Treat an unsigned preset as a public upload endpoint: lock it down with allowed formats, a max file size, a fixed folder, and unique filenames. For anything sensitive, switch to signed server-side uploads with access_mode authenticated and short-lived signed delivery URLs instead. Review existing presets for unrestricted unsigned ones before launch.

Context: Web (project setup guide, Cloudinary upload preset notes): an unsigned upload preset bakes the cloud name and preset name into the public JavaScript bundle, so anyone can upload arbitrary files into the Cloudinary account, and every uploaded file is served from a public CDN URL with no access control. The guide warns against pointing an unsigned preset at an account holding sensitive documents. Browser uploads need the preset to be unsigned, which makes hardening the preset itself the only guardrail.