Dossira

Security & Product Scope Overview

Security and product scope in the private preview

This page is the plain-language statement of what Dossira provides today. It intentionally separates implemented behavior from the broader room workflow still being developed.

For more detail, see:

1. Current product foundation

The private preview provides an organisation-bound file workspace. Internal members can browse folders and upload, preview, download, move, rename, and share files.

The following room-workflow capabilities are not currently available:

  • comments and decisions attached to files;
  • a customer-facing room activity or audit ledger;
  • a read-only sealed room state;
  • a complete room-record export;
  • public self-service billing and plan management.

2. Authentication and external sharing

Registered members can choose a passkey on supported devices through the host identity system. Email-password and magic-link sign-in are also available. Dossira does not promise universal passkey support, synchronisation, or recovery across every browser and device.

External recipients currently use a different access path:

  • a share restricted to a confirmed email address and verified with a PIN; or
  • an explicitly created public link, where the owner chooses that sharing mode.

External guest passkeys are not yet implemented. Public copy should not imply that every recipient signs in with a passkey.

Shares can have an expiry and can be revoked, extended, or reissued. Revocation prevents later access through the share. It cannot remove information already downloaded or captured outside Dossira.

3. Current encryption boundary

Production web and API connections use HTTPS, and the reviewed production infrastructure uses encrypted server disks. These controls are separate from optional E2EE.

Optional workspace E2EE is available for supported file-content operations by enrolled internal members.

The present boundary is narrower than full-room E2EE:

  • file payload upload, preview, and download can use E2EE in the supported store-first flow;
  • filenames and folder metadata are not covered by that E2EE boundary;
  • guest-sharing flows do not yet provide equivalent E2EE support;
  • the mirror-backed file path does not provide the same workspace E2EE behavior.

See the E2EE scope page before choosing or describing confidential-mode behavior.

4. Hosting facts

Dossira is provided by a Norwegian company. Customer data and user identities are hosted on Hetzner infrastructure in Germany and Finland. Dossira does not use AWS, Microsoft Azure or Google Cloud for this hosting.

Use these concrete facts rather than broader geographic or jurisdictional shorthand.

5. Audit and lifecycle status

The underlying services retain creator/timestamp provenance for resources and uploaded versions, share creation/update/revocation details, and limited confirmed-email challenge state. That is not the same as a customer-facing audit ledger.

The current private preview does not provide:

  • a complete ledger of room creation, membership, access, downloads, changes, decisions, sealing, and reopening;
  • a customer audit export;
  • a sealed or immutable room state.

Those capabilities must remain described as unavailable until they are implemented and verified.

Frequently asked questions

How do internal members sign in?
Registered members can choose a passkey on supported devices. Email-password and magic-link sign-in are also available.
How do external recipients access shared files?
External recipients currently use confirmed-email PIN verification or an explicitly created public share link. Guest passkeys are not yet supported.
Can access be revoked?
A share can expire or be revoked, which prevents later access through that share. This cannot erase a copy that a recipient already downloaded or captured outside Dossira.
Is a room audit ledger available?
No. Resources and uploaded versions retain limited creator/timestamp provenance, while shares retain management details and PIN challenge state. The private preview does not expose a complete customer-facing room activity ledger or audit export.
Can a workspace be sealed?
No. A room sealing or close-and-export lifecycle is not implemented in the current private preview.