Private evidence
Objects are stored in a private environment-specific bucket and are never exposed through an unauthenticated URL.
Trust boundary
Original evidence and personal communications deserve controls that match their sensitivity.
Case-file security model
These controls describe the account-based case-file system. That system is separate from the public checker and is not yet open for public evidence uploads.
Objects are stored in a private environment-specific bucket and are never exposed through an unauthenticated URL.
The original filename, MIME type, size, upload time, uploader, storage environment, and SHA-256 hash are retained.
Uploads fail closed through file validation and malware scanning before becoming available.
Authorized users receive an application-signed, expiring access link. Access is checked again and audited when used.
An internal assignment grants no access. The consumer first sees the named firm and authorizes a fixed snapshot.
Revocation blocks future platform access. It cannot erase copies a firm lawfully downloaded and independently retains.
The public checker does not accept files or expose case-file access. The controls above are not a third-party certification and will be independently reviewed before real evidence is accepted publicly.