Business Problem:
  • Files shared through respond.io are accessible via direct URL indefinitely
  • This follows industry best practices — URLs are not guessable or enumerable, storage does not permit directory listing, and the architecture meets the security standards under which respond.io is independently certified and audited by third parties, including ISO 27001.
  • However, some organizations in regulated industries (banking, insurance, healthcare) have internal policies or regulatory expectations that require additional controls beyond industry best practices. These customers need the ability to enforce their own stricter access rules within the platform.
Desired Outcome:
Organization or Workspace-level settings allowing Admins/Owners to:
  • Configure a URL expiration window (e.g. 24h, 7 days, 30 days), after which the file URL returns access denied
  • Optionally require authentication to access file URLs
Trade-off:
Recipients who don't download within the active window lose access permanently. Authenticated access would require a different delivery mechanism for end contacts who do not hold respond.io accounts.