Security

Encrypted for your company, not for the cloud

Files are encrypted with a key that exists only for your company. What must not circulate goes into the vault; what cannot be deleted has a legal hold; everything that happens stays written where nobody can rewrite it.

Security you see in the menu, not just in the contract

Right-click a folder, “Security and preservation”: substitutive preservation, document expiry, read-only archiving, protection with edits for a few only. Under the hood: AES-256-GCM encryption with a per-company derived key, previous versions kept 90 days, audit written twice — in the database and on write-once storage — and a log of every access to every share with IP, country and browser.

How it works

  1. Put what is sensitive in the vault

    The vault is a separate space: no public links, no previews outside, access to whom you decide and a second copy with review. If an administrator tries to get in on someone else’s behalf, they can’t.

  2. Lock what must not be touched

    Legal hold on a folder: no deletion, no edits, until the dispute is closed. The manual lock on a file protects the signed version; substitutive preservation makes it compliant.

  3. Read what happened, whenever you want

    The audit log says who did what and when; the share log says who opened what from where. The copy on write-once storage is there even if someone deletes from the database.

Your company’s key opens only your company’s files.

What you can do

  • One key per company

    AES-256-GCM with a per-tenant derived key and master-key fingerprint check; encrypted backup with a recovery passphrase.

  • Vault

    A closed space with no public surface: no links, no derivatives outside, separate trash, second copy with review and an emergency procedure.

  • Legal hold and preservation

    Per-folder legal hold, retention rules over time, substitutive preservation for documents that must still hold in ten years.

  • Versions and file lock

    Every overwrite keeps the previous version for 90 days. The edit lock from the desktop stops two people saving over the same file.

  • Watermark on PDFs, images and videos

    Text or the viewer’s email, diagonal or in the header, with the opacity you choose: burned into PDFs and images, overlaid on videos in preview — with the clean file’s download blocked.

  • Security blocks

    Print, screenshot, right-click and copy hindered; when the window loses focus or the pointer heads for the browser menus, the screen is covered with “Confidential” or the viewer’s email. Who is exempt you decide per user type.

In depth

Protecting documents

  • Vault

    Right-click a file, move it to the vault and choose a numeric code. The file stays visible in the list, but its content opens only with that code, which you decide who to tell. For the documents that concern precisely the people who hold the system keys: payslips, disciplinary measures, minutes, whistleblowing reports.

  • Watermark

    A watermark on PDFs and images: your own text — CONFIDENTIAL, DRAFT, RESTRICTED — or the email of whoever views or downloads. Diagonal, header, footer or centre, with the opacity and colour you choose.

  • Anonymiser

    Masks the personal data in deeds, contracts, rulings and medical reports while keeping the legal or clinical content intact. Detection happens entirely on our servers: no data is sent to external services.

  • Confidential folder

    The folder of the negotiation, the dispute, the reorganisation: for a few weeks it must vanish from everyone’s view. “Make confidential” hides it from anyone who is not a Files administrator, subfolders included. When you reopen it, whoever had access has it again, without redoing anything.

  • Read-only folder

    The closed case that must never change again, or the folder only two people should write to. “Archive” makes it read-only for everyone, administrators included; “Protect” for everyone except whom you choose. With an expiry if needed, cascading to subfolders and files.

  • Retention and legal hold

    Invoices, payslips, contracts, medical records: documents the law requires you to keep for a precise period. Retention locks them until that date: no trashing, no overwriting, no deleting — not even by the administrator. And when the period ends, destruction is tracked.

Proving and preserving

  • Blockchain timestamp

    Files computes the SHA-256 fingerprint of the content and anchors it to the Bitcoin blockchain through OpenTimestamps. The result is an immutable proof that the file, as it is, existed at that moment — verifiable by anyone, even without Kamzan.

  • Compliant digital preservation

    Sending to AgID-compliant preservation through Intesi Group, an accredited preservation provider: submission of the file with its metadata, receipt register, integrity certified over time. For payslips, contracts, invoices, minutes: everything the law requires you to preserve, not merely to keep.

  • Electronic signature with kSign

    The contract is in Files, the signers are in kSign. “Send to sign” from the context menu opens the signature request on the document in front of you: choose who signs and how, and kSign does its job. Requires the kSign product to be active in your company.

  • View tracking

    Enable it on a folder and every opening of its files is recorded: person, date, IP address, mode. A badge on the file says how many people opened it; the detail is one click away. For the accountant sending the annual accounts, the tax office handing over a return, anyone who needs to know the client has read it.

  • File expiry

    Every document with an end date — policy, certification, contract, permit — carries its expiry in Files. A reminder arrives beforehand, on expiry what you decided for that folder happens, and the “Expiring” collection shows what is about to end, in order of urgency.

Controlling who has access

  • Auditor

    The auditor sees every share, access and login of every Files user; they can investigate, ask for explanations and revoke. And every action of theirs — inspection, report, question, investigation — is logged and visible to administrators. For the DPO, the compliance officer, the reviewer who must answer “who had access to this, and when”.

  • Access change reason

    Every time someone assigns, changes or revokes an access level, Files asks for a reason and does not proceed without it. The register keeps who made the change, to whom, on which folder or file, from which level to which, and why. Administrators and auditors get an email.

  • View as user

    “Why can’t Marco see the Suppliers folder?” Instead of calling Marco, you open it as he sees it: folders, files and effective permissions, read-only, with a banner that always reminds you whose view it is. The personal space is excluded and every session is logged.

  • Archive controls

    Every week or every month Files flags inactive files: those shared but never opened by any recipient, and those nobody has shared or assigned for a long time. The report arrives by email and in the Control centre. No file is deleted or moved: only flagged.

  • User expiry

    The March intern, the project consultant, the audit reviewer: accounts that have an end, and that nobody remembers to close. With user expiry every account can have an end date — or suspend itself after a period of inactivity. On expiry access is blocked; data and account remain, and it renews in one click.

Frequently asked questions

Where are the files physically?

On servers in Europe, encrypted at rest with your company’s key and in transit with TLS. No subcontracting outside the Union.

Can whoever administers Kamzan open my vault?

No. The vault refuses even impersonation by the tenant administrator; access is only for those admitted, and every attempt stays in the log.

If I delete by mistake, how long can I recover?

Thirty days from the trash, which puts the file back in its original folder. If the folder is gone, it returns to the root. Overwritten versions stay ninety days.

How do you sign in? Is there two-factor authentication?

With the Kamzan account, one for every product. Each person can turn on two-step verification with an authenticator app or a passkey; the company can link sign-in to Microsoft or Google and, where configured, to SPID. After too many wrong attempts access is locked for a while, and expired or inactive accounts are suspended automatically.

Move your company files to the cloud

Request a demo: we’ll show you how Files makes storage and sharing simple and secure.

Request a demo