Security at PaperlessZen™
Security, for a document system, comes down to three questions. Who can see this? Who has seen it? And if I need to, can I take access back? A system of record for gift agreements, board minutes, and confidential contracts has to answer all three without hedging.
Here is how PaperlessZen™ answers them, and what is actually enforced rather than promised.
Access is granted, not assumed
Access to documents is role-based. People see what their role allows and nothing more. The most sensitive actions, the ones that change what a document is or how long it lives, are held behind a separate governance permission, so setting a retention schedule or placing a legal hold is not something an ordinary account can do by accident. Sensitive by default is the posture: a document is visible to the people who need it and closed to everyone else.
Files are reached through short-lived, signed links
Even inside the system, the underlying file is never a plain, permanent URL sitting on the open web. When a document is opened or downloaded, PaperlessZen generates a signed link that works for a short window and then stops working. A URL that leaks from a browser history or a forwarded message is not a standing door into your archive. It expires.
External sharing you can prove and revoke
Sharing a confidential agreement outside the institution is where most document leaks actually happen, so it is where PaperlessZen is strictest.
Create
A single-use token is bound to one document. The raw token is shown once, at creation, and never again.
Use
The recipient's token resolves to a short-lived download link, not to permanent access.
Expire
The download link stops working when its window closes.
Revoke
You can invalidate the token at any moment, and the share is closed.
Create
A single-use token is bound to one document. The raw token is shown once, at creation, and never again.
Use
The recipient's token resolves to a short-lived download link, not to permanent access.
Expire
The download link stops working when its window closes.
Revoke
You can invalidate the token at any moment, and the share is closed.
If you are not sure whether a link is still out there, you do not have to wonder. You revoke it, and it is closed.
This is the honest version of “secure sharing.” Not a password taped to an email, but a token you control from the moment it exists to the moment you shut it off.
Nothing is deleted by accident
An archive people trust is one where things do not quietly vanish. PaperlessZen treats deletion as reversible and governance as final.
Records can be locked to a retention schedule, so they live exactly as long as your policy says and no less. When a matter requires it, a legal hold freezes a document in place and overrides any retention or deletion until the hold is lifted. And even an ordinary delete is a soft-delete: the underlying file is kept, not destroyed. The result is an archive where “we lost it” and “someone deleted it” stop being things you have to fear.
A complete audit trail
Every view, every share, and every download is recorded. When someone asks who accessed a document, when, and under what authority, the answer is a record you can produce, not a reconstruction from memory. For institutions that get audited, or that simply need to show a board or a family that a confidential file was handled properly, that trail is the difference between a calm answer and a scramble.
It runs in your cloud, not ours
PaperlessZen is deployed into your institution’s own cloud subscription. Your documents are stored on infrastructure you already own and govern, under the enterprise agreement, encryption, and data residency controls you already have with your provider. They never leave your environment, and they are never commingled with another organization’s archive, because no other organization is there.
Microsoft Azure is our preferred and most developed platform. If your institution runs on AWS, Google Cloud, or another provider, we will work with your team to deploy there. Either way, the answer to “where do our documents live” is the same: in your cloud, under your control. You are the custodian. We provide the product.
What is enforced today
Everything above is live in the product now, not on a roadmap slide.
Enforced today
Deployment into your own cloud subscription, so your documents never leave your environment.
Role-based access, with governance actions behind a separate permission.
Files served through signed links that expire after a short window.
External shares as single-use tokens you can revoke immediately.
Retention schedules and legal holds that override deletion.
Soft-delete, so an ordinary delete keeps the underlying file.
A complete audit trail of every view, share, and download.
Straight talk about beta
PaperlessZen is an early-beta product, and we would rather be clear than impressive. Everything on this page is enforced today. During beta, every deployment runs in the customer’s own cloud, which means the hosting questions a security review opens with are answered by your own environment: your provider, your region, your encryption keys, your agreements. The questions that remain, our software practices, our release process, and our roadmap toward formal certifications, we are glad to cover directly with your team, and we will be honest about what is in place now versus what is planned. If your institution has a security questionnaire, send it. We will answer it plainly.
Want to see the controls in action, or hand us your requirements? Book a demo and bring your security team. You can also read how a document moves through the system end to end.
Frequently asked questions
Who can see our documents?
Only the people you grant access to. Access is role-based, and sensitive governance actions like changing a retention schedule or placing a legal hold are gated behind a separate permission. Your documents live in your institution's own cloud subscription, never mixed with another organization's.
Where does PaperlessZen run?
In your cloud, not ours. We deploy PaperlessZen into your institution's own cloud subscription, so your documents never leave your environment. Microsoft Azure is our preferred and most developed platform, and we can work with your team on AWS, Google Cloud, or another provider you already run.
Can we take back access to something we shared externally?
Yes, immediately. External shares use a single-use token that resolves to a short-lived download link. Revoking a share invalidates its token at once, so a link that was appropriate last week can be shut off the moment it is not.
What stops a document from being deleted by accident?
Records can be locked to a retention schedule and placed under a legal hold, both of which override deletion. Even a delete is a soft-delete: the underlying file is retained, not destroyed, so nothing important disappears on a misclick.
Do you have formal security certifications?
PaperlessZen is in early beta. The controls described on this page are live today. Because the system runs in your own cloud subscription, the infrastructure sits under your existing provider agreements and their certifications; our software and our practices are what your review needs to examine, and we will walk your security team through both plainly, what exists now and what is planned.