Security and trust

Your packet should be easy to share—not easy to expose.

SubPacket is designed around private storage, unguessable links, and explicit sharing controls.

Private uploads

Uploaded files live outside the public web root on your self-hosted storage volume. The database stores metadata, not public file URLs.

Controlled downloads

Downloads pass through an app-controlled route that checks the owner session or a valid packet token before streaming the file.

You choose what is shared

W-9s and other sensitive documents are excluded from the packet by default. You can revoke the packet link at any time.

What SubPacket does not claim

SubPacket does not verify insurance coverage, licenses, tax forms, safety records, or legal compliance. It is an organization and sharing tool. Requirements vary by trade, state, project, and GC.

Your responsibility

Use a strong account password, do not place banking information in a public packet, revoke links you no longer need, and keep independent backups. A production security review and legal review are recommended before handling sensitive customer volume.