Media2URL
TRUST CENTRE

Security Controls

Media2URL applies security controls across the file workflow, including account access, workspace permissions, uploads, storage, file delivery and removal.

No file-hosting service can remove every risk. Media2URL combines technical controls with clear user settings so you can choose how a file is uploaded, stored and shared.

Last security content review: August 19, 2026|Report a Security Issue|View Security Features

Account Protection

Account sessions and workspace permissions control who can manage uploaded assets.

Upload Protection

File checks, size limits and signed upload flows reduce unsafe or unauthorised uploads.

Link Protection

Visibility, password, expiry and supported download rules control how a file can be opened.

Operational Protection

Logs, abuse reporting and file-removal controls support investigation and response.

Security is shared between Media2URL and the account owner

Media2URL protects the platform infrastructure and provides controls for uploads, storage and links. The account owner decides which files are uploaded, who receives access and how long each link remains active. A public link should be treated as public information. A password-protected or private link still needs to be shared carefully because recipients may copy the URL or password.

Media2URL is responsible for

  • Platform access controls
  • Storage bucket permissions
  • Upload validation systems
  • Abuse-response workflows

You are responsible for

  • Choosing the correct file visibility
  • Protecting account login credentials
  • Removing files no longer required
  • Sharing links with intended recipients

Account and session protection

Account access controls protect the dashboard, workspaces and stored assets. Media2URL login sessions are tied to the authenticated account and do not expose permanent storage credentials in the browser. Suspicious access should be reported quickly so sessions can be reviewed and revoked where required.

Active
Protected Sessions

Sessions control dashboard actions and private data.

Active
Password Hashing

Stored securely through provider one-way hashes.

Active
Session Revocation

Invalidate active tokens during account recovery.

Active
Login Rate Limits

Mitigate automated brute-force login attacks.

Workspace and role permissions

Workspaces separate files, folders, settings and members between projects or clients. A person invited to one workspace does not automatically receive access to another. Roles control which actions a member can complete. This reduces the need to share the Owner account credentials with team members or clients.

RoleSecurity scope
OwnerFull access to billing, members, settings and workspace deletion
AdminMember management, role changes and workspace controls
EditorUpload, organise and process supported files
ViewerView assets and copy available links without editing control

* Permission details may vary as workspace features are updated. The dashboard shows the role assigned to each member.

Secure team invitations

Team invitations use email-linked tokens instead of shared passwords. A role can be selected before the invitation is sent. Pending invitations expire after seven days and can be revoked or regenerated if the original link should no longer be used.

Send invitation
Resend invitation
Revoke invitation
Regenerate token

Upload controls

Media2URL checks supported uploads before they enter the normal asset workflow. File type rules, plan limits, size checks and request limits help reduce accidental overuse and common unsafe upload patterns. Some file types can carry scripts or other content that creates additional browser risk. Media2URL can reject or restrict unsupported and higher-risk file types before they enter the normal asset workflow.

Presigned Requests

Temporary upload permission instead of permanent storage keys.

File Size Validation

Upload size is checked against active plan limits.

File Type Validation

MIME and extension validation before accepting files.

Rate Limiting

Mitigate automated resource abuse and bulk ingestion floods.

File type and content validation

A file extension does not always prove what the file contains. A file named as an image can still contain unexpected data or an incorrect MIME type. Media2URL compares available file information, content type and extension before the asset is accepted or delivered.

• Extension checks
• MIME-type checks
• File-size checks
• High-risk formats blocking

Malware Scanning Status

High-risk formats are blocked or limited. Broader automated malware scanning is being evaluated and should not be described as active until fully deployed.

Controlled file names and storage keys

Original filenames are useful for the dashboard, but they should not be the only identifier used inside storage. Media2URL assigns controlled object keys so two files with the same name do not overwrite each other. Hash or duplicate checks can also reduce unnecessary copies where the workflow supports them.

Unique Storage Key
Filename Separation
Collision Protection
Duplicate Detection

Storage and file delivery

Uploaded files are stored separately from the main application code. Storage permissions prevent the browser from gaining unrestricted access to the underlying bucket. Public assets are delivered according to their selected link mode. Private assets require the correct account, token or access rule before delivery.

* Data is encrypted in transit through HTTPS. Storage encryption at rest is provided by the underlying cloud-storage infrastructure.
Storage Separation

Media assets reside in dedicated object storage buckets.

Restricted Credentials

Permanent keys are never exposed during browser uploads.

Controlled Delivery

Different pathways handle public, unlisted and private assets.

File Revocation

Disable or revoke links and files immediately from settings.

HTTPS dashboard access
HTTPS upload requests
HTTPS link delivery
Secure cookie settings

Protected data transfer

Media2URL uses HTTPS for supported website, dashboard and file-delivery traffic. This protects data while it travels between the browser and the platform. HTTPS does not protect a file after a recipient downloads it. Sensitive downloads should still be handled through the correct device and access policy.

File access and sharing controls

Every file does not need the same sharing mode. Media2URL supports several access levels so the account owner can choose between open delivery and restricted access. The selected mode should match the actual purpose of the file. A customer invoice should not use the same access setting as a public website image.

Public

Anyone with the URL can open the supported file.

Unlisted

Anyone with the URL can open the supported file, but the share page is marked not to be indexed by search engines. Unlisted should not be treated as private or confidential access.

Private

Limited to authenticated members of the workspace.

Password Protected

Visitors must enter passwords before viewing content.

Expiry, view and download controls

Temporary links reduce the time during which a file remains available. Supported assets can use an expiry period, download cap or view-based rule depending on the selected workflow. Automated link previews and security scanners may affect view-based rules. Use one-time access only when this behaviour is acceptable.

Time Expiry
One-Time View
Download Cap
Manual Revoke

Signed delivery links

A signed link gives temporary access to an eligible protected asset without turning that file into a permanent public URL. The link includes a cryptographic signature and remains valid only for its configured lifetime.

Once that time expires, the signed address can no longer be used normally. Signing keys can also be rotated when existing signed access needs to be invalidated.

Signed delivery is useful when somebody needs direct file access for a limited period but the underlying asset should remain protected.

Cryptographic signature

Verifies that the protected URL was issued by Media2URL.

Custom lifetime

Limits how long the signed address remains valid.

Protected asset binding

The signature applies to the intended asset.

Key rotation

Allows existing signed access to be invalidated where supported.

Preview-only access and download limits

Preview-only mode can hide the standard download button and reduce casual saving from the share page. It cannot fully prevent a determined visitor from capturing content that appears on their screen.

Browser controls such as disabled right-click or image dragging are convenience barriers. They should not be treated as digital rights management (DRM).

Operational and workspace logs

Logs help investigate file changes, access updates and team actions. Depending on the workflow, Media2URL can record uploads, renaming, metadata edits, role changes and invitations. Log access remains limited to authorised workspace members.

• Member or system actor
• Logged action description
• Date and time stamps
• Related workspace logs
Workspace Activity Log (Example)
Priya uploaded campaign-banner.webp 10:42 AM
Rahul changed the file to Private 11:15 AM
Sourav invited a Viewer 01:30 PM
Amit revoked an expiring link 03:00 PM
* Supported workspace logs can be exported as CSV for internal review.

Link activity and account data

Media2URL records supported activity needed to operate file-sharing and workspace features. Depending on the workflow, this can include share-page views, recent downloads, bandwidth use, workspace quota information and activity associated with the account.

Media2URL does not currently provide visitor-country or referring-source analytics. Information collected for platform operation is handled according to the Privacy Policy and Data Retention Policy.

Share-page views

Records supported page-view activity.

Downloads and bandwidth

Shows recent download and transfer activity where supported.

Workspace usage

Tracks quota use required for account operation.

Retention

Handled according to the applicable retention policy.

Abuse and harmful-content response

Media hosting can be misused for phishing, malware, unlawful content or non-consensual material. Media2URL provides reporting channels so affected users and rights holders can identify a specific hosted URL. When a report presents an urgent safety or security risk, access may be disabled before the complete review is finished.

Security or malware
Abuse or prohibited
Copyright or DMCA
Privacy complaints

Required report details

  • • Exact Media2URL file URL
  • • Reason for the report
  • • Reporter contact information
  • • Safe supporting evidence (no live malware/illegal material)

Automated checks and manual review

Some risks can be identified through automated file rules, rate limits or account signals. Other reports require human review because the file, context and legal basis may not be obvious from the URL alone. Media2URL may restrict an account or asset during investigation when continued access could create an immediate risk.

• Automated file size checks
• Rate limits indicators
• Manual appeals process
• Urgent safety blocks first

File deletion and retention

Deleting a file removes it from the active workspace and stops normal access through its Media2URL links. Related versions, thumbnails or generated outputs may also be scheduled for removal. Technical records or backups may remain for a limited period for recovery, fraud prevention, billing or legal requirements.

Workspace deletion

Workspace deletion is a destructive Owner action. It removes active files, folders, members, versions and related workspace records. The interface requires confirmation before the request is completed. Any remaining technical records follow the published retention process.

Workspace deletion cautionWorkspace deletion cannot be treated like normal folder removal. Confirm the workspace name and understand which files will lose access before continuing.

Backups and recovery

Media2URL uses infrastructure backup or recovery processes for selected platform data. Backup coverage and retention can differ between databases, storage objects and operational logs.

Backups support service recovery. They are not a replacement for users keeping their own copy of business-critical source files.

Security incident response

A security incident may involve suspicious login activity, exposed credentials, unauthorised workspace access or harmful hosted content. Media2URL reviews the affected account, link or system and may revoke sessions, disable files or restrict access during investigation. Affected users are contacted when notification is required by circumstances and law.

Identify
Contain
Investigate
Recover

Report a security vulnerability

Security researchers and users can report a suspected vulnerability affecting Media2URL. Include enough information to reproduce the issue without accessing another user’s data or disrupting the service.

Do not perform destructive testing, denial-of-service attacks or unauthorised access while investigating a report.

Contact: support@media2url.com with subject: "Security Report"

Report checklist

  • • Affected page or feature
  • • Step-by-step reproduction guide
  • • Expected and actual behaviour
  • • Safe screenshots or reproduction logs

Payment and billing information

Payment details are handled by the selected payment provider rather than stored as full card data inside Media2URL. Media2URL may receive billing status, plan information and transaction references needed to manage the account.

Infrastructure and service providers

Media2URL relies on selected infrastructure providers for services such as application hosting, object storage, email delivery, authentication or payments. These providers only support the functions assigned to them. Relevant providers and data-handling details are listed in the Privacy Policy.

Steps you should take to protect your files

Protect Account Access

Use a strong password and do not share login credentials.

Review Link Visibility

Confirm whether the file is public, private, unlisted or protected.

Remove Old Access

Expire or delete files that are no longer required.

Report Suspicious Activity

Contact support after unexpected logins or file changes.

Files that require extra caution

Do not upload passwords, private keys, recovery codes or credential exports. These items should remain inside a dedicated secrets-management system. Government identification, medical information, financial records and other highly sensitive documents should only be uploaded after you understand the access mode, retention process and legal responsibilities involved.

What security controls cannot guarantee

A recipient can copy a public URL, share a password or capture content displayed on a screen. Preview-only mode and disabled right-click controls cannot stop every form of copying.

Expiry and one-time links reduce access time, but automated scanners or previews may open a link before the intended person. Use the sharing method that can tolerate these limitations.

Frequently asked questions

Contact Media2URL about security

Report suspicious account activity, harmful files, privacy concerns or a possible platform vulnerability as soon as possible. Include the exact URL or account context so the issue can be reviewed. For account-specific requests, contact us from the email address connected to the account where possible.

Direct Email: support@media2url.com

Related policies and reporting pages