SubPacket is designed around private storage, unguessable links, and explicit sharing controls.
Uploaded files live outside the public web root on your self-hosted storage volume. The database stores metadata, not public file URLs.
Downloads pass through an app-controlled route that checks the owner session or a valid packet token before streaming the file.
W-9s and other sensitive documents are excluded from the packet by default. You can revoke the packet link at any time.
SubPacket does not verify insurance coverage, licenses, tax forms, safety records, or legal compliance. It is an organization and sharing tool. Requirements vary by trade, state, project, and GC.
Use a strong account password, do not place banking information in a public packet, revoke links you no longer need, and keep independent backups. A production security review and legal review are recommended before handling sensitive customer volume.