Magic link
Short-lived, single-use email sign-in link.
IDENTITY · SESSION · FILE SAFETY
Every account, session, file and publication action crosses its own security gate. Uploading a file never publishes it automatically.
ACCOUNT PROTECTION
The live seller system will combine passwordless access with short sessions, server-side roles and step-up verification for critical actions.
Short-lived, single-use email sign-in link.
Phishing-resistant sign-in on supported devices.
HttpOnly, Secure and SameSite=Strict session policy.
Server-validated token on state-changing requests.
Seller and administrator permissions verified per action.
Fresh verification for publishing, payout and account changes.
FILE ACCEPTANCE CHAIN
A seller file first enters private quarantine. It never reaches public fulfilment until every gate passes.
Seller and product draft are authorised.
A short-lived signed upload grant is issued.
The file cannot enter a public bucket directly.
Extension, MIME, signature and size are checked.
Archives and contents receive security scanning.
A SHA-256 integrity fingerprint is recorded.
Rights and publication standards are assessed.
Only an approved copy reaches fulfilment.
PLANNED FILE POLICY
Initial automated acceptance is planned for lower-risk document formats only. Applications and executables require separate technical and signing review.
Open machine-readable policy →PDF, DOCX, XLSX, PPTX, CSV, TXT and safe image formats.
Android, iOS, Windows, macOS and executable packages.
Macro-enabled files, scripts, double extensions and password-protected archives.