A design-and-fabrication studio was emailing drawings back and forth — losing versions, leaking previews. I built a proper vault, locked by project, opened only by the right role.
A design-and-fabrication studio was managing sensitive client work over email. Design files, fabrication drawings, quotes — sent as attachments between designers, the fabrication team, and sales.
Two failure modes were happening regularly:
Kitchen_Final.pdf, Kitchen_Final_v2.pdf, and Kitchen_Final_v2_REALLY_FINAL.pdf were all floating in different inboxes. Fabrication built against the wrong one twice in six months.They needed a real vault. One place per project, locked by role, with an audit trail that could prove exactly who saw what and when.
Getting encryption right without wrecking usability. End-to-end encryption is easy to say, hard to make usable. The classic failure mode is “user forgets password → files lost forever.” I solved it with owner-held recovery keys stored in KMS. Recovery is possible via an owner-approval flow, but not via a support ticket. The studio owner has real power; support staff (none by design) don't.
The hash-chained audit log. Each entry stores prev_hash — the SHA-256 of the previous entry. Every hour a background job publishes the latest chain head to a separate KMS-signed record. Editing any historical entry breaks the chain from that point forward, and the tampered chain won't match the last signed head.
MIME confusion attacks. Users claim to upload PDFs, sometimes it's actually an executable renamed to .pdf (accident or attack). I inspect the file's actual magic bytes, not the extension or client-provided MIME type. Mismatches get rejected at the quarantine stage.
AWS WAF for a public-facing internal tool. The vault is only used internally but is publicly reachable (staff work from anywhere). WAF handles the OWASP baseline — rate limits, geo-blocking to allowed regions, bot detection — before requests even reach the app.
Encrypted end-to-end · audit-ready. Emails stopped being the file-transfer mechanism for sensitive design work. Version confusion dropped to zero — there's exactly one place a file lives, and its version history is visible.
The audit log has been useful exactly once: an ex-contractor was suspected of reusing designs elsewhere; the log showed no download post-termination — cleared them. That single use paid for the whole system.
Should've invested earlier in per-file preview generation. Right now, viewing a file requires downloading it (watermarked). A server-side preview generator that renders sanitized previews without requiring download would be safer and faster for casual viewing.
Security-critical internal tools are usually built as “secure enough” — role-based auth on top of a normal file store, with the encryption story being whatever AWS gives you by default. Fine for most companies. For clients with genuinely proprietary designs, that's not enough. Application-layer encryption the operator can't undo has a real engineering cost, but the trust it earns is disproportionate.