TrustedDrop Security Overview
Version: 1.0
Effective Date: July 6, 2026
1. Purpose
This Security Overview describes general security practices used by TrustedDrop. It is informational and does not create a warranty or guarantee.
2. Secure Transfer Design
The service is designed for limited-use file exchange, not permanent storage. Files may be subject to expiration, one-time download behavior, and automatic deletion.
3. Transport Security
The service should be accessed using HTTPS to protect data in transit between the user’s browser and the service.
4. Access Control
Access to uploaded files is controlled through secure transfer links, optional passwords or passphrases, expiration settings, and administrative controls.
5. Logging
The service logs limited metadata needed for security, abuse prevention, troubleshooting, legal compliance, and auditability. The service should not log passwords, encryption keys, or unnecessary file content.
6. Deletion
Files may be deleted after successful download, expiration, administrative action, or maintenance. Backup and cache behavior may vary depending on system configuration.
7. User Responsibilities
Users are responsible for sending links only to intended recipients, protecting passwords or passphrases, verifying recipient identity, and ensuring they have authority to share the uploaded files.
8. No Absolute Guarantee
No file transfer system can guarantee absolute confidentiality, availability, or integrity. Users should not use the service where a higher contractual, regulatory, or technical control is required unless separately agreed in writing.