Protected directory security

Gating only works if visitors cannot reach the file another way. AcquisitionSuite protects uploaded files at three levels.

1. A protected folder

Uploaded files are stored in wp-content/uploads/acquis-protected/, not in the normal media library, and are never listed in the Media screen or in search.

2. Direct access is blocked

On Apache and LiteSpeed, a .htaccess file in that folder disables directory indexing and denies all direct requests. Files are only ever served by AcquisitionSuite itself, after a valid signed token is presented.

The link a lead receives contains a random token, not a file path. It works once and expires after the configured time.

Nginx and other servers

.htaccess rules are ignored by Nginx. If your host runs Nginx, ask them (or add a server rule) to deny public access to the acquis-protected folder. Test it by opening a file’s direct URL in a private window: it should return an error, not the file.

Other safeguards

URL-gated files

An external URL is only as private as the link itself. Anyone who has the raw Google Drive or Dropbox link can open it directly, so use links that require a signed-in account or expire on their own if that matters.

Still stuck?Our support team replies by email. Contact support

Share with