Trust starts with clarity
Your clients’ documents deserve care.
Here is what the current application does—and what still needs to be ready before you trust it with real personal information.
Controls implemented in the application
- Request-specific links
- Random access tokens are stored as hashes. Links expire, can be revoked and can be replaced. Anyone with a valid link can access that request’s client page: keep the link private and verify the recipient.
- Private files and checked downloads
- Default document storage is outside the public web directory. Staff downloads check organisation membership, permissions and file availability. A guessed document identifier is not enough to download a file.
- File validation
- Uploads are limited by size and file count, with server-side type checks for PDF, JPEG and PNG. These checks do not replace malware scanning.
- Review and activity history
- Uploads, review decisions and downloads record activity. Replacement history keeps earlier versions; replacing a file does not erase it.
Production safeguards still to verify
HTTPS and secure cookies, private production storage, operational scanning, monitored queues, tested backup restoration, deletion and retention procedures, and a working incident response process must be checked on the actual deployment. A page describing a safeguard is not proof that it is operating.
We do not claim POPIA certification, guaranteed compliance, South African-only hosting or independently audited security. Your business must establish why it may collect each document and who should access it.
Reporting a concern
Contact the requesting business promptly if a link was shared incorrectly. Use GetDocs security support for service concerns. Do not send documents, passwords or secure request URLs in your initial report.