- Home
- Desktop Apps
- Using the Private Room to work on your documents securely
Using the Private Room to work on your documents securely
Introduction
The Private Room is designed to provide a secure environment for document editing and co-authoring.
The Private Room is a special section in the Documents module. Work in the Private Room is only available via ONLYOFFICE Desktop Editors.
Documents stored in the Private Room and data transferred during collaboration are encrypted with the AES-256 encryption algorithm to protect your data from unauthorized access.
Step 1. Enable the Private Room settings in the Control Panel
The Private Room functionality is enabled by default in the Control Panel for the server version (the paid version 5.6 of Desktop Editors is also required for working with Private Rooms).
The full access administrator or portal owner can disable/enable the Private Room in the Control Panel.
To access the Control Panel, sign in to your portal and click the 'Control Panel' icon on the Start Page. Alternatively, you can go to the Portal Settings and select the Control Panel link on the left-side panel.


Switch to the Private Room page in the PORTAL SETTINGS section of the Control Panel.
To disable/enable the Private Room, turn off/on the switcher and click the SAVE button. Private Rooms will be available for the current portal only.
Step 2. Connect to the ONLYOFFICE cloud via Desktop Editors
To start working in Private Rooms, users should install the latest version of the Desktop Editors with the Private Room support (version 5.6 and later).
To connect to the ONLYOFFICE cloud:
- Launch Desktop Editors.
- In the main program window, switch to the Connect to cloud tab at the left sidebar.
- Click the ONLYOFFICE button.
- Specify your web office address in the new window.
- Click the Connect now button.


- On the authorization page, specify the login and password used to access your cloud office account.


Technical details
When the user connects to the ONLYOFFICE cloud in Desktop Editors for the first time after the Private Room has been enabled:
- Desktop Editors remember the login and password entered by the user on the authorization page.
- Desktop Editors automatically generate and remember the user’s public key and private key.
- The private key is encrypted with the user’s password.
- The public key and the encrypted private key are sent to the portal.
When the user connects to the ONLYOFFICE cloud in Desktop Editors for the next time:
- Desktop Editors remember the entered user’s login and password.
- Desktop Editors verify and remember the user’s public key and the encrypted private key.
- The private key is decrypted with the user’s password.
Step 3. Store and manage documents in the Private Room
When users connected to the ONLYOFFICE cloud via Desktop Editors, they can use the Private Room section of the Documents module to store documents and collaborate on them securely.


The Private Room of each user contains:
- folders and files created by the current user,
- files shared with the current user by other users from the Private Room.
Within the Private Room, you can:
- create folders,
- create and upload files (
.docx
,.xlsx
,.pptx
), - share documents with other portal users,
- co-edit documents.
All documents are encrypted once uploaded or created. All the documents stored in the Private Room are encrypted and marked with the icon in the file list.


Uploading
- When uploading files, an existing file with the same name cannot be overwritten.
- You cannot upload files using the drag-and-drop method.
- You cannot upload folders.
Copying
- You cannot copy the files.
Moving
- You can move the files within the Private Room section only.
- You can move only your own items and cannot move items shared with you by other users.
- When moving files, an existing file with the same name cannot be overwritten.
Removing
- Files are removed permanently without passing through the Trash and cannot be restored.
Versioning
- You cannot restore previous versions of a file.
Sharing
- You can share files with users who have already obtained private and public keys.
- You can share files providing Full Access only.
- You cannot provide access to the file via an external link.
Technical details
All the OOXML
documents (.docx
, .xlsx
, .pptx
) in the Private Room are encrypted with their own passwords.
Saving the file
- Once the file is edited and saved, Desktop Editors generate the document password.
- The file is encrypted with the generated document password.
- The portal provides a list of public keys of the users who have access to the file.
- The document password is encrypted with the public keys of all users who have access to the file.
- The pairs of the encrypted document passwords and public keys of all users who have access to the file are recorded to the unencrypted part of the file.
- The file is stored to the cloud.
Opening the file
- When a user opens the file, the file is downloaded in Desktop Editors.
- Desktop Editors take the encrypted document password corresponding to the public key of the current user from the unencrypted part of the file.
- The encrypted document password is decrypted with the private key of the current user.
- The document password is used to open the document.
Step 4. Share and co-edit documents in the Private Room
To share your files stored in the Private Room with other users:
- Click the Share button to the right of the necessary document.
- In the Sharing Settings window, click the Add Users button to open the user list, then check the users you want to share the document with and click Save.
You can share the file with users who have already obtained private and public keys.
- By default, Full Access is provided. If you want to block access previously granted to a user, select the Deny Access option from the drop-down list next to the user name.
- Click Save at the bottom of the Sharing Settings window.


Now you can co-edit the file securely together with other users within the Private Room. When you work on the encrypted file, it is marked with the icon in the editor header.


Technical details
Opening the shared file
- When the user you shared the file with opens the file, the file is downloaded in Desktop Editors.
- Desktop Editors take the encrypted document password corresponding to the public key of the current user from the unencrypted part of the file.
- The encrypted document password is decrypted with the private key of the current user.
- The document password is used to open the document.
Saving the shared file
- Once the file is edited and saved, Desktop Editors generate the document password.
- The file is encrypted with the generated document password.
- The portal provides a list of public keys of the users who have access to the file.
- The document password is encrypted with the public keys of all users who have access to the file.
- The pairs of the encrypted document passwords and public keys of all users who have access to the file are recorded to the unencrypted part of the file.
- The file is stored to the cloud (as forcesave).
Watch video
Private Rooms in ONLYOFFICE Workspace for Secure Collaboration on Documents
Need the ultimate level of data security when collaborating? Try the unique technology in ONLYOFFICE Workspace - Private Rooms. It is also available in the open-source Community version!