Security
What we hold, what we don’t, and how it moves
We try to be precise rather than absolute. This page says what we do, and where the limits are.
The data flow
Your content lives in your bucket, not ours. We store the comments, not the content.
How it is protected
Tenant isolation
Each organisation’s data is scoped to its own workspace. Roles inside an organisation, including its top admin, carry no rights over the platform or other organisations. Our own staff console uses separate credentials and a separate session.
Files in your bucket
Files live in a bucket on your own cloud account, under an access key you create, scope to that bucket, and can revoke at any time.
Short-lived signed links
Reviewers’ browsers read files from your bucket using signed links that expire. Review links you share can be password-protected, set to expire, and revoked instantly.
Only the people you invite
Access is by invite. Roles control who can comment, upload, sign off or manage a project, and client users only see the projects they are given.
Backups of the review record
The comments, sign-offs and version history exist only in our database, so it is backed up nightly. Each backup is verified by restoring it into a scratch database and comparing row counts against the live one.
Sessions
Internal users and client users sign in with separate account types, and sessions refresh in the background rather than staying open indefinitely.
What we store
- Comments, issues, annotations and their timestamps
- Review rounds, checklists and sign-offs
- Version records and where each file lives in your bucket
- Account details for the people you invite
- The access key to your bucket, which you can revoke
What we can and can’t see
- We do not keep a hosted copy of your files.
- Our server does handle a file temporarily for some work: thumbnails, converting Office or video files, and unpacking HTML5 packages for review.
- Because we hold your bucket’s access key to serve signed links, we do not claim that we cannot access your files.
Certifications and audits
approvd.in does not currently hold any security certification or third-party audit. If your organisation needs a security questionnaire answered, email info@learningowl.in.
Report a concern
If you believe you have found a vulnerability, email info@learningowl.in with the details.
Run your next review round in approvd.in
Access is by invite for now. Tell us about your team and we will email your invite within 2 working days.