How BucketDesk protects your files.
Last updated October 5, 2026
BucketDesk is a workspace for files that stay in your own Amazon S3 buckets. This page describes how access works and what we do to keep it safe. For questions or a completed security questionnaire, email hello@bucketdesk.com.
Your files stay in your bucket
- BucketDesk does not keep copies of your files. Previews and downloads stream from your bucket when you open them.
- Microsoft Office previews use a temporary copy in Microsoft 365. It is permanently deleted within 24 hours.
- Document AI runs on Amazon Bedrock in your own AWS account, through a separate role you create, and only on files you ask about. BucketDesk does not index your bucket.
Access to your AWS account
- You connect through an IAM role you create with our CloudFormation template. No access keys are shared, and you can revoke the role at any time.
- Every connection has its own external ID, and BucketDesk only ever holds short-lived credentials that expire within an hour.
- The default role is read-only and can be limited to one bucket prefix. Uploads, deletes and other write actions work only after you switch them on.
- BucketDesk refuses connections to roles in its own AWS accounts, so one customer cannot point BucketDesk at another’s resources.
Accounts and workspaces
- Sign in with a password, a passkey, or an authenticator app. Two-factor authentication is required for workspace owners and admins from October 20, 2026.
- Workspace roles control who can view, operate, share and administer. Viewers cannot create share links or upload.
- Removing a member immediately revokes their share links, API tokens and AI assistant connections. Changing a password signs out other sessions, API tokens and AI connections.
- API tokens always expire, within a year at most. AI assistant access tokens last one hour.
- Views, shares, deletes and administrative changes are recorded in the workspace activity log.
Encryption
- All traffic uses TLS 1.2 or 1.3; older protocols are refused.
- Our database and backups are encrypted at rest. File names in notifications and activity details, connection secrets and document chats are encrypted again by the application. Tokens are stored only as one-way hashes.
Infrastructure and operations
- BucketDesk runs on AWS in the United States (us-east-1). The database sits in private subnets with no public access.
- Every change goes through code review, an automated test suite and a dependency audit that blocks releases with known high or critical vulnerabilities. Changes reach a separate staging account before production.
- The app runs only scripts it serves itself, enforced by a strict Content-Security-Policy.
- AWS CloudTrail records account activity, GuardDuty watches for threats, and alerts reach us by email.
- Application logs record request paths without query strings, so share tokens and search terms are not logged.
- The database has seven days of point-in-time recovery, plus a daily copy in a separate AWS account that cannot be deleted for its retention period.
Service providers
Amazon Web Services (hosting, email, Bedrock), Microsoft (Office previews), Stripe (payments) and Google (analytics, with your consent for cookies). See the privacy notice for details.
Compliance
BucketDesk follows written security procedures for access reviews, change management, incident response, backups and vendor review. We do not yet hold a SOC 2 report or other third-party certification. If your review requires one, tell us; we can answer your questionnaire and share more detail under NDA.
Report a vulnerability
Email hello@bucketdesk.com with “Security report” in the subject line. Include the steps to reproduce and what an attacker could gain. Please do not access other customers’ data or disrupt the service while testing. Our security.txt has the same details.