> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://uploadcare.com/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://uploadcare.com/docs/_mcp/server.

# Security and compliance

> Protect sensitive data with Uploadcare: secure uploads, access control, malware protection, and unsafe content detection tools.

At Uploadcare we honor the safety of personal and business-sensitive information
and implement compliance with GDPR, HIPAA and other standards and regulations.
Uploadcare provides you with advanced privacy features to upload, access and
manage your content in a secure way.

## Signed uploads

Control who and when can upload files. It prevents from uploading files using a
Public API key only. You'll have to generate a token on the backend
to upload a file. A token can also limit which upload methods a client may use
and how many files it may upload.

[Signed uploads](/docs/security/secure-uploads/) work for a particular
Uploadcare project.

## Signed URLs

Control who and when can request files. Enabling this feature limits access to
your project files. A user will require a token from your backend to access
the content.

[Signed URLs](/docs/security/secure-delivery/) work in conjunction with custom domains.

## Unsafe content moderation

Detect and identify [inappropriate, unwanted, NSFW, or offensive user-generated content](/docs/unsafe-content/)
in order to enhance user safety, ensure brand integrity, and comply with local and global regulations.

## Malware protection

Enable [malware checking](/docs/security/malware-protection/) for all uploaded files.

## Compliance

HIPAA is US legislation providing data privacy and security provisions for
safeguarding electronic protected health information (ePHI). On our Enterprise
plan, Uploadcare can be configured to support [HIPAA compliant](/docs/guides/hipaa/)
workflow.

Uploadcare is committed to complying with industry-standard privacy and security
measures and all applicable laws and regulations to keep customer and end-user
data safe and secure: SOC 2, HIPAA, GDPR. Learn more about it in our
[Trust Center](https://uploadcare.com/about/trust/).

## Table of Contents \[#toc]

| Article                                                      | Description                                                                                                                                              |
| ------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [Validation and moderation](/docs/moderation/)               | You can validate the types of files you want to accept, and apply various checks after                                                                   |
| [Signed uploads](/docs/security/secure-uploads/)             | Get to control who can and when can upload files to one of your Uploadcare projects                                                                      |
| [Signed URLs](/docs/security/secure-delivery/)               | Control who and for how long can access files in your project via signed URLs. Protect end-users sensitive data, authorize clients, limit access by time |
| [Unsafe content moderation](/docs/unsafe-content/)           | Detect and identify inappropriate, unwanted, NSFW, or offensive user-generated content                                                                   |
| [Malware protection](/docs/security/malware-protection/)     | Automatically detect infected or malicious files to protect your users                                                                                   |
| [HIPAA workflows](https://uploadcare.com/docs/guides/hipaa/) | HIPAA is US legislation providing data privacy and security provisions for safeguarding electronic protected health information (ePHI)                   |