Security and data handling
Confirmed information about how Smooth Bundle handles access, protected assets and account data. Where a formal policy is not yet public, this page says so directly.
Storage
Smooth Bundle stores uploaded originals and generated outputs in its asset system. The public documentation does not currently name a specific storage provider.
Encryption in transit
Public Smooth Bundle web, API and delivery URLs use HTTPS. Protected asset tokens should be sent only over HTTPS.
Encryption at rest
A public encryption-at-rest statement is not documented yet. This should be confirmed before making procurement or compliance commitments.
Access control
Accounts use authenticated sessions. Projects can have collaborators, and protected assets require token-based access or an authenticated Smooth Bundle user with project access.
Protected URLs
Protected assets can be requested with an Authorization bearer token or the documented token query parameter. Public URLs remain intended for public assets.
Account authentication
Smooth Bundle supports account login and optional two-factor authentication for regular accounts. Guest accounts are intended for temporary testing workflows.
Data deletion
The public API documents asset and version deletion. Account-level permanent deletion should be requested through support unless a self-serve flow is available for the account.
Backups
Backup policy is not publicly documented yet. Keep your own source copies of critical originals until backup and export commitments are formally published.
Incident handling
A public incident-response policy is not documented yet. Status information is available through the public status page.
Third-party processors
The app integrates with third-party services for areas such as payments, e-mail and infrastructure. A complete processor list is not currently published on this page.
Report a security issue
Use support until a dedicated security inbox is published
Blocker: a dedicated security contact has not been documented publicly yet. For now, send security reports to [email protected] and include enough detail to reproduce the issue.