Secure document storage

Encrypted repositories with permissions and a record of everything that happens to a file.

Most document storage answers one question: where is the file. Secure document storage has to answer several more. Who can open it. Who has opened it. SafeVault Vaults is built around those questions rather than around folders. It is one of three parts of the SafeVault platform, built by AmitaSoft, LLC, which completed a SOC 2 Type 2 examination covering Security, Availability, Processing Integrity and Confidentiality.

Encryption

Documents are encrypted in transit using TLS and at rest using AES-256, applied to both stored databases and stored document objects. Backups are encrypted under a documented business continuity policy.

In multi-tenant deployments, customer data is logically separated to prevent cross-tenant access.

What storage has to survive

Document storage is rarely tested on an ordinary day. It is tested when somebody leaves the firm and their access needs revoking across four years of files. When a client asks for everything you hold on them. When work that closed two years ago has to be found by someone who was not there at the time.

None of those are storage problems in the usual sense. They are questions about permissions, organisation and retrieval, and a system designed only to hold files answers none of them. That is the difference between a folder and a vault.

Permissions and access

Access is role-based and provisioned on a documented business need, then reviewed on a defined schedule. Multi-factor authentication is required for access to critical systems.

Permissions are granted to named people rather than to links. A document shared with someone is a permission you can withdraw, not a URL circulating indefinitely.

Audit history

Every action against a document is recorded: upload, view, share and permission change. The record is immutable.

This is the part most storage tools leave out, and the part that matters when a client, an auditor or a regulator asks a question about a specific file on a specific date.

Why immutability matters

An audit log that can be edited is not an audit log. If a record of access can itself be changed by someone with sufficient permissions, it proves nothing under scrutiny, which is the only moment it is ever needed.

SafeVault records document actions as an immutable history. The value is not the logging, which most systems do in some form. It is that the record cannot be quietly corrected afterwards, so what it says on the day of the question is what it said on the day of the event.

Organisation

Uploaded documents are categorised and tagged automatically, so retrieval does not depend on whoever named the file. Search covers document contents, not only filenames.

Retrieval also matters more as a vault ages. A document filed sensibly in year one is found easily in year one. Whether it is still findable in year four, by someone who was not there when it arrived, is the harder test and the one worth designing for.

The rest of the platform

Vaults holds documents. DocIQ reads them. Flows acts on them. The three work together and are described separately because they solve different problems.