Confidential documents. Encrypted, audited, for the right eyes only.
Secure files is the encrypted vault on every student record. Psychologist notes, SEN reports, health documents, legal letters and productivity files live in one place — with role-based access, signed URLs and full edit history.
Get startedWhat you get
RPC-gated access
Every view goes through the `can_access_student_secure_files` chokepoint. Psychologist notes stay confidential — only the author and school admin can see them.
Encrypted private bucket
Files live in the private `student-secure-files` bucket. No public links — only short-lived signed URLs issued on click.
Edit history
Every session logs open time, duration, number of edits and the user. Open the full history with one click from any file row.
Six categories
Psychologist, SEN, Health, Legal, Productivity and Other. Filter quickly — and keep confidential records separate from a pupil's daily work.
Two file types
Upload a PDF, image or document — or link an existing productivity file (Docs, Sheets, Slides) without ever moving data off the platform.
Role-based visibility
School admin, psychologist (own notes), SEN consultant and explicitly assigned staff. Parents and pupils only ever see what is shared with them.
How it works
1. Upload or link
Drag in a PDF, or link an existing Doc/Sheet/Slide. Pick a category — Psychologist, SEN, Health, Legal, Productivity or Other.
2. Access decided by RPC
On every view the client calls `can_access_student_secure_files`. The result drives the tab, the list and the signed URL.
3. Tracked editing
`SecureFileEditTracker` records each session: user, opened-at, duration and edit count. History is one click away from the file row.
4. Deletion with audit trail
Deletion requires an explicit action and leaves an audit trail — so you can document both who saw what, and when something was removed.
Built for confidential pupil data
Psychologist confidentiality
Journal notes have their own RLS and audit. Only the author psychologist and school admin — never teachers or parents without explicit sharing.
No AI exposure
Files are never sent through AI models. Secure files sit outside the prompt pipeline and are excluded from analysis and training.
GDPR & data minimisation
EU-hosted, signed URLs, short lifetimes and role-based access. Follows the same Privacy-by-Design patterns as the rest of the platform.
Full audit trail
Every open, edit and deletion is logged. School leadership can document access for inspections and the DPO at any time.
Keep confidential files in one place
Encrypted, audited and role-based — without moving data off the platform.

