Who inside CertNudge can see my documents?
Organisation users can access documents according to the roles and permissions available to their account.
Anyone holding a valid, active share link may also be able to access the specific document or resource shared through that link.
CertNudge operational access
CertNudge restricts staff and administrative access to authorised, need-to-know purposes required to operate, maintain, secure or support the service.
Who may be able to access a document?
Authorised organisation users
The organisation owner and other authorised users can access records according to their available role and permissions.
Anyone holding an active share link
CertNudge share links are bearer links. Anyone who obtains a valid link may be able to access the shared resource until the link expires or is revoked.
Authorised CertNudge personnel
Limited access may be required for authorised support, security, maintenance, incident investigation or legal purposes.
How are files normally accessed?
Files are stored in private Microsoft Azure Blob Storage. Normal authenticated downloads use short-lived authorised access rather than permanent public document addresses.
How can I control access?
- Review organisation users: Remove access when a person no longer needs to use the organisation's records.
- Protect share links: Send links only to the intended recipient.
- Revoke unused links: Revoke active links when access is no longer required.
- Use two-factor authentication: Enable the available authenticator-app option.
- Limit uploaded information: Do not upload unnecessary tenant personal data.
Revocation cannot undo an earlier download
Revoking a link prevents future use of that link, but it cannot remove a copy that was downloaded before revocation.
No system can promise absolute confidentiality
Security and access controls are intended to reduce risk, but no online service can guarantee that unauthorised access could never occur.