Skip to content

Security & privacy

Private by design, not by promise

Here is exactly how My Object protects your files — whether you’re a member or just using the free tools.

Self-hosted No third-party AI Free-tool files deleted in 30 min Audit trail

Your data stays on our servers

My Object is self-hosted. There is no public cloud storage provider and no outside AI company in the path of your files.

  • Files, the database and backups live on infrastructure we operate
  • Files are stored under random IDs — original file names are never used on disk
  • A SHA-256 checksum is kept for every file to detect corruption or tampering
  • All traffic is served over HTTPS

Free tools: temporary by design

Nothing you upload to the free tools is kept or reused.

  • Each task runs in its own temporary folder with a random job ID
  • Uploads are deleted as soon as processing finishes
  • Results are deleted after 30 minutes — or straight away with “Delete now”
  • Never stored in anyone’s Drive, never used to train AI, never sent to third parties
  • Processing uses open-source programs running on our own server
  • Usage is counted anonymously: which tool, how many files and how large — never names or contents

Least-privilege access

People only see what they’ve been given, and can only do what their role allows.

  • Company-wide roles with an editable permission matrix
  • Per-bucket membership: Owner, Editor or Viewer
  • Access is checked on every request, not just in the interface
  • Admins can deactivate accounts and reset passwords instantly

Accounts, sessions & keys

Credentials are never stored in a readable form.

  • Passwords are hashed with bcrypt
  • API keys are stored only as SHA-256 hashes and shown once when created
  • API keys can be limited to specific buckets and to read-only access, and can expire
  • Short-lived sign-in tokens with refresh; changing your password signs out other sessions

Sharing you stay in control of

Every link can be as narrow as you need.

  • Temporary links with password, expiry, download limit or single use
  • Links stop working automatically when they expire or reach their limit
  • Public folders are read-only
  • Sharing activity is recorded in the activity log

Signatures with evidence

Every signed document carries a record of how it was signed.

  • The document is frozen when sent — later edits can’t change what was signed
  • Optional 6-digit email code before a signer can open anything
  • Certificate with signer IP, device, browser, time zone and timestamps
  • SHA-256 fingerprint of the original and a complete audit trail

AI that never leaves the building

AI features are optional and run on a model hosted by us.

  • Off by default — each bucket owner decides whether to turn it on
  • Documents are read by our own Ollama model, not an outside AI service
  • Only extracted details (title, dates, keywords…) are stored alongside the file

Hardened application

Standard protections are switched on for every request.

  • Security headers (Helmet) and rate limiting on sign-in and public endpoints
  • Strict validation of every input; protection against path traversal
  • File name sanitisation on upload
  • Activity and audit logs with IP address, operating system and browser

My Object’s e-signatures are electronic signatures with an audit trail, like the standard signature in most e-sign tools. They are not certificate-based (PKI) digital signatures.