Security and data handling

Confirmed information about how Smooth Bundle handles access, protected assets and account data. Where a formal policy is not yet public, this page says so directly.

Smooth Bundle security

Storage

Smooth Bundle stores uploaded originals and generated outputs in its asset system. The public documentation does not currently name a specific storage provider.

Encryption in transit

Public Smooth Bundle web, API and delivery URLs use HTTPS. Protected asset tokens should be sent only over HTTPS.

Encryption at rest

A public encryption-at-rest statement is not documented yet. This should be confirmed before making procurement or compliance commitments.

Access control

Accounts use authenticated sessions. Projects can have collaborators, and protected assets require token-based access or an authenticated Smooth Bundle user with project access.

Protected URLs

Protected assets can be requested with an Authorization bearer token or the documented token query parameter. Public URLs remain intended for public assets.

Account authentication

Smooth Bundle supports account login and optional two-factor authentication for regular accounts. Guest accounts are intended for temporary testing workflows.

Data deletion

The public API documents asset and version deletion. Account-level permanent deletion should be requested through support unless a self-serve flow is available for the account.

Backups

Backup policy is not publicly documented yet. Keep your own source copies of critical originals until backup and export commitments are formally published.

Incident handling

A public incident-response policy is not documented yet. Status information is available through the public status page.

Third-party processors

The app integrates with third-party services for areas such as payments, e-mail and infrastructure. A complete processor list is not currently published on this page.

Report a security issue

Use support until a dedicated security inbox is published

Blocker: a dedicated security contact has not been documented publicly yet. For now, send security reports to [email protected] and include enough detail to reproduce the issue.