Upload
You open a case, declare who the data subject is, and add the documents you hold.
- Your originals are read only for the life of the case. Veil never edits a document you uploaded, so nothing that happens later can damage the copy you already hold.
- Storage is never browsable and holds no public object. Each file is reached through a short-lived link to that one object, issued by a route that re-checks membership and role at the moment of issue.
- Isolation between organisations is enforced by the database rather than by application code, so a cross-organisation read is refused at the lowest layer rather than the highest.