Durable files. Scoped access.

Files stay stored until you delete them or a retention policy does. Blob Yard keeps credentials at the server boundary and gives each client only the capability it needs for the next operation.

Direct transfer model

Files move directly between your client and private object storage through scoped presigned URLs.

Blob Yard coordinates authorization, metadata, quota, and audit without proxying every byte.

Credential boundary

Storage credentials stay server-side. The CLI stores refresh material in the operating system credential store where available.

Web, CLI, CI, share, and inbox access are checked independently at every server boundary.

Token lifecycle

Upload and download grants expire quickly. Share and inbox capabilities can expire or be revoked without deleting stored files, and raw capability tokens are stored only as hashes.

Public content boundary

Web Yards serve user-published static output only from isolated blobyard.app origins. Those origins never receive Blob Yard application cookies or host authenticated product pages.

Publishing requires explicit public consent. Blob Yard can suspend abusive content while keeping private project storage and account credentials separate.

Audit and reporting

Sensitive actions create actor-aware audit events. Logs redact authorization headers, cookies, OTPs, signed URL queries, and provider secrets.

Reports go privately to contact@reliabilityworks.co.uk at Reliability Works Ltd.