Security posture
· Authored by the My All Files product team
Transport & access
HTTPS/TLS on the public edge, token authentication for the API, and user-scoped file queries so tenants only see their own documents.
Application controls
Security headers (HSTS, CSP, nosniff), rate limits, soft-delete trash, PDF password encryption option, and append-only audit events with hash chaining.
Privacy tools
GDPR-style data export (metadata) and hard-delete flows in the Privacy tab. Share links use opaque tokens; app routes are noindex.
Note: HIPAA / SOC 2 Type 2 are organizational certifications, not automatic product claims. Contact support@myallfiles.com for enterprise posture questions.