The way you share files today is probably not safe

How to Send a File Securely

Every day, billions of files are shared over the internet using methods that are laughably insecure. This guide explains why — and what to do instead.

8.2 billion

Records exposed in data breaches last year

68%

Of breaches involve a human element — a forwarded file, a wrong inbox

$4.88M

Average cost of a data breach in 2024 (IBM)

Common methods, uncommon risk

Why "Good Enough" Is Not Good Enough

These are the six most popular ways people share files — and a real-world scenario showing exactly how each one can go catastrophically wrong.

Email Attachments

Risk: Critical
  • Stored in plain text on mail servers you don't control
  • Visible to your email provider's staff & algorithms
  • A single phished password exposes every file you've ever sent
  • No way to "unsend" once the recipient's inbox is compromised

Real-world scenario

"A law firm emails a client's signed contract. The email bounces through six different mail servers in three countries before arriving — every hop a potential interception point. The attachment sits in both the sender's Sent folder and the recipient's inbox, unencrypted, forever."

Consumer Cloud Links (Google Drive, Dropbox)

Risk: High
  • "Anyone with the link" means exactly that — anyone, forever
  • Links live in browser history, chat logs, and server access logs
  • The provider scans your files for ads, training data, and policy violations
  • Revoking access after the fact is often too late

Real-world scenario

"A recruiter shares a candidate's resume via a "anyone with the link" Google Drive URL. That link gets forwarded, shared in a Slack channel, and eventually indexed by a search engine. Three years later a stranger finds the candidate's home address and salary history."

Messaging Apps (WhatsApp, Telegram, Slack)

Risk: High
  • Cloud backups bypass the app's own encryption
  • Corporate Slack workspaces are visible to admins and eDiscovery
  • No control over how long files are retained on remote servers
  • Group chats mean every member can download and re-share your file

Real-world scenario

"An accountant DMs a client's tax return PDF over WhatsApp. The file is automatically backed up to iCloud on both devices, cached on WhatsApp's servers, and synced to every other device signed into the same Apple ID — including the client's teenager's iPad."

USB Drives & Physical Media

Risk: Medium
  • Physical loss is a 100% data breach with no recovery option
  • No audit trail — you never know who accessed the drive
  • Malware on the recipient's machine can silently copy every file
  • Mailing drives invites interception by postal authorities or couriers

Real-world scenario

"A hospital employee copies patient records to a USB drive to take home for a weekend project. The drive falls out of their bag on the subway. A stranger plugs it in out of curiosity. HIPAA violation. $1.9 million fine. Career over."

Public Wi-Fi Transfers (AirDrop, FTP, SMB)

Risk: Critical
  • Unencrypted protocols (FTP, HTTP) transmit files in plain text
  • Man-in-the-middle attacks on open Wi-Fi are trivially easy
  • AirDrop history exploits have exposed device identities in crowds
  • No authentication means anyone on the network can join the transfer

Real-world scenario

"A consultant uses an airport's free Wi-Fi to FTP a proposal to a client. A threat actor running a Wi-Fi honeypot captures the entire transfer in seconds. The proposal — containing the client's unreleased product roadmap — appears on a competitor's desk by Monday."

"Secure" Corporate VPN + Shared Drives

Risk: Medium
  • Broad network permissions mean colleagues see more than intended
  • Insider threats account for 34% of all data breaches (Verizon DBIR)
  • VPNs protect data in transit but nothing on the server itself
  • Access is rarely revoked when it should be

Real-world scenario

"An employee saves a confidential merger document to the company's shared network drive "just temporarily." A disgruntled colleague in a different department stumbles on it. By 9 a.m. it's in the hands of a journalist. The acquisition collapses."

The Three Vectors Every Attacker Exploits

File breaches almost always fall into one of three categories. Understanding them is the first step to protecting yourself.

01

Data in Transit

Your file travels across dozens of routers and switches between you and the recipient. Any unencrypted hop is an opportunity for interception. HTTPS helps, but only up to the server — after that, the file often sits unencrypted.

02

Data at Rest

Once a file lands on a server — yours, theirs, a mail relay — it usually sits in plaintext storage. A single database compromise or misconfigured S3 bucket exposes everything. Most consumer services do not encrypt at rest.

03

Access Control

Permanent links, shared passwords, and over-permissioned accounts mean the right person gets access today — and the wrong person gets access indefinitely. There is no expiry, no audit, and no way to revoke.

The CipherSend difference

Every Vector. Covered.

CipherSend was designed from the ground up to eliminate all three attack surfaces — not as an afterthought, but as the core architectural principle.

AES-256 Encryption at Rest

Every file is encrypted on your device before it ever leaves. The server stores only ciphertext — even a full breach of our infrastructure exposes nothing readable.

Unique Per-File Keys

Each file gets its own randomly-generated encryption key. Compromising one file is mathematically impossible to leverage against any other.

Auto-Expiring Links

Set links to expire in 1 hour, 24 hours, or up to 30 days. Once expired, the download link returns 404 — even if someone bookmarked or forwarded it.

Password-Protected Downloads

Add a one-time password to any share. Even if your email is intercepted, the file stays locked without the passphrase you share through a separate channel.

Full Audit Trail

Every download is logged with timestamp and IP. Know exactly who accessed your file — and when. Share the audit log with compliance teams in one click.

Zero Plaintext Storage

We never store unencrypted files. Our servers are architected so that database administrators, engineers, and even court orders cannot produce the original file contents.

How CipherSend Stacks Up

Head-to-head against the alternatives

FeatureEmailDrive/DropboxCipherSend
End-to-end encryption
Encrypted at rest
Link expirationPartial
Password protectionPartial
Download audit logPaid only
Instant revocation
No provider scanning
No account for recipient

Send a File Securely in 4 Steps

No PhD in cryptography required.

Upload your file

Drag and drop any file up to 5 GB. It is encrypted client-side before upload begins.

Set your rules

Choose expiration, download limits, and an optional password. You decide how long the file lives.

Send the link

CipherSend emails a branded download link directly to your recipient — no account required on their end.

Track and revoke

Monitor downloads in real time. Revoke access instantly if plans change.

Stop Gambling With Your Files

It takes 30 seconds to create an account and send your first encrypted file. Free, forever, for everyday use.