Direct answer
A file uploaded to Velvet goes straight from the browser into private storage, then waits for two independent checks: a hash match against known abuse imagery, which can quarantine it, and a classification pass that only gates public visibility. Once cleared and attached to a paid link, it is delivered through URLs signed for 15 minutes inside a buyer session that lasts 30 days.
Creators are told to think about content protection at the point of sale. Most of what determines whether a library is safe happens before that, in the minutes after an upload.
This is the actual sequence a file goes through on Velvet, and what each stage can and cannot do to it.
Summary
- The browser uploads directly to private storage, so the file is never public at any point.
- A new asset starts as pending and is claimed in small batches for scanning, with no double claim between workers.
- A hash match against known abuse imagery quarantines the asset and the serve path then refuses it.
- A separate classification pass decides only whether an asset may appear publicly; it never quarantines.
The bytes go straight to storage
Uploads travel from the browser to a private bucket using a pre-signed request, so the file never sits on a public URL waiting to be processed. Because the API does not see the bytes in transit, scanning happens afterwards as a background job rather than inline, and every new asset begins in a pending state.
- Pending is the default written by the database, not a value the client can choose.
- Files are organised into folders on the creator's side, which is a library concern rather than an access one.
- Nothing is servable while it is pending a check it has not passed.
Two scans, two different consequences
The first check compares the file against a database of known abuse imagery maintained by a child-protection organisation. A match is not a content-rating question and does not have a grey area: it flags the asset and quarantines it. The second check is a classification pass that scores the image and decides whether it may appear on a public surface. Confusing the two is how platforms end up either over-blocking or under-protecting.
- The classification model runs in the process itself, so no third party receives the image to score it.
- A classification result never quarantines an asset; it only gates the public surface.
- The two run as separate jobs with separate failure modes, so one being unavailable does not disable the other.
What a quarantine does to the serve path
A quarantined asset is refused by the gate that every media request passes through, so the block is at the point of serving rather than at the point of listing. Removing an item from a page cannot un-quarantine it, and no other surface can route around it. A clean result releases an asset that was held for scanning back to its normal state.
- Claiming a batch for scanning uses a lock that skips rows another worker already holds, so two workers cannot scan the same asset.
- A detection writes a full audit trail alongside the status change.
- With live scanning disabled the asset is marked as skipped rather than silently treated as clean.
What the buyer finally gets
When a cleared asset is attached to a paid link and someone buys it, entitlement is checked against the buyer's record first, and only then is a storage URL signed for 15 minutes. The buyer holds an access session for 30 days, so returning to the content means reopening the page rather than paying again.
- Attached extras are signed under the same entitlement check as the primary file.
- A forwarded media URL is dead within fifteen minutes, while the page it came from still asks the recipient to buy.
- The public link URL resolves the immutable link id as well as the editable slug, so retitling an offer never breaks a buyer's access.
Outcomes
- Upload before you need the file, so a scan is never in the way of a send.
- Treat a pending asset as unsendable rather than assuming it will clear in time.
- Keep folders organised by what you sell, not by when you shot it.
- Check that an offer's attachments are all cleared before publishing it.
- Expect signed media URLs to expire; share the link page, never the media URL.
Questions
Does anyone at Velvet look at my files?
The routine checks are automated. One compares against a hash database of known abuse imagery, the other is a classifier that runs inside the service itself. Neither involves a person browsing a library.
Why does a file sometimes take a while to become sendable?
Because scanning happens after the upload rather than during it. Assets are claimed in small batches, so a large upload session clears over a few passes.
What is the difference between quarantined and not public?
Quarantined means the serve path refuses the file entirely. Not public means the classifier decided it should not appear on a public surface, while it remains usable in paid, private contexts.
Can a buyer download and reshare the file?
They can save what they bought, as with any digital purchase. What Velvet controls is the URL: it is signed for 15 minutes, so passing the link on does not pass the access on.
What happens if I delete a link someone already bought?
It is archived rather than destroyed, so the buyer's access is not broken by a tidy-up on the creator's side.
Upload one file and follow it through
Open a creator account, upload a single asset, attach it to a paid link and buy it from a second browser.