Security & privacy
Private by design, not by promise
Here is exactly how My Object protects your files — whether you’re a member or just using the free tools.
Your data stays on our servers
My Object is self-hosted. There is no public cloud storage provider and no outside AI company in the path of your files.
- Files, the database and backups live on infrastructure we operate
- Files are stored under random IDs — original file names are never used on disk
- A SHA-256 checksum is kept for every file to detect corruption or tampering
- All traffic is served over HTTPS
Free tools: temporary by design
Nothing you upload to the free tools is kept or reused.
- Each task runs in its own temporary folder with a random job ID
- Uploads are deleted as soon as processing finishes
- Results are deleted after 30 minutes — or straight away with “Delete now”
- Never stored in anyone’s Drive, never used to train AI, never sent to third parties
- Processing uses open-source programs running on our own server
- Usage is counted anonymously: which tool, how many files and how large — never names or contents
Least-privilege access
People only see what they’ve been given, and can only do what their role allows.
- Company-wide roles with an editable permission matrix
- Per-bucket membership: Owner, Editor or Viewer
- Access is checked on every request, not just in the interface
- Admins can deactivate accounts and reset passwords instantly
Accounts, sessions & keys
Credentials are never stored in a readable form.
- Passwords are hashed with bcrypt
- API keys are stored only as SHA-256 hashes and shown once when created
- API keys can be limited to specific buckets and to read-only access, and can expire
- Short-lived sign-in tokens with refresh; changing your password signs out other sessions
Sharing you stay in control of
Every link can be as narrow as you need.
- Temporary links with password, expiry, download limit or single use
- Links stop working automatically when they expire or reach their limit
- Public folders are read-only
- Sharing activity is recorded in the activity log
Signatures with evidence
Every signed document carries a record of how it was signed.
- The document is frozen when sent — later edits can’t change what was signed
- Optional 6-digit email code before a signer can open anything
- Certificate with signer IP, device, browser, time zone and timestamps
- SHA-256 fingerprint of the original and a complete audit trail
AI that never leaves the building
AI features are optional and run on a model hosted by us.
- Off by default — each bucket owner decides whether to turn it on
- Documents are read by our own Ollama model, not an outside AI service
- Only extracted details (title, dates, keywords…) are stored alongside the file
Hardened application
Standard protections are switched on for every request.
- Security headers (Helmet) and rate limiting on sign-in and public endpoints
- Strict validation of every input; protection against path traversal
- File name sanitisation on upload
- Activity and audit logs with IP address, operating system and browser
My Object’s e-signatures are electronic signatures with an audit trail, like the standard signature in most e-sign tools. They are not certificate-based (PKI) digital signatures.
Keep your documents where you can see them
Sign in to your private workspace, or use the free tools with nothing to sign up for.