Obsi Drive · Security

Private, explicit, governed.

Authenticated sessions, workspace membership, file ownership, explicit sharing, API-key scopes, guarded delivery, and protected mutations keep private workspace content from becoming a public bucket.

Obsi Drive
securityOne canonical file layerSource-aware · protected when chosen · governed automation
01

Authenticated workspace access

Private routes resolve the signed-in user before returning personal, team, or scoped-member workspace data.

02

File and folder permissions

Access checks ownership, application/workspace context, membership, or explicit share access before private content is returned.

03

Guarded file delivery

Private content, previews, downloads, thumbnails, and posters are served through guarded paths rather than unprotected public URLs.

04

OAuth connection secrets

Provider connection tokens are encrypted before storage and current provider access is requested read-only where possible.

05

Developer access

SDK API keys are hashed when stored and can carry bounded file scopes.

06

Operational boundaries

Database, object-storage, OAuth-provider, billing-provider, and runtime-secret controls remain explicit deployment responsibilities.

Obsi Drive

One library. Every source still visible.

OverviewBook a call →