Watermarks, evidence, retention, and legal hold
Interpret Vault protection honestly and operate high-impact controls safely.
Identity-watermarked preview
Vault preview does not return an ordinary presigned download URL. Supported image, PDF, and text representations are rendered with viewer identity, UTC time, and a random evidence identifier embedded into the returned bytes. Unsupported types fail closed.
docs-vault-watermark.pngReview access evidence
Document open, page view, close, denied download, and print-attempt signals feed append-only evidence. Export includes NDA records, page events, chain fields, and a manifest hash. These are application events, not proof that the recipient understood every visible page.
docs-vault-evidence.pngApply or release legal hold
Legal hold blocks policy/content changes and deletion for protected copies. The action requires security permission and recent step-up verification. Release only under an approved legal process; governance/compliance retention may continue to block deletion after hold release.
docs-vault-legal-hold.png