FILE STORAGE

Every document, connected to its record

An archive that behaves like part of your accounting, because it is. File invoices, payslips, and tax exports the moment they are generated — and keep them linked to the records behind them.

Connected archive

Documents and records move together

In most tools the file archive and the accounting data drift apart. In Cove they are one system: every generated invoice, payslip, or tax export can be filed on the spot, and every stored document keeps a live link to the record it documents.

  • One save dialog, everywhere

    Wherever Cove generates a document — invoices, HR documents, payslips, tax exports — the same Save to File Storage dialog appears. Pick a folder and it is filed.

  • Two-way links, and a warning that names things

    Delete a document and Cove lists by name the records that go with it — and the other way around. Trash is reversible, so the cascade only fires on a permanent delete or an empty-trash.

  • Statutory invoices are protected

    Issued invoices in your statutory numbering sequence cannot be swept away by a cascade. The archive respects the bookkeeping rules that protect them.

  • Virtual folders that fill themselves

    Issued and received invoices and receipts appear as ready-made virtual folders — always complete, with no manual filing.

A real file manager inside your accounting

Everything you expect from a file manager, running in the same workspace as your books.

Drag-and-drop folder tree

Reorganize folders and files by dragging them — the structure you would build on your desktop, in the browser.

Preview and download

Open multi-page PDFs and images right in the app, and download the original whenever you need it.

Tags

Label documents across folders, so a contract lives in one place and is found in many.

Copy documents and folders

Duplicate a single file or a whole folder in one action.

Soft delete

Deleted files move to a recoverable state first, so an accidental delete is not a lost document.

Storage quotas you can see

Usage is metered per plan, so you always know how much of your storage is in use.

Reviewed on the way in, private at rest

Documents that need review never create records silently — and your archive stays yours. Cove keeps a person in the loop for approvals, serves every private file through short-lived signed URLs, and meters storage transparently per plan.

Intake from anywhere

Upload a document by hand, let an email agent pick it up from your inbox, or generate it inside Cove.

Approval before anything posts

Extracted invoices and receipts land in the approvals queue — nothing becomes a record until someone signs off.

Filed and linked on approval

On approval the record is created and the document is stored, with a live link between the two.

Signed-URL serving

Private files are never on a public link. Each download runs through a short-lived signed URL generated for that request.

Workspace isolation

Access follows your team roles and permissions — row-level security applies to documents just like every other record in Cove.

Per-plan storage with clear metering

1 GB on Free, 25 GB on VAT, 150 GB on Accounting, 500 GB on Company — with metered overage instead of a hard wall on paid plans.

YOUR DATA

The archive is yours, including on the way out

Download all my data builds one package for the whole organization: one machine-readable NDJSON file per table, the stored documents themselves, a manifest, and a README. The right of access and portability under GDPR art. 15 and art. 20 does not sit behind a plan — the door is guarded by permissions and frequency, not by price (GDPR art. 12(5)).

Records and files together

The package carries the rows and the documents as they were uploaded. It stays for seven days, and each download runs through a short-lived signed link.

Credentials do not travel with it

API-key hashes, webhook signing secrets, mailbox tokens, an invoice's public pay-page token, and invite hashes come out nulled — including inside the row snapshots the audit log keeps.

The manifest states what is missing

Every table left out is named with its reason. A table whose read failed is marked partial — a truncated package must not look like a complete one.

Every touch leaves a trail

Uploading, moving, approving, and deleting a document, a folder, or a link to a record are all recorded by a database trigger, with the author and the moment. Reading the log is its own permission.

Frequently asked questions