The least complex defensible design is private object storage plus a short-lived signed URL minted only after application authorization succeeds. For a marketplace retaining signed documents until an explicit deletion deadline, the URL is a temporary delivery credential; it is not the retention ...
Source: [Dev.to](https://dev.to/sterlingvance2196/marketplace-saas-exports-object-storage-signed-url-expiration-after-user-authorization-576k)