Implemented controls
The service uses third-party authentication, server-side workspace and project authorization, role checks, trusted-origin controls for sensitive actions, private object storage, scoped file delivery, public-link expiry and revocation, signed provider webhooks, idempotent billing records, secret separation, and operational event logging.
Shared responsibility
Customers must protect sign-in accounts, manage members and recipients, remove former collaborators, avoid exposing public links, retain source backups, and report suspicious activity promptly. A public link is a bearer credential within its allowed scope.
Reporting a vulnerability
Send security reports to [email protected] with reproduction steps, affected URLs, impact, and a safe proof of concept. Do not access customer data, disrupt service, use social engineering, or publicly disclose an unresolved issue. AssetsFlow currently has no public bug bounty and makes no promise of payment or a fixed response SLA.