Skip to content

Centralized Document Management System (DMS)

Infrastructure

Other services hand files over here and receive an identifier. Each company has its own storage method and its own encryption key.

Domain
Platform file and document management
Target customers
IT and information security units; all business services that need secure file archiving
Main capabilities
Multi-method storage, dedicated per-company envelope encryption, anti-malware scanning, public short link, monitoring dashboard

Any organization with several software systems eventually runs into the same recurring problem. Each system stores files on its own, each with a different security method, and nobody has a complete picture of which file is where and who can access it. The centralized document management system was built to solve this problem. Instead of reimplementing file storage and security, every other platform service (from credit to contracts) hands its files to this system and receives an identifier, which it later uses to retrieve the file.

The system is multi-company by design. Each company can configure its own storage method separately from the other companies on the same platform, and can have its own dedicated encryption key. This means a leak or configuration error in one company does not reach another company's data.

Another important point is that the access level is kept separate from the storage method. The system administrator first decides how sensitive a file is (public, private in the database, or private in encrypted storage), and the system then restricts the permitted storage methods on that basis, and never the other way around.

Key capabilities

  • Three separate access levels

    A public file without encryption that is served through a short link, a private file in the database, and a private file in encrypted storage. Each has its own rules and its own permitted storage methods.

  • Seven selectable storage methods

    Local disk, SQL database, S3-compatible cloud storage (such as Arvan Cloud and Cloudflare R2), FTP, SFTP and Azure Blob. Each company configures its own method separately from the others.

  • Dedicated two-layer encryption for each company

    Each file is encrypted with a random AES-256-GCM key, and that key is protected with the same company's public key (RSA-OAEP). Each company's key is in turn held under an organizational root key.

  • Two key management models

    Server-managed keys for day-to-day work, or sender-managed keys for cases where even the server must not have access to the file's content.

  • Encryption key locking

    As long as a file encrypted with a company's key exists, that key cannot be changed. This prevents files from becoming unrecoverable by accident.

  • Upload security pipeline

    Before final storage, every file passes size and extension validation, a check for malicious executables and, when enabled, an antivirus scan.

  • Sharing between services

    A file can be granted to several other platform services without being copied.

  • Public short link

    For public files, a short anonymous link is generated that requires no authentication.

  • Monitoring dashboard

    An overview of file volume, categories, the number of access grants issued and the upload trend over any chosen period.

Business value

Without a single point for managing documents, every technical team has to reinvent the wheel, and the security of sensitive files is usually the casualty. This system takes the cost of building and maintaining file infrastructure off every service and provides one uniform security standard (encryption, access control, malware scanning) for all of them. For the CEO and the information security manager, this means one inspection and audit point instead of dozens of scattered ones. For the IT unit, it means the ability to change the cloud storage provider without changing the code of any other service.

What sets it apart

  • Storage settings and encryption keys are configured entirely per company, rather than as one global configuration for the whole platform.
  • The storage provider can be changed (local, domestic cloud, international cloud) without dependence on any specific vendor.
  • Security is part of the upload path itself, and is not a layer added afterward.
  • Designed for internal use by many services at once, with a clear access-sharing model.
Get in Touch

See this module on demo data

In a demo session we walk through your organization's scenarios on Dara's demo environment and answer your technical and finance teams' questions.