Security Controls
Media2URL applies security controls across the file workflow, including account access, workspace permissions, uploads, storage, file delivery and removal.
No file-hosting service can remove every risk. Media2URL combines technical controls with clear user settings so you can choose how a file is uploaded, stored and shared.
Account Protection
Account sessions and workspace permissions control who can manage uploaded assets.
Upload Protection
File checks, size limits and signed upload flows reduce unsafe or unauthorised uploads.
Link Protection
Visibility, password, expiry and supported download rules control how a file can be opened.
Operational Protection
Logs, abuse reporting and file-removal controls support investigation and response.
Security is shared between Media2URL and the account owner
Media2URL protects the platform infrastructure and provides controls for uploads, storage and links. The account owner decides which files are uploaded, who receives access and how long each link remains active. A public link should be treated as public information. A password-protected or private link still needs to be shared carefully because recipients may copy the URL or password.
Media2URL is responsible for
- Platform access controls
- Storage bucket permissions
- Upload validation systems
- Abuse-response workflows
You are responsible for
- Choosing the correct file visibility
- Protecting account login credentials
- Removing files no longer required
- Sharing links with intended recipients
Account and session protection
Account access controls protect the dashboard, workspaces and stored assets. Media2URL login sessions are tied to the authenticated account and do not expose permanent storage credentials in the browser. Suspicious access should be reported quickly so sessions can be reviewed and revoked where required.
Sessions control dashboard actions and private data.
Stored securely through provider one-way hashes.
Invalidate active tokens during account recovery.
Mitigate automated brute-force login attacks.
Workspace and role permissions
Workspaces separate files, folders, settings and members between projects or clients. A person invited to one workspace does not automatically receive access to another. Roles control which actions a member can complete. This reduces the need to share the Owner account credentials with team members or clients.
| Role | Security scope |
|---|---|
| Owner | Full access to billing, members, settings and workspace deletion |
| Admin | Member management, role changes and workspace controls |
| Editor | Upload, organise and process supported files |
| Viewer | View assets and copy available links without editing control |
* Permission details may vary as workspace features are updated. The dashboard shows the role assigned to each member.
Secure team invitations
Team invitations use email-linked tokens instead of shared passwords. A role can be selected before the invitation is sent. Pending invitations expire after seven days and can be revoked or regenerated if the original link should no longer be used.
Upload controls
Media2URL checks supported uploads before they enter the normal asset workflow. File type rules, plan limits, size checks and request limits help reduce accidental overuse and common unsafe upload patterns. Some file types can carry scripts or other content that creates additional browser risk. Media2URL can reject or restrict unsupported and higher-risk file types before they enter the normal asset workflow.
Temporary upload permission instead of permanent storage keys.
Upload size is checked against active plan limits.
MIME and extension validation before accepting files.
Mitigate automated resource abuse and bulk ingestion floods.
File type and content validation
A file extension does not always prove what the file contains. A file named as an image can still contain unexpected data or an incorrect MIME type. Media2URL compares available file information, content type and extension before the asset is accepted or delivered.
Malware Scanning Status
High-risk formats are blocked or limited. Broader automated malware scanning is being evaluated and should not be described as active until fully deployed.
Controlled file names and storage keys
Original filenames are useful for the dashboard, but they should not be the only identifier used inside storage. Media2URL assigns controlled object keys so two files with the same name do not overwrite each other. Hash or duplicate checks can also reduce unnecessary copies where the workflow supports them.
Storage and file delivery
Uploaded files are stored separately from the main application code. Storage permissions prevent the browser from gaining unrestricted access to the underlying bucket. Public assets are delivered according to their selected link mode. Private assets require the correct account, token or access rule before delivery.
Media assets reside in dedicated object storage buckets.
Permanent keys are never exposed during browser uploads.
Different pathways handle public, unlisted and private assets.
Disable or revoke links and files immediately from settings.
Protected data transfer
Media2URL uses HTTPS for supported website, dashboard and file-delivery traffic. This protects data while it travels between the browser and the platform. HTTPS does not protect a file after a recipient downloads it. Sensitive downloads should still be handled through the correct device and access policy.
File access and sharing controls
Every file does not need the same sharing mode. Media2URL supports several access levels so the account owner can choose between open delivery and restricted access. The selected mode should match the actual purpose of the file. A customer invoice should not use the same access setting as a public website image.
Anyone with the URL can open the supported file.
Anyone with the URL can open the supported file, but the share page is marked not to be indexed by search engines. Unlisted should not be treated as private or confidential access.
Limited to authenticated members of the workspace.
Visitors must enter passwords before viewing content.
Expiry, view and download controls
Temporary links reduce the time during which a file remains available. Supported assets can use an expiry period, download cap or view-based rule depending on the selected workflow. Automated link previews and security scanners may affect view-based rules. Use one-time access only when this behaviour is acceptable.
Signed delivery links
A signed link gives temporary access to an eligible protected asset without turning that file into a permanent public URL. The link includes a cryptographic signature and remains valid only for its configured lifetime.
Once that time expires, the signed address can no longer be used normally. Signing keys can also be rotated when existing signed access needs to be invalidated.
Signed delivery is useful when somebody needs direct file access for a limited period but the underlying asset should remain protected.
Verifies that the protected URL was issued by Media2URL.
Limits how long the signed address remains valid.
The signature applies to the intended asset.
Allows existing signed access to be invalidated where supported.
Preview-only access and download limits
Preview-only mode can hide the standard download button and reduce casual saving from the share page. It cannot fully prevent a determined visitor from capturing content that appears on their screen.
Browser controls such as disabled right-click or image dragging are convenience barriers. They should not be treated as digital rights management (DRM).
Operational and workspace logs
Logs help investigate file changes, access updates and team actions. Depending on the workflow, Media2URL can record uploads, renaming, metadata edits, role changes and invitations. Log access remains limited to authorised workspace members.
Link activity and account data
Media2URL records supported activity needed to operate file-sharing and workspace features. Depending on the workflow, this can include share-page views, recent downloads, bandwidth use, workspace quota information and activity associated with the account.
Media2URL does not currently provide visitor-country or referring-source analytics. Information collected for platform operation is handled according to the Privacy Policy and Data Retention Policy.
Records supported page-view activity.
Shows recent download and transfer activity where supported.
Tracks quota use required for account operation.
Handled according to the applicable retention policy.
Abuse and harmful-content response
Media hosting can be misused for phishing, malware, unlawful content or non-consensual material. Media2URL provides reporting channels so affected users and rights holders can identify a specific hosted URL. When a report presents an urgent safety or security risk, access may be disabled before the complete review is finished.
Required report details
- • Exact Media2URL file URL
- • Reason for the report
- • Reporter contact information
- • Safe supporting evidence (no live malware/illegal material)
Automated checks and manual review
Some risks can be identified through automated file rules, rate limits or account signals. Other reports require human review because the file, context and legal basis may not be obvious from the URL alone. Media2URL may restrict an account or asset during investigation when continued access could create an immediate risk.
File deletion and retention
Deleting a file removes it from the active workspace and stops normal access through its Media2URL links. Related versions, thumbnails or generated outputs may also be scheduled for removal. Technical records or backups may remain for a limited period for recovery, fraud prevention, billing or legal requirements.
Workspace deletion
Workspace deletion is a destructive Owner action. It removes active files, folders, members, versions and related workspace records. The interface requires confirmation before the request is completed. Any remaining technical records follow the published retention process.
Backups and recovery
Media2URL uses infrastructure backup or recovery processes for selected platform data. Backup coverage and retention can differ between databases, storage objects and operational logs.
Backups support service recovery. They are not a replacement for users keeping their own copy of business-critical source files.
Security incident response
A security incident may involve suspicious login activity, exposed credentials, unauthorised workspace access or harmful hosted content. Media2URL reviews the affected account, link or system and may revoke sessions, disable files or restrict access during investigation. Affected users are contacted when notification is required by circumstances and law.
Report a security vulnerability
Security researchers and users can report a suspected vulnerability affecting Media2URL. Include enough information to reproduce the issue without accessing another user’s data or disrupting the service.
Do not perform destructive testing, denial-of-service attacks or unauthorised access while investigating a report.
Report checklist
- • Affected page or feature
- • Step-by-step reproduction guide
- • Expected and actual behaviour
- • Safe screenshots or reproduction logs
Payment and billing information
Payment details are handled by the selected payment provider rather than stored as full card data inside Media2URL. Media2URL may receive billing status, plan information and transaction references needed to manage the account.
Infrastructure and service providers
Media2URL relies on selected infrastructure providers for services such as application hosting, object storage, email delivery, authentication or payments. These providers only support the functions assigned to them. Relevant providers and data-handling details are listed in the Privacy Policy.
Steps you should take to protect your files
Protect Account Access
Use a strong password and do not share login credentials.
Review Link Visibility
Confirm whether the file is public, private, unlisted or protected.
Remove Old Access
Expire or delete files that are no longer required.
Report Suspicious Activity
Contact support after unexpected logins or file changes.
Files that require extra caution
Do not upload passwords, private keys, recovery codes or credential exports. These items should remain inside a dedicated secrets-management system. Government identification, medical information, financial records and other highly sensitive documents should only be uploaded after you understand the access mode, retention process and legal responsibilities involved.
What security controls cannot guarantee
A recipient can copy a public URL, share a password or capture content displayed on a screen. Preview-only mode and disabled right-click controls cannot stop every form of copying.
Expiry and one-time links reduce access time, but automated scanners or previews may open a link before the intended person. Use the sharing method that can tolerate these limitations.
Frequently asked questions
Contact Media2URL about security
Report suspicious account activity, harmful files, privacy concerns or a possible platform vulnerability as soon as possible. Include the exact URL or account context so the issue can be reviewed. For account-specific requests, contact us from the email address connected to the account where possible.