Skip to content
MEDALDIGITAL

Security and configuration

Clear controls. Honest boundaries.

Security claims should describe implemented safeguards, not planned features. Here is where this prototype stands.

01

Current demo boundary

No real accounts, private cloud storage, organization isolation, secure external links, or backend malware scanning are configured. The workspace is public sample UI. Role selection demonstrates interface behavior only and is not a security boundary.

02

Upload handling in the demo

Uploads remain in memory in the current browser session. Common raster images, audio, video, and PDF can be previewed locally where the browser supports them. HTML, JavaScript, active SVG, and archives are never executed in the workspace. Do not upload confidential or untrusted files.

03

Required production safeguards

Configure server-enforced organization isolation, roles, secure sessions, private originals and renditions, file validation, scanning and quarantine, signed access, audit logs, and backup and restore. Validate every download and search against permissions.

04

AI content handling

Private assets must not be used for model training without applicable explicit authorization. Extracted text must be treated as untrusted data, not as application instructions. Production AI services are not connected.

05

No unverified claims

Certifications, SSO, data residency, retention guarantees, encryption specifics, and restoration commitments will be published only after verification. Revoking a link can stop future access, not erase files already downloaded.