← All documentation

Security and backups

The audit log

Sessions

Access tokens are valid for 15 minutes; refresh tokens are random, stored only as hashes and replaced on every use. Reusing an old one ends the session. Signing out, a password change or deactivating a user takes effect at once.

Audit log

Every write, every opened file and every export or download is recorded with user, file, result and address, including refused requests and sign-ins. Only identifiers are stored, no contents; the database refuses to change or delete entries.

Backups

The backup container writes an encrypted file with the database dump and all files every night and keeps them for a configurable number of days. Every week (by default) it restores the newest one into a scratch database and compares the row counts. Restoring on the server is a single command that first backs up the current state.