Controlled access
Each manufacturer receives a personal, expiring, one-time invitation. MEDDEV administrative access is also assigned individually and remains revocable by the service owner. Invitation and session secrets are stored as cryptographic hashes.
Session protection
Sessions are time-limited. Cookies use Secure, HttpOnly and SameSite=Strict protections. State-changing client requests require an additional anti-forgery token.
Private encrypted storage
Documents are held in a non-public storage bucket in the European Union. Cloudflare R2 applies AES-256 encryption at rest and Transport Layer Security during transfer.
File handling checks
Permitted formats and file sizes are restricted. File signatures are checked against their declared type. Manufacturer uploads remain quarantined until MEDDEV completes handling checks.
Integrity and traceability
A SHA-256 digest is recorded for each accepted file. Room, session, upload, status and download events are entered in an audit log. Network addresses are pseudonymised before logging.
Browser safeguards
Responses are not cached and the portal is excluded from search indexing. Security headers restrict framing, content loading, referrer disclosure and browser permissions.