FeaturesBring your own storage
Seller-controlled files

Your files stay in your bucket. Not ours.

Connect your S3, R2, or GCS bucket. CodeHawke handles buyer entitlement checking and signed delivery — your assets stay in your infrastructure. No re-uploading if you ever change platforms.

Your
bucket, your files
Signed
per-buyer URLs
Zero
re-upload needed
Storage connection — S3 bucket route
Connected bucket
my-product-files.s3.us-east-1
Connected
Private bucket · Read-only access credentials · ACL public access: blocked
Product path mappings
UI Kit Pro Bundle
products/ui-kit-pro/
4 files
Photography Masterclass
products/photo-master/
11 files
Dev Starter Templates
products/dev-templates/
7 files
Delivery log — latest
Alex R.signed
ui-kit-pro/components.zip
2 min ago
Maria C.signed
photo-master/module-01.mp4
14 min ago
Jordan K.downloaded
ui-kit-pro/figma.fig
1h ago
Sam L.downloaded
dev-templates/starter.zip
3h ago
Why this matters

Platform-hosted files create dependency risk.

When your product files live on a platform's servers, you can't move without re-uploading everything. Storage limits, bandwidth fees, and pricing changes are outside your control. BYOB means your asset infrastructure is portable — CodeHawke just controls the access layer.

Platform-hosted files
BYOB (your bucket)
Files locked to platform account
Files in your controlled bucket
Re-upload required to switch platforms
Switch without touching files
Platform sets storage pricing
Your cloud storage rates
Bandwidth billed at platform rates
Your egress costs, your control

Connect your bucket

Link an S3, Cloudflare R2, or Google Cloud Storage bucket. Files stay in your infrastructure, not on CodeHawke servers.

Signed delivery URLs

CodeHawke generates time-limited, buyer-specific signed URLs at fulfillment time. The bucket itself stays private.

Access control from purchase

Only buyers with valid orders get delivery URLs. Refunded or cancelled orders stop generating new signed links.

Delivery audit log

Every signed link generation and download event is logged against the order. Support can see exactly what was delivered.

Folder-level product mapping

Map an S3 prefix or folder to a product. Update the folder and all future buyers get the new version automatically.

No vendor lock-in

Your files stay on your infrastructure. Switching platforms or storage providers does not require re-uploading assets.

How it works

Connect once. Signed delivery for every buyer.

The storage connection is configured once per account. Product-level bucket path mapping is product configuration — not per-file setup. Buyers never interact with your bucket directly.

Step
What happens
Connect bucket
Add your storage credentials to CodeHawke. The bucket remains private to the outside world.
Map to product
Link a bucket path or folder to a product. Files at that path become the delivery for that product.
Buyer purchases
Order completes. CodeHawke checks entitlement and generates a signed URL for the buyer.
Buyer downloads
Signed URL works for the configured window. After expiry, a new URL can be regenerated from the order.
Audit trail
Download event logged against order with timestamp, file path, and buyer identity.

Your infrastructure. Our access layer.

Keep files in your S3, R2, or GCS bucket. Let CodeHawke handle buyer entitlement checking, signed URLs, and the delivery audit log.

Try CodeHawke