Security White Paper

Security White Paper - Orangedox Blog Post

Orangedox helps our customer secure their documents, allowing them to be confident that only the intended recipient gains access. However, is it ok to trust Orangedox with your confidential documents? And what measures does Orangedox employ to ensure their platform is safe?

How safe is Orangedox?

Entrusting an online service with your confidential files is a decision that shouldn’t be taken lightly. To that point here’s a list of the security best practices that Orangedox employs to help secure your confidential files on our platform.

Access Tokens

Orangedox integrates directly with your cloud storage provider, either Google Drive or Dropbox. Doing so allows Orangedox to pull files directly from your cloud storage provider, allowing you to update your shared files without having to re-upload them. However, this does require that Orangedox has continued access to your cloud storage account. This is done with OAuth Access Tokens that Orangedox stores and uses to gain access to your account. These access tokens are encrypted by Orangedox using 256-bit Advanced Encryption Standard (AES-256) then stored on Amazon AWS. At no time does any internal employee at Orangedox have access to unencrypted access tokens. 

Only Previewed Files are stored by Orangedox

Unlike similar document protection services Orangedox doesn’t store every file that you share with our service. Instead we integrate with your cloud storage service, either Google Drive or Dropbox, and whenever someone downloads a file shared via Orangedox it comes directly from your cloud storage provider. At no time does Orangedox cache or store this file.  

However there is an exception, any file that Orangedox generates a preview for (see the full list here of supported file types) will be stored on our servers. This is required so that Orangedox can provide a web preview of your file online and we will call these files “Previewed Files”  

Previewed Files Encryption

All previewed files are stored on Amazon’s S3 and are encrypted with 256-bit Advanced Encryption Standard (AES-256).  

Access to Previewed Files

Previewed files are not accessible by internal Orangedox employees, and only designed security engineer(s) are granted access in one of the following scenarios 

⦁ to verify that the file does not violate our Terms of Service: Acceptable Use Policy

⦁ to debug an issue with the previewed file at the customer’s request

Removal of Previewed Files

Orangedox does not keep previewed files indefinitely, periodically we clean out old versions of previewed files that are not currently shared.

If you have any questions on how we handle our customers data please reach our security team at support@orangedox.com

 -------------------------------------

Orangedox lets you securely share your Google Drive documents. Never worry again about your confidential documents getting into the wrong hands. Prevent document forwarding and disable access at any time.


Keep Reading

Virtual Data Rooms in M&A: A Complete Guide Image
Virtual Data Rooms in M&A: A Complete Guide
Facilitate secure M&A transactions with Virtual Data Rooms. Learn how VDRs protect critical informat...
Chad Brown
Chad Brown
14 min read
Securing Your Deals: Is Password Protection Enough? Image
Securing Your Deals: Is Password Protection Enough?
Is password protection enough? Explore modern strategies for safeguarding sensitive deal documents b...
Chad Brown
Chad Brown
7 min read
What are Virtual Data Rooms? Image
What are Virtual Data Rooms?
Discover virtual data rooms, what they are, who uses them and what features you should expect when p...
Chad Brown
Chad Brown
11 min read
Close Deals with Google Drive Virtual Data Rooms Image
Close Deals with Google Drive Virtual Data Rooms
Close deals faster by leveraging technology. See how using a Virtual Data Room with Google Drive sim...
Chad Brown
Chad Brown
7 min read
5 Successful Startup Pitch Decks and Why They Work Image
5 Successful Startup Pitch Decks and Why They Work
Need pitch inspiration? Analyze 5 successful startup pitch decks that unlocked funding. Learn how to...
Chad Brown
Chad Brown
11 min read
What to Include in Your Data Room for Investors? Image
What to Include in Your Data Room for Investors?
Secure startup funding with an Investor Data Room. Efficiently share and track confidential document...
Chad Brown
Chad Brown
8 min read
What Is Document Watermarking? Image
What Is Document Watermarking?
Learn what watermarking is, how static, dynamic, and invisible watermarks work, and why businesses u...
Chad Brown
Chad Brown
11 min read
Document Tracking 101 with Orangedox Image
Document Tracking 101 with Orangedox
Sharing a document is only half the story. The other half? Knowing what happens after you hit send. ...
Chad Brown
Chad Brown
7 min read
How do you pitch to Investors? Image
How do you pitch to Investors?
Pitching to investors? Learn how to capture attention fast, tell a compelling story, and use secure ...
Chad Brown
Chad Brown
7 min read
How to Send Large Files through Gmail Using Google Drive Image
How to Send Large Files through Gmail Using Google Drive
Bypass Gmail size limits. Learn how to easily share large files using Google Drive and Orangedox wit...
Chad Brown
Chad Brown
6 min read