Skip to content

Security

How SteadyLink checks every upload, controls who can open a file, protects stored bytes, and records what happens in your workspace.

On this page

Security in SteadyLink is part of the normal file workflow rather than a separate product. Every upload is checked before it can be delivered, every file is public or private by an explicit rule, and changes in a workspace are recorded. This page summarizes those protections for workspace admins and for anyone reviewing SteadyLink for their organization, and links to the detail.

Upload policies#

A bucket can restrict what it accepts:

  • Maximum upload size, in MB, on top of your plan's file size limit.
  • Allowed MIME type prefixes, such as image/ or application/pdf.
  • Allowed filename extensions, such as pdf or png.

SteadyLink detects a file's real type from its bytes and compares the detected type, not the filename or the type the uploader claimed, with the bucket's rules. A file whose declared type contradicts its contents is rejected as a MIME mismatch. A file that breaks a policy is blocked: no revision is created, nothing is delivered, its temporary bytes are deleted, and the attempt is recorded. See Upload lifecycle.

Malware scanning and clean delivery#

Every revision is scanned with ClamAV after it is stored. Until the result is in, delivery refuses to serve the revision and answers 423 Locked. A revision found to contain malware is marked infected and is never delivered, cannot be restored, and is removed from the file's current position. Workspace settings show this as Require a clean scan before delivery under Settings > Workspace > Defaults for new files.

Scans are sized for the file: larger files get longer to scan, and a scan that cannot finish is retried rather than treated as clean.

Delivery hardening#

Some file types can run code in a browser. SteadyLink limits that by default:

  • HTML and SVG files are delivered as downloads (Content-Disposition: attachment) instead of being rendered on the delivery domain.
  • Responses tell browsers not to guess a different content type than the one SteadyLink detected.

Public, private, and signed access#

Each file is public or private, either explicitly or by inheriting its bucket's default. New workspaces start with private as the default for new files. A private file opens only with a valid signed link, which expires and can be revoked. See Private links.

Encryption#

Stored files are encrypted at rest by the storage platform. Workspaces can also turn on Encrypt original files in Settings > Security. With it on, SteadyLink encrypts each new revision with the workspace's own AES-256-GCM data key before storing it, and decrypts it inside the service for delivery and conversions. The setting applies to revisions uploaded after it is turned on; existing revisions are not re-encrypted. Turning it off affects only new uploads, and encrypted revisions stay readable.

Accounts and access#

  • Two-step verification protects each person's sign-in with an authenticator app and one-time recovery codes. See Two-step verification.
  • Roles limit what each member can do. See Workspaces and roles.
  • Scoped API keys give integrations only the access they need, can expire, and can be revoked at once. See API key safety.
  • Single sign-on lets Business and Enterprise workspaces require sign-in through their identity provider. See Single sign-on.
  • Signed-in browsers are listed in Settings > Security, where you can sign out any session other than the current one.

Audit history#

SteadyLink records security-relevant actions with the workspace, the acting user when there is one, and the time: uploads and replacements, policy blocks and malware detections, visibility changes, revision restores and deletions, signed-link creation, API key creation and revocation, member and role changes, and sign-in events such as two-step verification changes. Recent workspace activity is available from GET /api/analytics/activity.

Storage totals and workspace defaults#

Storage counts every retained revision plus space reserved for uploads in progress, so deleting old revisions is how you reclaim space. Admins set the workspace defaults for new files (public or private, and clean-scan delivery) in Settings > Workspace. See Usage and limits.

In this section#

Next steps#