
- Your download activities (when you accessed the documents)
- Automatic cleanup and deletion (when the security footage was archived)
Security Events:
- Failed login attempts (recording attempted break-ins)
- Suspicious upload behaviors (unusual activity patterns)
- Uploads blocked for failing validation (wrong type or signature)
- Unauthorised access attempts (failed security breaches)
Real Audit Trail Example
What you see:
15 Jan 2025, 2:30 PM: Document request created for Sarah Client
15 Jan 2025, 2:31 PM: Secure email sent to sarah.client@email.com
15 Jan 2025, 4:45 PM: Client uploaded 3 documents (validated and encrypted) 16 Jan 2025, 9:15 AM: You downloaded documents (1 ZIP file)
16 Jan 2025, 9:16 AM: All documents automatically deleted from servers
Technical details (for compliance): Request ID: req_abc123 | IP: 192.168.1.100 | Browser: Chrome 120.0.0.0 | Security: High
Retention Policies
- Active Requests: Full logging during lifecycle
- Completed Requests: Extended retention for compliance
- Security Events: Long-term security monitoring
- Professional Records: Regulatory compliance periods
Security Monitoring & Alerts
Real-Time Monitoring Dashboard
Professional Security Insights
- Active request security status
- Recent validation and access summary
- Client access patterns analysis
- System security health indicators
Alert Categories
- Immediate Alerts: Critical security events
- Daily Summaries: Regular activity reports
- Weekly Reviews: Trend analysis and insights
- Monthly Reports: Compliance documentation
Automated Security Responses
Threat Response Automation
- Detection: Security threat identified
- Classification: Threat severity assessment
- Response: Automatic protective measures
- Notification: Professional and client alerts
- Documentation: Audit trail creation
Professional Notifications
- Email alerts for critical events
- Dashboard security indicators
- Mobile push notifications (if configured)
- SMS alerts for highest-priority threats
Professional Security Controls
Access Control Management
Authentication Security
- Multi-Factor Authentication: Available for high-security accounts
- Session Management: Automatic timeout protections
- Device Recognition: Trusted device identification
- Geographic Monitoring: Unusual location alerts
Authorisation Controls
- Professional-only access to sensitive features
- Client access limited to specific requests
- Time-based access controls
- IP address restrictions (enterprise feature)
Data Loss Prevention
Upload Restrictions
- File type limitations for security
- Size restrictions prevent abuse
- Content scanning for sensitive data
- Professional approval workflows
Download Protection
- One-time download enforcement
- Time-limited access windows
- Download attempt monitoring
- Unauthorized access prevention
Compliance & Regulatory Support
Professional Standards Compliance
Legal Profession Requirements
- SRA Compliance: Solicitors Regulation Authority
- Law Society Standards: Professional conduct rules
- GDPR Compliance: Data protection regulations
- Client Confidentiality: Professional privilege protection
Financial Services Compliance
- FCA Requirements: Helps meet Financial Conduct Authority obligations
- Payments: Processed by Stripe (PCI DSS Level 1) — FileSeal never handles card data
- SOC 2 Type II: Hosted on SOC 2 Type II-certified infrastructure (Vercel, Neon)
Regulatory Reporting
Compliance Documentation
- Security incident reports
- Data processing records
- Client consent documentation
- Professional obligation compliance
Audit Support
- Complete audit trail provision
- Regulatory inquiry assistance
- Professional standard verification
- Compliance certificate provision
Enterprise Security Features
Advanced Protection Options
Professional Tier Security
- Configurable expiry and access controls
- Extended audit trail retention
- Priority security support
- Custom security configurations
Enterprise Integration
- Single Sign-On (SSO) support
- Active Directory integration
- Custom security policies
- Dedicated security contact
Next Level: Explore GDPR Compliance or learn about Professional Customization.