Security - SpreadsheetWeb Hub | SpreadsheetWeb Help
SpreadsheetWeb Hub

Security

Security is a critical component of the SpreadsheetWeb Hub platform. This article provides a comprehensive overview of the security measures implemented…

Security is a critical component of the SpreadsheetWeb Hub platform. This article provides a comprehensive overview of the security measures implemented within SpreadsheetWeb, covering application, spreadsheet, data, and authorized access aspects.

Application Security

When converting an Excel file into a web application on SpreadsheetWeb, users have two primary security settings:

  1. Allow Anonymous:
    • Selecting this setting allows the application to be publicly accessible to anyone who has the URL.
    • This is particularly suitable for public-facing applications such as online calculators, forms, surveys, or questionnaires.
  2. Require Authorization:
    • This option restricts application access by prompting users to log in with valid credentials.
    • It is ideal for applications containing sensitive information or scenarios where users must save data for future reference or updates.
  3. Allow Anonymous with API Authentication**:**
    • Requires authentication (client_credentials) for access to calculation endpoints, but does not require explicit access to that specific application. As long as your client
      authenticates and is part of that workspace, calculations will work. Loading data will work with authorization – i.e., you need rights to that data for it to work.

Additionally, access to the application’s design interface is restricted exclusively to authorized personnel. Users must be explicitly granted design privileges to edit or update application configurations.

Spreadsheet Security

Creating an application on SpreadsheetWeb involves uploading your Excel spreadsheet to our platform. Uploaded spreadsheet files are securely stored within our protected databases. Access to these files is strictly limited to authorized users, ensuring the privacy and integrity of your data.

Data Security

Applications built with SpreadsheetWeb may include data storage capabilities, with data securely maintained in our databases. SpreadsheetWeb features a user management module allowing granular configuration of data access permissions, including:

  • No Data Access: Users can submit data without permission to access or view the stored information.
  • Personal Data Access: Users may only access data they have personally submitted.
  • Controlled Data Access: Certain users or groups can have comprehensive access to all stored data or selectively restricted data based on specific criteria, such as geographic location or departmental restrictions. For example, specific administrators may access only data submitted by international users.

Authorized Access by SpreadsheetWeb Administrators

A frequently asked question concerns whether SpreadsheetWeb administrators can access customer data, including the spreadsheet files, applications, or stored data.

  • In the Public Cloud platform, SpreadsheetWeb administrators have access to the databases solely for system management, maintenance, and support purposes. However, administrators will never access customer workspaces unless explicitly authorized by the customer’s own administrators for troubleshooting and support needs.
  • For highly regulated industries where any third-party access, even for support purposes, may pose compliance risks, SpreadsheetWeb provides a Server License option. This license enables clients to host the entire SpreadsheetWeb platform directly on their servers, eliminating any access by the SpreadsheetWeb administrative team and ensuring complete control and security over sensitive data.

In summary, SpreadsheetWeb employs rigorous security protocols to safeguard applications, spreadsheets, and data, providing flexible security configurations tailored to meet varying client requirements.