Security & reliability

Your work, kept somewhere serious.

A studio’s files are the studio. So the boring, load-bearing things — where the bytes sit, who can reach them, what happens when something is deleted by mistake — are not an afterthought here. Here is exactly how it works, with nothing dressed up.

Your files live in Amsterdam

We had a choice about where your files would live, and we did not make it on price. They sit on Backblaze B2, a serious, modern object store, in a data centre in Amsterdam — which is to say in Europe, where a European studio’s work belongs and where, under our hand, it stays. We pin the region deliberately, so your files are never shuttled across an ocean to wherever capacity happens to be cheapest that week; they stay put, in a jurisdiction you can name.

The store is built to keep your bytes intact across its own infrastructure, without you ever having to think about it, and we chose the home we would happily trust with our own work before we put yours there. The same instinct that makes us fuss over a single dropdown made us fuss over this.

Our own AI, that trains on nothing

To make your files findable, Spaces does a little quiet work on each one — lifting the key facts from a document, a date, an invoice number, who it is from, much as a receipts app reads the total off a receipt, and describing what is in a photo so that months later you can search for it by what you saw. That work is done by our own AI — and we mean that more literally than most. When a product says “our AI”, it usually means one of the big names in a thin shell, your files forwarded off to be read by someone else’s machine. Ours is an open model, one we host and run ourselves. Your work never trains a model, ours or anyone else’s; it is not mined, not profiled, and not sold. It is looked at to be useful to you, the once, and then forgotten.

Owning the model is what lets us promise that your files are here to serve you and only you — never someone’s training data, never someone’s advertising. The privacy comes from how the thing is built, not from a line in a policy.

Encrypted, coming and going

Everything travels to and from Spaces over TLS, so the connection between your machine and your files is always encrypted. At rest, the store encrypts every object it holds. Downloads and previews are served through short-lived, signed links that expire on their own, never through public URLs that linger.

Access that follows how you delegate

Permissions are built around how studios hand work around, not around an org chart. Clients see what they were sent, freelancers see what they were brought on for, and account leads see everything. A whole area can be sealed to its owner alone, invisible to the rest of the team, for the work that is not for the room. Share links are long, unguessable capabilities you can revoke at any moment, and a link can be set to expire on a date you choose — after which it goes fully dark.

And for the material where a forwarded URL would genuinely hurt, a share can carry a guest list. The people you name prove their email once with a six-digit code; anyone else holding the same URL meets a calm page with no filename, no preview and nothing to request; and because the list is checked on every request, removing a name shuts that person out on their next click. One boundary no tool escapes, and we will say it plainly: once someone you named has downloaded a file, what they do with it afterwards is beyond any gate.

Score whatever you use today

Ten checks, whatever you currently share files with — a drive, a transfer tool, email. Count the yeses.

  1. Files are encrypted in transit and at rest.
  2. Download URLs are short-lived and signed, never permanent public links.
  3. An outside person can open a share without creating an account.
  4. A share can be limited to a named list of people, each one verified.
  5. Removing someone from that list takes effect on their next request.
  6. An expiry date can be set on any share, and an expired link goes fully dark.
  7. Any link can be revoked in one action.
  8. Who uploaded, moved, shared and deleted what is still answerable months later.
  9. You know which country your files sit in, and it does not move.
  10. An internal comment can never surface on an external share.

Eight or more and your effort belongs in habits rather than tooling. Five to seven, the gaps are usually expiry and the audit trail — the two that matter in a dispute. Under five, you are relying on a policy where you needed a control. Spaces answers yes to all ten, and every mechanism behind those answers is described on this page.

A trail you can read back

Every meaningful action — an upload, a move, a share, a deletion — leaves a record, so a year later the question of who did what, and when, has an answer instead of a shrug. And nothing is lost to a slip of the hand: anything deleted, file or folder, moves to a recoverable trash and can be restored for thirty days before it is purged for good.

Privacy and GDPR

We are GDPR-compliant and act as your data processor, under a Data Processing Agreement that sets out exactly what we may and may not do with your files. We keep the list of sub-processors short and documented, and the full detail lives on the privacy and DPA pages, where it belongs.

Honest about where we are

We are a small, careful team, and we would rather tell you the truth than wave a wall of badges at you. What is written above is real and in place today. The formal certifications that larger buyers eventually ask for — the audits and the acronyms — are on the road ahead as we grow into them, not claimed before their time. If you have a specific requirement, write to us and we will give you a straight answer.

Questions a checklist can’t answer?

Email hello@vidualspaces.com and a person will reply. And if you are weighing the whole move, the practical case is on cloud storage for small business.