Every row carries its workspace
Tenant scoping is applied by the database layer itself rather than remembered at each query, and one workspace reading another’s rows is asserted against a real database in the test suite.
Workspace isolation, upload scanning, signed file links and the audit log are on every plan including Free. Putting any of them behind a price would make the cheap tier the unsafe one — which is bad selling, and true of whatever ships it.
Each one answers a different question, and they run in this order — because these files are served back to other people in the workspace.
The declared content type is ignored. A file is identified from its magic bytes, and an Office document is recognised by parsing its ZIP directory — never by decompressing it.
A package carrying a VBA project or an Excel 4.0 macro sheet is refused. A macro-enabled file renamed to .xlsx is structurally valid, so this is the gate that catches it.
The bytes are streamed to a malware scanner before they reach storage, so an infected file never becomes an object. If the scanner is unreachable the upload is refused — an outage must not quietly become a bypass.
SVG is excluded deliberately. It is an image that can carry script, and these files are shown to colleagues.
Tenant scoping is applied by the database layer itself rather than remembered at each query, and one workspace reading another’s rows is asserted against a real database in the test suite.
Access tokens carry an identity, never a permission list. Revoking a role takes effect on the next request instead of whenever a token happens to expire.
Presenting a token that has already been rotated revokes the whole family. The forced re-login is the intended outcome.
The bucket is not public. Reads go through short-lived signed links minted per request, so revoking access is a database change rather than a file move.
No updates, no deletes. A smaller plan sees a shorter window of history — the rows themselves are never removed.
Google sign-in and passkeys. Users are provisioned by invitation; signing in with an unknown address is refused rather than silently creating an account.
There is no impersonation. Support cannot log in as you. If seeing a workspace ever becomes genuinely necessary, that belongs behind a time-boxed grant the customer starts and sees in their own audit log — not behind an operator's convenience.
And there is no cross-workspace search. Operating the platform needs to know how much there is and whether it is healthy; none of that requires reading anyone's tasks. Every operator query returns counts and structural columns, and a test asserts against a real database that no text a customer typed appears in an operator's response.
The demo includes the audit trail. Move a card, approve a week, then read back exactly what was recorded about it.
Try the live demo