PreviewFile IconPreviewFile.dev

Security & Privacy

Learn how PreviewFile.dev protects your users' files with comprehensive security features

Security & Privacy

PreviewFile.dev is built from the ground up to protect your users' files. Every feature is designed with security and privacy in mind.

Core Security Features

🔒 Dynamic Watermarks

Add custom text watermarks to protect sensitive documents and deter unauthorized sharing.

  • Custom text: Add company names, confidentiality notices, or user identifiers
  • Position control: Overlay watermarks across the document
  • Non-removable: Watermarks are rendered during preview, not stored in files
  • Use cases: Legal documents, contracts, confidential reports

⏱️ Time-Limited Access (TTL)

Set expiration times to ensure links don't remain accessible indefinitely.

  • Flexible duration: From 15 minutes to 7 days (plan limits apply)
  • Automatic expiration: Links become inaccessible after TTL expires
  • No manual cleanup: Server automatically handles expired sessions
  • Use cases: Temporary document sharing, time-sensitive files

🚫 Download Protection

Prevent viewers from downloading files while still allowing preview access.

  • Preview-only mode: Users can view but not save files locally
  • Right-click disabled: Prevents easy download attempts
  • DevTools protection: Additional layers to prevent technical workarounds
  • Use cases: Sensitive PDFs, confidential presentations, proprietary documents

🔥 One-Time Access (Burn After Reading)

Create links that self-destruct after a single view.

  • Single-use links: Automatically expire after first access
  • View tracking: System records when link was accessed
  • Perfect forward secrecy: Once viewed, the link cannot be reused
  • Use cases: Highly confidential documents, password resets, temporary credentials

🔐 Password Protection

Secure your files with password-based access control.

  • Optional passwords: Add an extra layer of security to any file
  • Bcrypt hashing: Passwords are never stored in plain text (10 rounds)
  • URL parameter support: Share password separately or include in URL
  • Session caching: Browser remembers verification during active session
  • Use cases: Client deliverables, confidential reports, secure file sharing

Prevent unauthorized embedding and bandwidth theft.

  • Referrer validation: Only allow access from approved domains
  • IP/User-Agent binding: Tie sessions to specific clients
  • CloudFront signed URLs: Cryptographically secure access tokens
  • Use cases: Protecting CDN bandwidth, controlling distribution

Privacy by Design

Client-Side Rendering

  • No data retention: File contents are not stored beyond temporary links
  • Bandwidth efficient: Direct client-to-storage connections where possible
  • Server Conversion: Due to technical limitations, doc/office files require server-side conversion

Minimal Data Collection

We only collect what's necessary to provide the service.

  • File metadata only: Filename, size, MIME type, expiration time
  • No content scanning: File contents are never analyzed or indexed
  • Optional user data: Authentication is optional for basic usage
  • Audit logs: Access logs are retained only as long as needed for security

Secure Storage Integration

Files are stored in industry-standard S3-compatible storage.

  • Encryption at rest: S3 server-side encryption (SSE-S3)
  • Encryption in transit: HTTPS/TLS for all connections
  • Private buckets: Storage is not publicly accessible
  • Signed URLs: Time-limited, cryptographically signed access tokens

Compliance & Best Practices

Data Residency

  • Multi-region support: Choose storage region closest to your users
  • Private deployment: Self-host for complete data control
  • GDPR considerations: Minimal PII collection, data deletion on request

Access Control

  • User authentication: Optional Clerk-based authentication
  • API key management: Secure token-based API access
  • Rate limiting: Protect against abuse and DDoS

Security Headers

  • Content Security Policy (CSP): Prevent XSS attacks
  • X-Frame-Options: Prevent clickjacking
  • Strict-Transport-Security: Enforce HTTPS

For Developers

API Security

// All API requests require authentication
const response = await fetch('https://previewfile.dev/api/u', {
  method: 'POST',
  headers: {
    'Authorization': `Bearer ${API_KEY}`,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    url: 'https://example.com/confidential.pdf',
    ttlMinutes: 60,
    watermark: 'CONFIDENTIAL - Internal Use Only',
    noDownload: true,
    oneTime: false,
    password: 'secure-password-123',  // Optional password protection
  }),
});

Password Protection Examples

// Share URL with password as query parameter
const previewUrl = 'https://previewfile.dev/p/abc123?pwd=mypassword';

// Or share separately for better security
const link = 'https://previewfile.dev/p/abc123';
const password = 'mypassword';  // Share via different channel

// Access from code with password
const fileData = await fetch('/api/preview/abc123', {
  headers: {
    'Authorization': `Bearer mypassword`
  }
});

Security Configuration Example

// Create a highly secure preview link
const securePreview = await trpc.preview.create.mutate({
  file: uploadedFile,
  ttlMinutes: 30,                    // Expire in 30 minutes
  watermark: `${user.email} - ${new Date().toISOString()}`,  // User + timestamp watermark
  noDownload: true,                   // Prevent downloads
  oneTime: true,                      // Single-use link
  password: 'temp-secure-pass',      // Require password for access
});

// Share the link and password via different channels
console.log('Link:', securePreview.previewUrl);
console.log('Password:', 'temp-secure-pass');  // Send via SMS/email separately

Threat Model

PreviewFile.dev protects against:

  • ✅ Unauthorized distribution: TTL and one-time links prevent uncontrolled sharing
  • ✅ Data theft: Download protection and watermarks deter copying
  • ✅ Hotlinking/bandwidth theft: Referrer validation and signed URLs
  • ✅ XSS/Injection attacks: Strict CSP and input validation

Next Steps

  • Explore the API Documentation to implement security features
  • Check Pricing for enterprise security options
  • Contact us for security questionnaires or compliance documentation

On this page