SESSION Stage 03 — Store

One link. One password. One version that is actually final.

WavBox is where final_v7_REAL_final.wav goes to die. Every take, stem, reference, and master stays attached to the song it belongs to, with the history that explains how it got there.

Your hard drive is not a catalog.

The files survive. The context does not. Six months later you have four folders, three cloud drives, and a WhatsApp thread, and no reliable way to answer which master you actually sent to distribution — or who you promised what.

Upload

Everything lands in one place

Stems, takes, references, and masters upload against the record they belong to. Every version is kept and byte-verified on arrival, so the file you get back is the file you put in.

Organize

The history explains itself

Each asset carries its category, ISRC, credits, bookmarks, and full version lineage. Archive what is done, restore what you were wrong about, and keep the working set clean.

Share

Send a link, not a 2GB email

Server-issued share links carry real password enforcement and tell you who opened the file and when. Access is scoped per person and you can pull it back at any point.

How the storage actually works

Versioning
Every upload is a version, not an overwrite. Full lineage per asset.
Integrity
Uploads are byte-verified on commit, so a truncated transfer fails loudly instead of silently.
Metadata
Category, ISRC, credits, and bookmarks travel with the file.
Lifecycle
Live, archived, and restorable states, so cleaning up is not deleting.
Sharing
Server-issued links with enforced passwords and open tracking.
Isolation
Per-user access is enforced at the database level, not just hidden in the interface.

Questions people actually ask.

What is the best way to send stems to a collaborator?

A link beats an attachment every time: no size ceiling, no duplicated copies drifting apart, and you keep control after you hit send. WavBox issues share links from the server with password enforcement and open tracking, so you can see who actually opened the stems and revoke access when the session is over.

How does SESSION handle version control for music?

Every upload is stored as a version rather than replacing what came before, and each version keeps its own lineage, credits, and metadata. That means "which mix did I send in March" is a question with an answer instead of a folder-archaeology problem.

Can collaborators see each other files?

No. Access is scoped per user and enforced with row-level security in the database itself, with writes restricted to server-side functions. That means isolation does not depend on the interface hiding the right buttons — it holds even if someone talks directly to the API.

Are password-protected share links really secure?

Server-issued links are, because the password is checked on the server before the file is released. SESSION also has an offline fallback for links created without a cloud-backed asset, and that fallback checks in the browser — treat it as convenience rather than security, and use server-issued links for anything sensitive.

The rest of the record.

This is one rung. SESSION carries the same record through protection, mastering, storage, audience, and the money it earns.

Be there when the first wave opens.

Response promise: access requests receive a reply within one business day.

One email when your wave opens. No newsletter, no resale. See our privacy policy.

Request access