I would love to hear more. I had a gig where we considered S3 and B2 for serving very private files (financial records). With B2 I could not find a good way to ensure that, assuming the URL is known, a file could only be accessed by an authorized party.