Discussions
Warning: File security & Netsuite
We just discovered a rather alarming behaviour as to the way Netsuite handles security of files in the File Cabinet.
If you check "Available Without Login", then obviously your file is available to anyone anywhere. This makes sense and is especially useful when making web sites.
However, if you do NOT check that box, the file is available to ANY USER OF NETSUITE, not just people from your account. If ANY user of any version of Netsuite in any account with rights to see files somehow stumbles on a direct link to your file, he can access it. This is particularly bad for you if you have confidential documents under signed NDA. To be fair, though, if you click the "Available Without Login" title, the help does say exactly that - any user of Netsuite can access your file.