Security & Privacy
Learn how PreviewFile.dev protects your users' files with comprehensive security features
Security & Privacy
PreviewFile.dev is built from the ground up to protect your users' files. Every feature is designed with security and privacy in mind.
Core Security Features
🔒 Dynamic Watermarks
Add custom text watermarks to protect sensitive documents and deter unauthorized sharing.
- Custom text: Add company names, confidentiality notices, or user identifiers
- Position control: Overlay watermarks across the document
- Non-removable: Watermarks are rendered during preview, not stored in files
- Use cases: Legal documents, contracts, confidential reports
⏱️ Time-Limited Access (TTL)
Set expiration times to ensure links don't remain accessible indefinitely.
- Flexible duration: From 15 minutes to 7 days (plan limits apply)
- Automatic expiration: Links become inaccessible after TTL expires
- No manual cleanup: Server automatically handles expired sessions
- Use cases: Temporary document sharing, time-sensitive files
🚫 Download Protection
Prevent viewers from downloading files while still allowing preview access.
- Preview-only mode: Users can view but not save files locally
- Right-click disabled: Prevents easy download attempts
- DevTools protection: Additional layers to prevent technical workarounds
- Use cases: Sensitive PDFs, confidential presentations, proprietary documents
🔥 One-Time Access (Burn After Reading)
Create links that self-destruct after a single view.
- Single-use links: Automatically expire after first access
- View tracking: System records when link was accessed
- Perfect forward secrecy: Once viewed, the link cannot be reused
- Use cases: Highly confidential documents, password resets, temporary credentials
🔐 Password Protection
Secure your files with password-based access control.
- Optional passwords: Add an extra layer of security to any file
- Bcrypt hashing: Passwords are never stored in plain text (10 rounds)
- URL parameter support: Share password separately or include in URL
- Session caching: Browser remembers verification during active session
- Use cases: Client deliverables, confidential reports, secure file sharing
🔗 Hotlink Protection
Prevent unauthorized embedding and bandwidth theft.
- Referrer validation: Only allow access from approved domains
- IP/User-Agent binding: Tie sessions to specific clients
- CloudFront signed URLs: Cryptographically secure access tokens
- Use cases: Protecting CDN bandwidth, controlling distribution
Privacy by Design
Client-Side Rendering
- No data retention: File contents are not stored beyond temporary links
- Bandwidth efficient: Direct client-to-storage connections where possible
- Server Conversion: Due to technical limitations, doc/office files require server-side conversion
Minimal Data Collection
We only collect what's necessary to provide the service.
- File metadata only: Filename, size, MIME type, expiration time
- No content scanning: File contents are never analyzed or indexed
- Optional user data: Authentication is optional for basic usage
- Audit logs: Access logs are retained only as long as needed for security
Secure Storage Integration
Files are stored in industry-standard S3-compatible storage.
- Encryption at rest: S3 server-side encryption (SSE-S3)
- Encryption in transit: HTTPS/TLS for all connections
- Private buckets: Storage is not publicly accessible
- Signed URLs: Time-limited, cryptographically signed access tokens
Compliance & Best Practices
Data Residency
- Multi-region support: Choose storage region closest to your users
- Private deployment: Self-host for complete data control
- GDPR considerations: Minimal PII collection, data deletion on request
Access Control
- User authentication: Optional Clerk-based authentication
- API key management: Secure token-based API access
- Rate limiting: Protect against abuse and DDoS
Security Headers
- Content Security Policy (CSP): Prevent XSS attacks
- X-Frame-Options: Prevent clickjacking
- Strict-Transport-Security: Enforce HTTPS
For Developers
API Security
// All API requests require authentication
const response = await fetch('https://previewfile.dev/api/u', {
method: 'POST',
headers: {
'Authorization': `Bearer ${API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
url: 'https://example.com/confidential.pdf',
ttlMinutes: 60,
watermark: 'CONFIDENTIAL - Internal Use Only',
noDownload: true,
oneTime: false,
password: 'secure-password-123', // Optional password protection
}),
});Password Protection Examples
// Share URL with password as query parameter
const previewUrl = 'https://previewfile.dev/p/abc123?pwd=mypassword';
// Or share separately for better security
const link = 'https://previewfile.dev/p/abc123';
const password = 'mypassword'; // Share via different channel
// Access from code with password
const fileData = await fetch('/api/preview/abc123', {
headers: {
'Authorization': `Bearer mypassword`
}
});Security Configuration Example
// Create a highly secure preview link
const securePreview = await trpc.preview.create.mutate({
file: uploadedFile,
ttlMinutes: 30, // Expire in 30 minutes
watermark: `${user.email} - ${new Date().toISOString()}`, // User + timestamp watermark
noDownload: true, // Prevent downloads
oneTime: true, // Single-use link
password: 'temp-secure-pass', // Require password for access
});
// Share the link and password via different channels
console.log('Link:', securePreview.previewUrl);
console.log('Password:', 'temp-secure-pass'); // Send via SMS/email separatelyThreat Model
PreviewFile.dev protects against:
- ✅ Unauthorized distribution: TTL and one-time links prevent uncontrolled sharing
- ✅ Data theft: Download protection and watermarks deter copying
- ✅ Hotlinking/bandwidth theft: Referrer validation and signed URLs
- ✅ XSS/Injection attacks: Strict CSP and input validation
Next Steps
- Explore the API Documentation to implement security features
- Check Pricing for enterprise security options
- Contact us for security questionnaires or compliance documentation