ClientsDock

Security at ClientsDock

How we protect client deliverables

Security-first client delivery

ClientsDock is built for freelancers and agencies sharing sensitive deliverables. We use signed download URLs, optional PIN or magic-link access, and activity logging — without asking your clients to create accounts.
Signed file URLs
Optional PIN & magic links
Complete Audit Logging
GDPR Compliant

Comprehensive Security Features

Encryption in transit and at rest

Industry-standard protection for your data

  • TLS for all connections to ClientsDock

  • Files encrypted at rest on Google Cloud Storage

  • No permanent public file URLs

  • Secrets managed via environment configuration

Flexible access control

Choose how clients reach each portal

  • Unguessable portal links (UUID)

  • Optional PIN protection with bcrypt hashing

  • Optional magic-link email access

  • Short-lived client session tokens

Time-Limited Access

Files are never permanently exposed

  • 10-minute expiring download URLs

  • No public or indexable file links

  • Automatic session expiration

  • Complete access control

Activity logging

Track portal and file access

  • Portal view and download logging

  • Comment and approval activity

  • IP and timestamp metadata where available

  • Creator-visible activity timelines

Cloud infrastructure

Built on established cloud providers

  • Google Cloud Platform (Firebase, Storage, Functions)

  • Cloudflare for CDN and edge security

  • HTTPS everywhere

  • Regional hosting options via cloud providers

Privacy by Design

GDPR compliant from the ground up

  • Data minimization principles

  • User consent management

  • Right to deletion

  • Transparent data handling

Multi-Layer Protection

🛡️ Cloudflare Security Layer

DDoS Protection, WAF, Rate Limiting

🔐 Application Security Layer

Authentication, Session Management

🗄️ Data Storage Layer

AES-256 Encryption, Access Controls

☁️ Google Cloud Infrastructure

SOC 2, ISO 27001, Physical Security

Compliance & Certifications

GDPR-oriented practices
Compliant

Privacy policy published

HTTPS / TLS
Compliant

All app traffic

Data minimization
Compliant

No client accounts required

Third-party infrastructure
Compliant

Google Cloud & Cloudflare

Technical Security Specifications

Encryption Standards
  • Data at Rest

    AES-256 encryption with Google Cloud KMS

  • Data in Transit

    TLS 1.3 with perfect forward secrecy

  • Portal URLs

    Cryptographically secure UUID4 generation

  • Password Hashing

    bcrypt with 12 salt rounds

  • Session Tokens

    JWT with configurable expiration

Infrastructure Security
  • Cloud Provider

    Google Cloud Platform (SOC 2 Type 2 certified)

  • CDN Security

    Cloudflare with DDoS protection and WAF

  • Database

    Firestore with encryption and access controls

  • File Storage

    Google Cloud Storage with IAM policies

  • Monitoring

    Real-time security event detection and alerting

Common Security Questions

Customer data is stored on Google Cloud Platform infrastructure with configurable geographic regions for data residency compliance.

No. All files are encrypted at rest and only accessible via authenticated client sessions with time-limited signed URLs.

Immediate portal deactivation with secure file deletion and cryptographic verification within 30 days.

Complete audit logs with detailed activity reports available for compliance and security teams.

Multi-layer security with secure URLs, optional authentication, session validation, and real-time monitoring.

Get Started Securely

Ready to share files with confidence? ClientsDock's security-first approach means you can focus on your work while we protect your data.

Security Questions?

security@clientsdock.com

compliance@clientsdock.com

Security Resources

Last updated: July 20, 2026 | Security practices are continuously monitored and improved

Security — ClientsDock