Personal Vault and sharing limits
Configure Personal Vault restrictions, manage PIN-protected encrypted files, and create password-protected sharing links.
Personal Vault and sharing limits
Personal Vault provides encrypted, user-owned file storage and time- and download-limited sharing workflows inside the Trustity Cloud Portal. Files are scoped to the signed-in owner even when organization policy defines limits. Use it only for information approved by your organization’s classification, privacy, retention, and sharing policies.
Encryption and vault PIN
Files are encrypted in the browser before upload. The material needed to open a file is wrapped with your vault PIN on the device. Trustity does not hold that PIN, so Trustity cannot open your Personal Vault files. On first upload you also receive a recovery key - store it offline. Losing both the PIN and the recovery key means the files cannot be opened.
When you upload or decrypt, the portal asks for the PIN in a prompt. Within the same signed-in session the PIN may be remembered on the device; after sign-out you must enter it again.
This zero-knowledge model applies to File Vault file contents. It does not describe PAM rotated local-admin passwords, which remain encrypted under portal-managed keys for authorized operators.
Policy controls
In the Vault policy, administrators can set:
- Maximum file size for an individual upload
- Blocked file extensions
- Organization storage quota
- Maximum sharing duration
- Maximum download count
- Additional access-posture or sharing requirements available in the tenant
Policy limits are upper bounds, not recommended defaults for every share. Users should choose the shortest duration and fewest downloads needed.
Configure Personal Vault
- Identify allowed data classifications and prohibited content.
- Set a maximum file size appropriate for normal business use.
- Block executable or other disallowed extensions according to security policy.
- Set conservative share-duration and download limits.
- Confirm who may upload, decrypt, delete, and share files (share typically requires Owner/Admin).
- Pilot uploads, downloads, PIN prompts, quota handling, and expired links with non-sensitive files.
- Document how users store recovery keys and who to contact for process issues (Trustity cannot reset a forgotten PIN).
Extension blocking is a policy safeguard, not malware scanning or content inspection. Do not rely on a filename extension to establish that a file is safe.
Upload and download workflow
- Open Personal Vault and review current storage usage.
- Select an approved file.
- Confirm its size and extension comply with policy.
- Choose Upload, enter and confirm your vault PIN when prompted, and save the recovery key when shown.
- Wait for the success confirmation before closing the browser.
- Verify the file appears with the expected name and size.
- When needed, choose Decrypt, enter the vault PIN (or recovery key), and download through the authorized portal session.
- Store the downloaded copy only in an approved location and remove temporary copies according to policy.
If an upload fails, check individual file size, blocked extension, available storage quota, network connectivity, session status, and PIN confirmation. Do not rename a prohibited file merely to bypass an extension rule.
Create a sharing link
- Select Share for the correct file (Owner/Admin).
- Choose the shortest available expiry that meets the business need.
- Choose the lowest practical download count.
- Set a share password (required). Recipients decrypt in the browser with that password; your vault PIN is never sent to them.
- Create the link and send the link and password through separate approved channels to verified recipients.
- Record the business owner and expiry when required.
- Confirm the recipient can access the intended file and no other file.
A link can be used by anyone who receives both the link and the share password. Treat both as sensitive. Download limits reduce repeated access but do not prevent a recipient from retaining a downloaded copy.
Sharing limits and expectations
The organization policy defines maximum duration and download values. The share dialog may offer shorter presets. A link stops being usable when its expiry or permitted-download condition is reached.
“Unlimited” or a high preset in the interface should still remain within organization policy and must not be used as a substitute for permanent managed collaboration storage.
Delete and revoke
Delete a file only after confirming retention requirements and ownership. Deletion is not a substitute for revoking copies already downloaded by recipients. If a link is sent incorrectly, follow the incident process immediately and remove or disable access through the controls available in your tenant.
Operational review
- Monitor storage consumption and investigate unexpected growth.
- Review blocked extensions and business exceptions periodically.
- Prefer short-lived, low-download links.
- Remove obsolete files according to retention policy.
- Remind users that PIN and recovery key custody is their responsibility.
- Never upload credentials, unlock information, or unsupported secrets merely to transfer them.
