Secure file handling

Files you bring into Pytheus are handled with the same care as the rest of your data.

Last updated September 22, 2026

Assessments often come with supporting material: contracts, evidence, exports, and notes. Files you bring into Pytheus are protected the same way as everything else in your account, scoped to your tenant and reachable only by people with the right role.

Why files need attention

Files are easy to overlook and easy to leak. A contract or an evidence document can hold sensitive detail that never appears in a score: vendor terms, renewal dates, configuration notes, named systems. If files were handled loosely, they would become the soft spot in an otherwise careful program. Pytheus treats them as part of your protected data, not as loose attachments.

What to keep in mind

  • Uploaded files stay within your tenant, separated from other organizations.

  • Access to files follows the same roles that govern the rest of Pytheus.

  • File activity is captured in your account record alongside other actions.

Evidence documents are a special case: once their structured facts are extracted, the original file is erased and the deletion verified, so Pytheus keeps the proof without keeping your document content. See Evidence intake sessions. Contracts, by contrast, support spend and renewal tracking and do not drive your scores on their own.

Be deliberate about what you upload. The strongest file handling still cannot reduce the risk of a document that did not need to be there. Bring in what supports the work, and nothing more.

File handling sits inside the same boundaries as the rest of the platform. See Tenant isolation and Retention and deletion.

Secure File Handling in Pytheus · Pytheus Docs