Яндекс.Метрика
Internal/external file access

Internal/external file access

How to set up internal and external zones in Pachca to protect your company documents

Pachca lets you split your company workspace into two zones for working with files: a secure internal zone and an external one. This way, confidential documents, images and other files never leave your company's network. They can be accessed only from networks you trust and aren't available from external addresses.

Here's how it works:

  • Files sent from the secure zone (an IP allowlist) can be viewed and downloaded only by users inside that zone.

    • Users in the external zone (outside the allowlist) can't view or download these files.
  • Files sent from the external zone can be viewed and downloaded by all workspace members, no matter which zone they connect from.

__wf_reserved_inherit How the two zones handle files

The easiest way to set up the two zones is with a corporate VPN (with a list of subnets in CIDR notation). Your company's users can then go online through one or two public IP addresses. Add these addresses to the IP allowlist in Pachca, and Pachca uses them to determine which zone a user is in when working with files.

To add IP addresses to the allowlist:

  • You need the workspace Owner role on the Corporation plan
  • Go to Workspace settings. To open it, click the workspace name in the top-left corner.
  • Go to the IP allowlist tab and enter the address you want to allow.

__wf_reserved_inherit

In practice, the two zones work like this:

  • Employees connect to the corporate VPN on their devices and go online through an IP address from the secure zone.

  • When an employee uploads a file while on the corporate VPN, it's marked as an attachment for the secure zone. Users whose IP addresses aren't on the allowlist can't view or download it.

    • Users whose IP addresses are outside the allowlist can't preview or download files sent inside the secure zone. These files are marked with a lock, and a download attempt shows a placeholder saying the file isn't available.
  • If users in the external zone (on a home network or in a coffee shop) send files in Pachca, these attachments can be viewed and downloaded by all workspace members, whatever their IP address.

__wf_reserved_inherit

If you have questions about separate file access or ideas for improving this article, contact our support in Telegram or MAX. We'll do our best to help and update the article :)

‍

Updated: August 4, 2025

More in Administration

Accounts in Pachca
How Pachca is structured: the difference between an account, a user and a member profile
Inviting your team
How to invite your team to Pachca, the team chat app: two ways to add employees
Change your email in Pachca
How to change your email address in Pachca: a guide for employees and administrators
Errors when adding people by email
Common errors when adding users to Pachca by email and how to fix them
Managing members in Pachca
Managing members in Pachca: how to add, edit and remove people from your team
Group tags
Add employees to all the chats they need at once with group tags
Advanced administration via API
How to automate user administration in Pachca with the API: creating users, managing them and tags
Ports and addresses Pachca needs
Ports and addresses Pachca needs to work properly: setting up your corporate firewall
Storage in Pachca
Everything about file storage in Pachca: limits, managing storage space and working with documents
Setting up DLP in Pachca
Add an extra layer of protection for personal data, tokens and passwords
Two-factor authentication (2FA)
How to turn on two-factor authentication in Pachca for extra account security
Import chats from Slack
How to import your chat history from Slack into Pachca: a step-by-step migration guide
Import chats from Mattermost
Pachca lets you move your chat history and files from Mattermost into your workspace.
Import chats from Telegram
If your team is moving to Pachca from Telegram, you can bring your chat history over to your team chat app.
Exporting messages from Pachca
How to export messages from Pachca: data format, settings and export limitations
SSO options in Pachca
Single sign-on (SSO) in Pachca: SAML, LDAP and Keycloak connection options and step-by-step guides
SSO in Pachca with LDAP
SSO in Pachca with Multifactor.ru
SSO in Pachca with Blitz Identity Provider
SSO in Pachca with Authentik
SSO in Pachca with Keycloak
SSO in Pachca with Azure OpenID
SSO in Pachca with ADFS OpenID
This guide explains how to configure ADFS on Windows Server 2016 or later to connect it to Pachca.
SSO in Pachca with Google Workspace SAML
SSO in Pachca with Indeed IdP over SAML
SSO in Pachca with Yandex 360
SSO in Pachca with Yandex Identity Hub
BYOK: Bring Your Own Key in Pachca
How encryption with your own key (BYOK) works in the Pachca team chat app
Advanced encryption in Pachca
How to set up advanced encryption in Pachca for extra protection of your company data
Set up BYOK with HashiCorp Vault
Set up BYOK with Yandex KMS
Set up BYOK with Cloud.ru KMS