Private report reference
Each report has a unique reference that is not a predictable public file path.
Secure report delivery
DBX ONE reports are delivered through a protected hosted viewer. The authorised practice email is verified with a one-time code before the report, downloads or supporting invoice evidence can be opened.
Report access flow
How reports are protected
Email is used to notify the authorised recipient and deliver access instructions. The report and supporting files remain in private storage and are served only after the access checks have been completed.
Each report has a unique reference that is not a predictable public file path.
The recipient enters the authorised practice email before a one-time access code is issued.
A successful code creates a time-limited secure session rather than leaving permanent access in the email link.
Reports, source invoices and supporting evidence are stored outside the public website folders.
Invoice evidence and report downloads use authenticated routes, so copying a file address alone does not bypass access checks.
Verification, report opening and protected downloads may be recorded for security, support and audit purposes.
Excel, CSV and printable PDF downloads appear inside the verified report session and use the same protected delivery route.
Protection at each stage
The interactive HTML report is delivered through controlled access. The public website, secure viewer, private storage and administrative controls have separate roles.
| Stage | Control |
|---|---|
| Submission | Invoices are uploaded through the protected submission route and linked to a unique DBX reference. |
| Storage | Submitted files and generated reports are held in private cloud object storage rather than a public web directory. |
| Delivery | The authorised practice email receives a report reference and private access route, not the report as an attachment. |
| Verification | A one-time code is sent to the authorised email address before a short-lived viewing session is created. |
| Evidence | Supporting invoices and downloads are served through protected endpoints within the verified session. |
| Administration | Publishing, revocation and client-closure actions require a separate short-lived administrator session. |
Retention
Viewing access expires for security. The underlying invoice and report data follows the agreed service status and the Data Processing Agreement.
The decision period lasts up to 90 days after delivery. During that period, the practice can review the report and decide whether to continue.
When the practice agrees to continue, the relevant historical invoice and report data is retained for month-on-month comparison and recurring-issue analysis.
If written continuation has not been agreed by the deadline, DBX ONE automatically deletes the website-stored supplier documents, report and associated access records.
Stopping the service
The 90-day automatic-deletion deadline is accepted as part of the free-trial DPA. If the practice agrees to continue before then, historical data is retained for trend analysis until the service ends or the practice requests deletion. Expiring or revoking report access does not itself erase the underlying data.