Overview
This article explains how documents are handled within the Onefile platform and outlines the safety measures in place to protect users and their files.
Onefile provides a secure environment for storing and transferring documents. It is intentionally designed to act as a secure repository and does not read, analyse, or alter the informational content of any file uploaded by a user.
How Onefile Handles Uploaded Documents
Zero-Interference
When a user uploads or downloads a document through Onefile:
- The platform does not open or inspect the data contained within the file.
- The platform does not modify or alter the file in any way.
- Files pass through the system exactly as they are provided by the user.
Secure Transfer
All document transfers are protected using encrypted connections, ensuring files remain secure and private during transit.
File Validation and Allowed Formats
To maintain security without compromising privacy, Onefile uses Structural Validation rather than content scanning.
- Broad Compatibility: The platform supports a comprehensive list of file types designed to meet the diverse evidence requirements of our customers (spanning standard office documents, design files, media, and technical formats).
- Blocking Executables: To protect the platform, we enforce a strict block on system executables (such as .exe files). This prevents the upload of software that could run commands on a device.
- MIME-Type Validation: Upon upload, the system validates the file's technical signature (MIME-type). This checks the true identity of the file to ensure it is not a disguised executable.
This approach allows users to upload the necessary evidence formats they need, without the platform ever "running" a program or accessing the data inside.
Virus and Malware Protection
Because Onefile does not process the contents of files, it does not perform server-side virus or malware scanning. Instead, security is managed at the endpoint:
- Endpoint Scanning: Any virus or malware detection is performed by the antivirus software on the user’s own device (laptop, tablet, etc.).
- Passive Storage: The platform stores the file inertly; it does not "run" files.
- No Interference: This approach ensures that Onefile remains a neutral, secure storage environment and never interferes with customer data.
User Responsibilities (Terms & Conditions)
The Onefile Terms & Conditions outline clear expectations for maintaining this secure environment.
Relevant sections include:
- 4.4 - Acceptable Content: Users must not upload anything obscene, offensive, unlawful, or damaging to data, the software, or the performance of any computer system.
- 4.6 - Software Integrity: Users must not tamper with the software in any way, including by introducing malicious code.
Guidance for Users on Personal Devices If a user or assessor is accessing Onefile via a personal device:
- They must ensure their local antivirus software is installed and up to date.
- Their local software will automatically scan files as they are downloaded or opened.
- No additional scanning occurs within the Onefile cloud environment.
❓Need Help?
If you encounter any issues or have questions, please contact Onefile Support or your internal support channels.