Product

Storage

Generated documents have to go somewhere. That somewhere can be your own bucket, which means the files stay under your account and your retention policy.

Two drivers

DriverWhere files liveSuits
localA volume on the app serverTrying things out
s3Your Amazon S3 bucketProduction

Signed URLs

Documents are not public. Each download link is signed and expires, and the expiry is set per request — a quote link that should die in a week and an invoice link that should last a month are the same call with a different number.

Where a CDN sits in front of the bucket, links can be issued unsigned against the CDN hostname instead, which removes the expiry ceiling that presigning imposes.

Object layout

Files are keyed by workspace, then year and month, then request id:{workspace}/{yyyy}/{mm}/{request_id}.pdf. An optional prefix can be set when the bucket is shared with something else. The layout means a period's output is a single prefix — convenient for lifecycle rules.

Server-side encryption

Uploads to S3 are written with AES256 server-side encryption.

Retention

The app does not delete files. Because the bucket is yours, retention is a lifecycle rule you set on it — which also means nothing here can quietly remove a document you are required to keep.