How we protect client deliverables
Industry-standard protection for your data
TLS for all connections to ClientsDock
Files encrypted at rest on Google Cloud Storage
No permanent public file URLs
Secrets managed via environment configuration
Choose how clients reach each portal
Unguessable portal links (UUID)
Optional PIN protection with bcrypt hashing
Optional magic-link email access
Short-lived client session tokens
Files are never permanently exposed
10-minute expiring download URLs
No public or indexable file links
Automatic session expiration
Complete access control
Track portal and file access
Portal view and download logging
Comment and approval activity
IP and timestamp metadata where available
Creator-visible activity timelines
Built on established cloud providers
Google Cloud Platform (Firebase, Storage, Functions)
Cloudflare for CDN and edge security
HTTPS everywhere
Regional hosting options via cloud providers
GDPR compliant from the ground up
Data minimization principles
User consent management
Right to deletion
Transparent data handling
DDoS Protection, WAF, Rate Limiting
Authentication, Session Management
AES-256 Encryption, Access Controls
SOC 2, ISO 27001, Physical Security
Privacy policy published
All app traffic
No client accounts required
Google Cloud & Cloudflare
Data at Rest
AES-256 encryption with Google Cloud KMS
Data in Transit
TLS 1.3 with perfect forward secrecy
Portal URLs
Cryptographically secure UUID4 generation
Password Hashing
bcrypt with 12 salt rounds
Session Tokens
JWT with configurable expiration
Cloud Provider
Google Cloud Platform (SOC 2 Type 2 certified)
CDN Security
Cloudflare with DDoS protection and WAF
Database
Firestore with encryption and access controls
File Storage
Google Cloud Storage with IAM policies
Monitoring
Real-time security event detection and alerting
Customer data is stored on Google Cloud Platform infrastructure with configurable geographic regions for data residency compliance.
No. All files are encrypted at rest and only accessible via authenticated client sessions with time-limited signed URLs.
Immediate portal deactivation with secure file deletion and cryptographic verification within 30 days.
Complete audit logs with detailed activity reports available for compliance and security teams.
Multi-layer security with secure URLs, optional authentication, session validation, and real-time monitoring.
security@clientsdock.com
compliance@clientsdock.com
Last updated: July 20, 2026 | Security practices are continuously monitored and improved