Security & sovereignty

Your library is yours, and stays where you put it.

VisualIQ is multi-tenant by design, not by retrofit. Each organisation's assets, users, albums and tags live in their own tenancy, reached through their own address. Unlike most other cloud systems — your files stay yours, they don't become ours and then we grant you access to them for a fee. Yours. Always.

Separate tenancies

Every query is scoped to your organisation. There is no shared pool to leak out of, and an address never grants access — it only narrows it.

Australian hosting

Assets, database and backups stay on Australian infrastructure, and nothing is copied offshore.

Private by default

Nothing is viewable without a sign-in unless somebody deliberately creates a share link for it, and that link can expire.

Accountable access

Roles, ownership and an activity trail — who uploaded, who edited, who shared, and when.

The detail

What that means in practice.

Your originals are never modified

Every derivative — thumbnail, preview, web copy, edited version — is generated as a separate file. The master you uploaded stays byte-for-byte as it arrived, which is the only property that makes a library trustworthy in ten years' time.

Sign-in

Passwords are stored as bcrypt hashes and never in any other form. Repeated failures lock an account for a while rather than forever, so a wrong guess is an inconvenience and an attack is a wall. Administrators can be required to use a second factor.

Nothing can be hammered

Signing up, asking for a verification email again, finishing setup and checking whether an address is free are all rate-limited — per network address, and separately per email address, so a script cannot get around the first ceiling by spreading itself across machines. Signing in is covered by the lockout above. The limits are generous enough that nobody having a bad morning will meet one.

The browser never decides what you may do

Permissions are worked out on the server, and every action is checked again when it arrives — not only when the button was drawn. A button you cannot use is usually not shown to you, but that is a courtesy, not the control. Nothing an altered page can send will do something the account behind it was not allowed to do.

What is indexed

Only these public pages are visible to search engines. Everything behind the sign-in — libraries, assets, albums, share links, the administration screens — is served with headers that keep it out of every index, and always has been.

Sharing

A share link carries a long random token, names exactly one album, and can see nothing the token does not name. It can be given an expiry date and a passcode, and revoked at any moment. Nothing else in your library is reachable without an account.

Deleting, and changing your mind

Nothing is removed the moment somebody presses Delete. Deleted assets go to a recycle bin — the person's own, and an organisation-wide one an administrator can see — and can be restored from either. Thirty days is the default and the number is yours to set.

Who did what

Uploading, editing, moving, sharing, deleting, restoring, changing somebody's role — each writes a line naming the person, the thing and the moment. Administrators can read the trail for their own organisation and nobody can read anybody else's.

Backups and getting out

The database is backed up nightly and the datastore is on redundant storage. If you ever want your library back in your own hands, ask: you get the original files and a manifest of the metadata, and no argument about it.

Reporting or suggesting something

If you think you have found a security problem, a bug or have a great idea, email hello@visualiq.au and tell us all about it. You will get a reply from the developer themselves, not a ticket robot, and we will tell you what we did about it — or when we'll have your great idea built for you.