Dashboard
Overview of your system
What's waiting for you
Favourites
Most recent
My Vaults
Vault Name
| Name | Size | Type | Modified | Modified by | Actions | |
|---|---|---|---|---|---|---|
| Loading files... | ||||||
Vault Details
Storage Usage
Security
Vault Access Control
Whitelist departments and individual users. Everyone else is denied.
Department access
Individual users
| User | Permission Level | Granted | Actions | |
|---|---|---|---|---|
| Loading permissions... | ||||
Vault Information
Security
Danger Zone
Destructive actions that cannot be undone
Notes
Upload links
An upload link lets anyone you share it with send files to you — no account needed. Each link drops uploads into its own dedicated vault that only you can open. Pause a link to stop new uploads without losing what's already in it; revoke it to close it for good.
Temporary Access Credentials
User Management
Groups & Roles
Organize people into departments and review role distribution
Select a department to manage its members, or create a new one.
Live Monitor
Real-time system activity and analytics
Active Users
0
Real-time
Events/Min
0
0 total
Active Sessions
0
No activity
Event Filters
Live Event Stream
0 eventsWaiting for events...
Real-time events will appear here
System Settings
Configure system preferences and policies (Admin Only)
General Configuration
MAX_FILE_SIZE_MB ceiling. Blank = use that ceiling.
Brand Identity
Customize how this instance is named and presented. Changes apply live — no restart. Leave a field blank to fall back to the built-in default. The application name lives on the General tab.
Links
https://, http://, or a site-relative /path is accepted.
Theme Colors
Hex colors (#2563eb or #25f) applied to the interface theme. Blank keeps the default.
Logo & Favicon
Upload a logo and favicon (PNG, JPG, WebP, GIF, ICO or SVG, up to 2 MB). Uploaded assets are stored on the server and survive restarts. Reset restores the built-in default.
Security & Authentication
JWT_ACCESS_TOKEN_EXPIRE_MINUTES. Blank = use the deployment's value.
Login, lockout, vault-unlock, SFTP and API rate limits are configured in Rate limits at the bottom of this tab.
Two-factor authentication (MFA)
Authenticator app (TOTP) only. Email codes are not available yet.
Step-up: actions that require a second factor
Per action, choose whether the user must present their authenticator (OTP) and/or re-enter their password. Turning OTP on for an action requires everyone — admins included — to enroll before performing it.
Toggle the options above, then save once.Rate limits
Each limit shows the read-only deployment value (from the environment / .env) and an optional custom value that overrides it. Tick Override to edit a custom value; untick it to fall back to the deployment value. Use the button to see what a limit does and when it triggers. A blank or out-of-range custom value always falls back to the deployment default — a limit can never be turned off here.
Storage Configuration
Total Storage
-
Used Storage
-
Available
-
Email — Sending profiles
host.docker.internal or the service name), not localhost.Email templates
Automated emails
New template
SFTP Authentication Policy
Members of the selected departments may only authenticate to SFTP with a temporary credential — direct password and SSH-key auth are refused. This is per-department by design, so SSH-key automation in other departments keeps working.
User Directory
Controls the recipient search in the “Grant access” picker. Whole deployment (default) lets a sharer find any active account by username or email. Same department only restricts the search to accounts that share a department with the searcher.
Zero-Knowledge Vaults
When enabled, users can create vaults whose contents are encrypted in the browser — the server stores only opaque ciphertext and can never read them. Zero-knowledge vaults are web-only (they are not exposed over SFTP).
When enabled (and zero-knowledge is allowed above), new vaults must be zero-knowledge — except for members of the exempt departments below, who may still create standard vaults.
When set, the in-browser zero-knowledge key is dropped from memory after this many minutes of inactivity, so the user must re-enter their encryption passphrase to open a zero-knowledge vault again. Independent of the login session timeout.
Temporary Vault Passcodes
When enabled, a temporary credential can carry a short-lived passcode that opens a standard vault in place of its real password — scoped, expiring, revocable, and rate-limited. Passcodes are a standard-vault feature only; zero-knowledge vaults never get a passcode (their contents are decryptable only with the account passphrase). Leave off to keep today’s behavior (a holder must know the real vault password).
A one-time passcode is burned after a single redemption (safest for untrusted devices / break-glass). Multi-use can still be chosen per passcode at mint time.
Forbid one passcode from spanning multiple vaults in a batch mint.
When off, passcodes are always system-generated at high entropy (strongest against offline cracking). When on, a minter may type a custom passcode that must satisfy the complexity policy below.
At least 8. Applies to custom passcodes and sets the length of generated ones.
The most simultaneously-active temporary credentials one account may hold (all temporary credentials, not only passcode-protected ones). Defaults to 10; blank = unlimited.
Requirements a custom passcode must meet (generated passcodes are always high-entropy). Tuned separately from the account-password policy.
Optional ceiling on how long a passcode stays valid; it never exceeds the temporary credential’s own lifetime.
On by default. A temporary credential may include a zero-knowledge vault, but the holder must still enter the real account passphrase to decrypt it (no passcode is available for ZK vaults). Turn this off to forbid ZK vaults in temporary credentials entirely.
Vault Password Handling
When enabled, every vault’s unlock window is forced to 0 deployment-wide — a user must re-enter a vault’s password each time it is opened, and the per-user “remember” preference is locked on. Use for shared or untrusted devices. Leave off to let each vault keep its own unlock window.
Sharing
When enabled, users may share a file, folder, or whole standard vault with other authenticated members of this deployment, governed by the tags below. Sharing is never anonymous — every recipient must sign in. Leave off to disable sharing entirely.
Share Tags
A tag classifies a share and carries its policy (how long it lasts, how many recipients/downloads, which audiences, whether view-only) plus a create-allowlist controlling who may create shares with it. Deactivating a tag stops new shares under it; existing shares keep the limits they were created with.
Notes
The largest a single note's text may be (100–1,000,000). Applies to all notes.
Public note links
When enabled, users may turn a note into a shareable link that anyone with the link can open (no sign-in). Each link is a snapshot — later edits don't change what a link shows — governed by the tags below. Turning this off immediately pauses every public link (they stop opening) but does not delete them — turn it back on and they work again. To permanently stop links, revoke them under "All public links" below (per link, or "Revoke all active"). Internal member-to-member sharing is unaffected.
An anti-abuse cap on how many active public links one user may hold.
Public file & folder links
When enabled, a user can turn a file or folder in a Standard vault into a link that anyone can download from (no sign-in). Unlike note links these serve the live file, not a snapshot. They are governed by the same tags below — a tag only offers file/folder links when its "Can be used for" list includes them — and share the same per-user cap as note links. Turning this off immediately pauses every public file link (they stop opening) without deleting them; revoke them under "All public file & folder links" below to stop them permanently.
Link tags
A tag is a security floor for a link (token length, expiry, whether a password/PIN is required, how many views) and controls what it can link to (notes, files, and/or folders). A user creating a link may only make it stronger than its tag, never weaker. Deactivating a tag stops new links under it; existing links keep the policy they were created with. Granular per-user/per-department allowlists are managed via the API for now.
All public note links
Every public note link across all users. Revoke any link (or all active links at once) without turning the whole feature off. Snapshots are not shown here.
All public file & folder links
Every public file/folder link across all users. Revoke any link (or all active links at once) without turning the whole feature off.
Upload links
When enabled, a user can create a link that lets anyone (no sign-in) upload files into a new, dedicated vault that only that user can open. Links are governed by the tags below. Turning this off immediately pauses every upload link (they stop accepting uploads) without deleting anything; revoke a link under "All upload links" below to close it permanently.
An anti-abuse cap on how many active upload links one user may hold.
Upload-link tags
A tag is a security floor for an upload link (link length, expiry, whether a password/PIN is required, how many files, size limits, retention). A user creating a link may only make it stronger than its tag, never weaker. Deactivating a tag stops new links under it; existing links keep their policy.
All upload links
Every upload link across all users. Revoke any link to close it (the received files stay in its vault).
Account onboarding
When on, an administrator can generate an invitation link for a new account. No email is sent — you copy the link and share it. Off by default.
When on, a visitor can create their own account from the login screen. Off by default.
Invitations
How long an invitation link stays valid — from 1 hour to 720 (30 days).
Self-signup
Restrict which email domains may sign up or accept an invitation.
Type a domain (without the “@”) and press Add. Domains are lowercased and de-duplicated.
Identity & email
Applies the same way to admin-created accounts, invitations, and self-signup.
What people type to sign in. “Email only” is refused only if it would lock out every administrator; anyone without an email is warned below.
A user changing their own email must confirm a one-time code sent to the new address; administrators setting an email are exempt. Requires email (SMTP) to be configured — set it up on the Email tab first.
How long the email-change verification code stays valid — from 1 to 60 minutes.
Password reset
When on, a “Forgot password?” link appears on the sign-in screen and emails a one-time reset link. An administrator can always send a reset link from the Users page, regardless of this switch. Off by default. Requires email (SMTP) configured.
How long a password-reset link stays valid — from 1 to 60 minutes.
What this means right now
—
Audit Log Filters
Audit Log Entries
0 entries| Timestamp | User | Action | Status | IP Address | Details |
|---|---|---|---|---|---|
| Click "Search" to load audit log entries | |||||
Log access
Pull this deployment's container logs into your own
monitoring system via an authenticated endpoint
(GET /logs). Off by default — enable a
component below and mint a scoped token. The token is shown
once; only its hash is stored.
When on, an unauthenticated or invalid request to
/logs returns 404 instead of
401, so the endpoint is undetectable without a
valid token. Leave off if a monitoring system needs the
standard “unauthorized” response.