Trust & Security

How we protect your client files

Last reviewed 2026-09-15

BulkShare handles client deliverables for agencies, studios, and freelancers. Security isn't optional — it's foundational. Files travel over HTTPS, rest under AES-256 on Cloudflare R2 storage, and expire on your terms. Here's what's in place today, in plain language.

What every file gets, automatically

HTTPS in transit
BulkShare serves its production app over HTTPS and sends an HSTS header. The TLS version is negotiated by your browser and the hosting infrastructure.
AES-256 at rest
Cloudflare R2 automatically encrypts stored objects with AES-256 using provider-managed keys. This is not end-to-end encryption.
Isolated storage per user
Each user's files live under a unique namespaced prefix. Access gated by authenticated server actions that verify session ownership.
Cloudflare + Vercel infrastructure
The app runs on Vercel and primary file storage uses Cloudflare R2. These providers publish their own security documentation; their certifications do not extend automatically to BulkShare.

What you control on every shared link

Password-protected links
Pro can require a password before any file is accessible. Applied to every file in the delivery.
Configurable link expiry
Set custom expiry windows so client access auto-revokes after the delivery window. No manual cleanup.
24-hour anonymous expiry
Anonymous download access expires after 24 hours. Expired uploads are removed by scheduled cleanup.
Download visibility
See recorded link views and download requests for follow-ups. Activity is not proof that a person read a file or completed a download.

Minimal data, predictable handling

Minimal data collection
Only what's needed to operate: email for auth, uploaded files for delivery, basic analytics for link activity. We don't sell data or share with ad networks.
Soft delete + permanent removal
Dashboard files move to trash before permanent removal. Permanent deletion removes the stored object; it cannot remove copies recipients have already downloaded.
Data deletion requests
Delete your account and all data anytime. For full GDPR deletion requests, contact us — we process promptly.
Service delivery and safety checks
Storage providers process files to deliver the service. Automated safety checks may inspect uploads, including anonymous files. See our privacy policy for data-handling details.

HTTP security headers

Configured at the edge, on every response.

HeaderPurpose
Strict-Transport-SecurityForces HTTPS, prevents downgrade
Content-Security-PolicyRestricts which scripts and resources can load
X-Content-Type-OptionsPrevents MIME-type sniffing
X-Frame-OptionsPrevents clickjacking via iframes
Referrer-PolicyControls referrer information sent to external sites

Compliance status

Current controls and limits. For storage encryption details, see Cloudflare R2's security documentation.

In place

  • HTTPS + HSTS
  • R2 encryption at rest
  • Link access controls
  • Download-link expiry

Discuss before use

  • Data-processing terms
  • Data residency needs
  • Regulated client files

Not claimed

  • BulkShare SOC 2
  • Independent security audit
  • End-to-end encryption

Common questions

Files stored on Cloudflare R2 use automatic AES-256 encryption at rest. BulkShare uses HTTPS for transfers. This is server-side encryption, not end-to-end encryption.