Trust & Security
How we protect your client files
Last reviewed 2026-09-15
BulkShare handles client deliverables for agencies, studios, and freelancers. Security isn't optional — it's foundational. Files travel over HTTPS, rest under AES-256 on Cloudflare R2 storage, and expire on your terms. Here's what's in place today, in plain language.
What every file gets, automatically
- HTTPS in transit
- BulkShare serves its production app over HTTPS and sends an HSTS header. The TLS version is negotiated by your browser and the hosting infrastructure.
- AES-256 at rest
- Cloudflare R2 automatically encrypts stored objects with AES-256 using provider-managed keys. This is not end-to-end encryption.
- Isolated storage per user
- Each user's files live under a unique namespaced prefix. Access gated by authenticated server actions that verify session ownership.
- Cloudflare + Vercel infrastructure
- The app runs on Vercel and primary file storage uses Cloudflare R2. These providers publish their own security documentation; their certifications do not extend automatically to BulkShare.
What you control on every shared link
- Password-protected links
- Pro can require a password before any file is accessible. Applied to every file in the delivery.
- Configurable link expiry
- Set custom expiry windows so client access auto-revokes after the delivery window. No manual cleanup.
- 24-hour anonymous expiry
- Anonymous download access expires after 24 hours. Expired uploads are removed by scheduled cleanup.
- Download visibility
- See recorded link views and download requests for follow-ups. Activity is not proof that a person read a file or completed a download.
Minimal data, predictable handling
- Minimal data collection
- Only what's needed to operate: email for auth, uploaded files for delivery, basic analytics for link activity. We don't sell data or share with ad networks.
- Soft delete + permanent removal
- Dashboard files move to trash before permanent removal. Permanent deletion removes the stored object; it cannot remove copies recipients have already downloaded.
- Data deletion requests
- Delete your account and all data anytime. For full GDPR deletion requests, contact us — we process promptly.
- Service delivery and safety checks
- Storage providers process files to deliver the service. Automated safety checks may inspect uploads, including anonymous files. See our privacy policy for data-handling details.
HTTP security headers
Configured at the edge, on every response.
| Header | Purpose |
|---|---|
| Strict-Transport-Security | Forces HTTPS, prevents downgrade |
| Content-Security-Policy | Restricts which scripts and resources can load |
| X-Content-Type-Options | Prevents MIME-type sniffing |
| X-Frame-Options | Prevents clickjacking via iframes |
| Referrer-Policy | Controls referrer information sent to external sites |
Compliance status
Current controls and limits. For storage encryption details, see Cloudflare R2's security documentation.
In place
- HTTPS + HSTS
- R2 encryption at rest
- Link access controls
- Download-link expiry
Discuss before use
- Data-processing terms
- Data residency needs
- Regulated client files
Not claimed
- BulkShare SOC 2
- Independent security audit
- End-to-end encryption
Related: Privacy policy · Terms of service · Secure client file delivery