Your brand and your rules
Security & governance
Two-factor and passkeys, sessions, roles and folder access, policies such as legal hold, single sign-on, admin scopes, audit exports, SIEM and IP allow-lists.
Updated 2026-09-21
Your account#
- Passwords are 12 to 256 characters and stored with a modern password hash. Changing yours needs the current one and signs out every other session; Forgot password sends a 6-digit code and signs out everywhere. Either way you get an email.
- Two-factor authentication (Security page) uses an authenticator app. Enrol by scanning the QR code and entering the first code; you get ten recovery codes of the form
xxxxx-xxxxx, shown once — each is single-use, and you can regenerate the set with a current code. Turning it off needs your password and a code. Staff accounts must have it on. - Passkeys — up to ten per account, registered from a signed-in session; sign in without typing an email. A passkey sign-in counts as two-factor.
- Sessions & devices lists every sign-in with the device, a hashed hint of the address (never the address itself), whether it was two-factor verified, when it was last seen and when it expires (30 days from sign-in). Revoke one, or Sign out every other device. API keys cannot manage sessions or change passwords.
Roles, groups and folder access#
Four roles: owner (one per workspace; ownership is transferred, not granted), admin, member and guest. Members upload, share and run portals; guests see what they are allowed to and download where permitted. Every write needs a verified email.
Groups (Members page, admins) collect people; folder access grants a level on a path to a person or a group: none < view < download < upload < manage. The most specific path wins, and a tie takes the higher level. Without a rule, members get manage and guests view — both defaults can be changed for the workspace. Owners and admins always have manage. Search results and listings respect these rules.
Workspace policies#
Under Security (admins; some owner-only):
| Policy | Effect |
|---|---|
| Legal hold (owner) | Nothing can be deleted permanently — trash is not emptied, versions are kept, send-mode links do not delete their files — until it is lifted. The reason is recorded. |
| Require a password on every link | Pro and above. |
| Maximum link retention | 1 to 3,650 days, never above the plan's ceiling. |
| Checksum policy | SHA-256 (default) or SHA-512, recorded per file on arrival and shown on receipts. |
| Trash and versions | Retention in days (never above the plan), whether previous versions are kept, and for how long. |
| Bandwidth windows | Cap transfers during office hours, per weekday and time range, in the workspace time zone. |
| Daily digest | Per person: a daily summary email of the workspace's activity, or off. |
Activity and audit#
Activity shows every action — transfers, share links and portals, files and folders, members and access, security and developers, plan and storage — with who did it and when, filterable by person and category. The same trail backs the audit exports below.
Enterprise controls#
Included with the Enterprise plan:
- Single sign-on — OpenID Connect with PKCE, one provider per workspace routed by email domain. Options: the domains it covers, whether it is enforced (password sign-in refused for those domains), the default role for new people, and on/off. People are created on first sign-in; your identity provider owns the second factor.
- Admin scopes — split what admins can do: billing (plan, invoices, payment), members (invite, remove, roles), security (policies, SSO, sessions, exports, SIEM) and content (empty the trash, delete for good). The owner always has all four; without the feature every admin has all four.
- Audit and event exports — CSV or JSON Lines of the audit log and of workspace events, up to 100,000 rows per export with a marker when truncated.
- SIEM stream — one HTTPS endpoint per workspace receiving signed batches of events (the same signature scheme as webhooks). The secret is shown once; 50 consecutive failures pause the stream and email the owner; Enable resumes from where it stopped.
- IP allow-list — up to 200 addresses or ranges (IPv4 and IPv6). Boita refuses a list that would lock out the person saving it, and the owner keeps a 15-minute grace window after every change. Blocked people see this workspace only accepts connections from its approved networks. Test my current IP tells you where you stand.
- Device policy — require the desktop app for member transfers, and/or restrict transfers to approved computers by their install id. Recipient and portal traffic is not affected.
Where your data lives#
Files sit on Boita's transfer nodes in India, encrypted in transit; checksums are recorded for every file. Recipient and uploader pages never expose your folder paths, IP addresses are hashed wherever they are shown, and every staff action on your workspace is audited with a reason. The DPDP statement explains what recipient data is used for; the Trust page lists sub-processors, retention and backups.