Skip to content

Security

What we hold, what we don’t, and how it moves

We try to be precise rather than absolute. This page says what we do, and where the limits are.

The data flow

Your content lives in your bucket, not ours. We store the comments, not the content.

Diagram: your studio uploads to your own bucket; your client's browser streams from your bucket using short-lived signed links; approvd.in holds only the comments.

How it is protected

Tenant isolation

Each organisation’s data is scoped to its own workspace. Roles inside an organisation, including its top admin, carry no rights over the platform or other organisations. Our own staff console uses separate credentials and a separate session.

Files in your bucket

Files live in a bucket on your own cloud account, under an access key you create, scope to that bucket, and can revoke at any time.

Short-lived signed links

Reviewers’ browsers read files from your bucket using signed links that expire. Review links you share can be password-protected, set to expire, and revoked instantly.

Only the people you invite

Access is by invite. Roles control who can comment, upload, sign off or manage a project, and client users only see the projects they are given.

Backups of the review record

The comments, sign-offs and version history exist only in our database, so it is backed up nightly. Each backup is verified by restoring it into a scratch database and comparing row counts against the live one.

Sessions

Internal users and client users sign in with separate account types, and sessions refresh in the background rather than staying open indefinitely.

What we store

  • Comments, issues, annotations and their timestamps
  • Review rounds, checklists and sign-offs
  • Version records and where each file lives in your bucket
  • Account details for the people you invite
  • The access key to your bucket, which you can revoke

What we can and can’t see

  • We do not keep a hosted copy of your files.
  • Our server does handle a file temporarily for some work: thumbnails, converting Office or video files, and unpacking HTML5 packages for review.
  • Because we hold your bucket’s access key to serve signed links, we do not claim that we cannot access your files.

Certifications and audits

approvd.in does not currently hold any security certification or third-party audit. If your organisation needs a security questionnaire answered, email info@learningowl.in.

Report a concern

If you believe you have found a vulnerability, email info@learningowl.in with the details.

Run your next review round in approvd.in

Access is by invite for now. Tell us about your team and we will email your invite within 2 working days.