ABSQUARE Secure Sandbox

ABSQUARE Secure Sandbox

Encrypted document exchange inside a secure vault.

Choose your door — clients and AB Square staff stay in separate, access-logged lanes with a 30-day retention period.

🔒 HIPAA-compliant 🔐 Encrypted at rest 🧾 Access footprints ⏳ 30-day retention
🔒

Login as customer

Upload documents and track status inside the secure sandbox.

Login as AB Square user

Review client files, update status, and manage sandbox access.

About Secure Sandbox

ABSQUARE Secure Sandbox is a sealed document exchange portal for healthcare and revenue-cycle teams. Customers upload files into an encrypted vault; AB Square staff review them in separate, permissioned lanes — with every preview, download, and status change recorded as an access footprint.

  • No more PHI traveling through open email threads or shared drives.
  • Identity comes from verified sign-in — the portal never trusts browser-supplied user IDs.
  • Uploads are type-checked, size-capped, encrypted at rest, and automatically retained for 30 days.
  • In-app preview and status tracking keep work inside the vault, not outside it.

FAQ — from a customer’s seat

Straight answers about how Secure Sandbox protects your documents and what you should expect when you use it.

Is this safe for documents that may contain PHI?

Yes — Secure Sandbox is built as a HIPAA-aligned exchange vault. Files are encrypted at rest, access is limited to signed-in users in the correct role lane, and every sensitive action leaves an access footprint. Do not upload PHI through the demo request form or email; use the portal after you are onboarded.

Who can see my uploaded files?

Customers only see their own documents. AB Square staff only see clients they are assigned to. Admins can manage access, but the application still records who opened, downloaded, or changed a document’s status.

How do I sign in? Do I share passwords with AB Square?

No password sharing. You sign in through a secure Cognito-hosted login with modern browser protections (PKCE). Your session tokens stay in your browser tab session and are not emailed around.

Are my files encrypted?

Yes. Documents are stored with encryption at rest in cloud object storage. Downloads and in-app previews use short-lived signed URLs rather than permanent public links.

What file types can I upload?

Common business document types only — PDF, Word, Excel, plain text, PNG, JPG, and TIFF — up to 25 MB. Executable or script-bearing formats are blocked so uploaded files cannot become active content in the portal.

Can someone guess another customer’s document link?

Document access is authorized from your verified sign-in identity on the server, not from an ID you type into the browser. Even if someone tries another customer’s identifier, the API rejects it. That broken-object-level access control check is intentional.

What is an “access footprint”?

Whenever someone previews, downloads, or changes status on a document, Secure Sandbox appends a timestamped activity entry showing who did what. You can see that trail next to the document while it remains in the vault.

How long are documents kept?

Documents are retained for 30 days from upload, then expire and are removed from active access. Download anything you need to keep before the expiry date shown in the portal.

Why can’t I just email the file to AB Square?

Email creates uncontrolled copies, weak forwarding trails, and no reliable preview/status workflow. Secure Sandbox keeps exchange inside one vault with encryption, role separation, retention, and an audit trail.

What happens after I book a demo?

You submit your name, email, phone, and inquiry type. You receive a confirmation email with a unique ticket number, and our team contacts you within 24 hours to schedule a walkthrough tailored to your workflow and security questions.

Does the website itself help stop attacks like script injection?

Yes. Pages ship with a Content Security Policy, user-controlled text is escaped before rendering, and API responses avoid leaking internal errors. These controls work together so a single mistake is less likely to become a security incident.

Who do I contact for a security questionnaire or BAA discussion?

Email rcm.inquiry@joinabsquare.com or use Book your demo now and choose “Security & compliance” as the inquiry type. Include your ticket number in follow-ups.

ABSQUARE Secure Sandbox · docs.joinabsquare.com · every access is logged