# How Multica Handles File Storage with S3 and CloudFront Signed URLs

> Discover how Multica uses S3 and CloudFront signed URLs to securely manage and serve user-specific file storage without public bucket access. Learn about their robust security approach.

- Repository: [multica-ai/multica](https://github.com/multica-ai/multica)
- Tags: how-to-guide
- Published: 2026-04-11

---

**Multica stores binary attachments in Amazon S3 and serves them through CloudFront using RSA-signed URLs and cookies, enforcing per-user access without exposing the bucket publicly.**

The [multica-ai/multica](https://github.com/multica-ai/multica) repository implements a secure file storage layer that combines S3 durability with CloudFront edge delivery. Instead of generating presigned S3 URLs, the system uses CloudFront signed URLs and signed cookies to control access, leveraging private RSA keys stored in AWS Secrets Manager or environment variables.

## S3 Storage Architecture

Mult