Product
Storage
Generated documents have to go somewhere. That somewhere can be your own bucket, which means the files stay under your account and your retention policy.
Two drivers
| Driver | Where files live | Suits |
|---|---|---|
local | A volume on the app server | Trying things out |
s3 | Your Amazon S3 bucket | Production |
Signed URLs
Documents are not public. Each download link is signed and expires, and the expiry is set per request — a quote link that should die in a week and an invoice link that should last a month are the same call with a different number.
Where a CDN sits in front of the bucket, links can be issued unsigned against the CDN hostname instead, which removes the expiry ceiling that presigning imposes.
Object layout
Files are keyed by workspace, then year and month, then request id:{workspace}/{yyyy}/{mm}/{request_id}.pdf. An optional prefix can be set when the bucket is shared with something else. The layout means a period's output is a single prefix — convenient for lifecycle rules.
Server-side encryption
Uploads to S3 are written with AES256 server-side encryption.
Retention
The app does not delete files. Because the bucket is yours, retention is a lifecycle rule you set on it — which also means nothing here can quietly remove a document you are required to keep.