Skip to content
Developer API Dropzone Widget
Dropzone widget

End-to-end encrypted file collection, embedded in your site.

An embeddable Dropzone upload widget for collecting encrypted files from anyone. One script tag on any page, portal, or helpdesk — white-label, mobile-ready, with files encrypted in the visitor's browser before they ever reach a server.

<script> new SendSafelyDropzone(...).initialize()
How to wire it up Integration guide
Three surfaces, one widget

One Dropzone, deployed three ways

Same client-side encryption, same connectors, same audit trail. Pick the surface that fits the page you're embedding into.

JS widget
Embeddable JS widget

A single script tag on your existing web form. Drag-and-drop or click-to-upload. Files are encrypted in the visitor's browser and uploaded directly to SendSafely — never to your origin.

API reference
AI-powered · Beta
AI Custom Form Builder

Build secure, branded intake forms using natural-language prompts — no coding required. Describe the form you need and the AI assistant generates a responsive, production-ready form with encrypted file uploads, validation, and custom branding, published directly to your SendSafely portal.

Coming soon
How to wire it up

Drop the widget into your form

The widget renders into a DOM element you provide and writes the encrypted package URL plus thread id into hidden inputs your form already submits. Your backend never touches the file. 

What visitors see

Visitors stay on your site — encryption happens silently

The widget renders inside your form. Visitors drag files in like any other upload. OpenPGP encryption runs in their browser before bytes leave the device.

acme.example/support/submit
Acme Support — submit a request
Send us the affected files

Drop your logs, screenshots, or signed forms in the area on the right. Files are encrypted before they leave your browser.

Your email jamie@example.com
Ticket subject Cannot generate Q1 export
Details The export job fails after about ninety seconds. Logs attached.
Attachments
Drop files here
or click to choose · encrypted on this device
End-to-end encrypted
export-error.log 182 KB · encrypted
Encrypted
timeout-screenshot.png 1.4 MB · encrypted
Encrypted
Encryption runs in the visitor's browser. The package URL and thread id are posted with the form — the file bytes go directly to SendSafely.
Customization

White-label by default — control look, behavior, and connectors

The Dropzone is designed to disappear into your brand. Custom logo, custom colors, configurable upload behavior, and a JavaScript API for everything in between.

Logo & colors

Set your own background color, prompt copy, and dimensions so the widget matches your form layout and brand.

Programmatic control

Drive the upload flow from your own interface — start uploads, finalize the package, attach a message or label, and check whether uploads are still in progress.

Submit on your terms

Keep the form on the page after an upload instead of submitting automatically, and fire your Dropzone webhook only when you're ready.

Identify the sender

Stamp each upload with the visitor's email when your form already collected it, so submissions arrive attributed.

Mobile & camera-ready

The widget renders on phones with smartphone camera upload support — works the same whether visitors are at a desk or in the field.

Connectors built in

Route uploads straight into Zendesk, Salesforce, Jira, Freshdesk, Intercom, or 8,000+ apps via Zapier.

Encryption in the visitor's browser

Files are encrypted before they reach your server

The Dropzone widget encrypts each file on the visitor's device using OpenPGP before any bytes leave their browser. Your origin only sees the encrypted package URL and thread id — never the file contents. SendSafely sees ciphertext only.

The 256-bit Client Secret is embedded in the URL fragment, which browsers never send to the server. Recipients verify identity before downloading, and every upload, view, and download is logged for compliance reporting.

Compliance & certifications
SOC 2 Type 2 HIPAA PCI DSS GDPR CCPA
Client-side OpenPGP
Files are encrypted on the device before they ever leave it.
Split-key architecture
The decryption key is split so no single party—including SendSafely—can decrypt file contents on its own.
Full audit trail
Every send, recipient open, identity check, and download is logged with timestamps for compliance reporting.
Where teams embed it

Four common places the Dropzone slots in

Anywhere you already collect a file from a customer is a candidate. Same widget, different page.

Support & helpdesk forms

Replace risky email attachments on your contact-us and customer-support pages. Connectors attach uploads directly to Zendesk, Salesforce, Jira, Freshdesk, or Intercom tickets.

Marketing & intake landing pages

Drop the widget into Marketo, Pardot, or Unbounce landing pages to collect identity documents, signed contracts, or RFP responses without leaving your funnel.

Chat widgets & AI agents

The Dropzone Modal opens inside chat experiences — used by Forethought Solve Chat Widget — so AI agents can collect sensitive files without ever decrypting them.

Regulated intake (KYC, healthcare, legal)

Collect onboarding documents, signed disclosures, or medical files inside your own portal. Audit-logged and  expiration-controlled.

Embed and ship

One script tag. End-to-end encrypted uploads.

Wire the Dropzone widget into your existing form and start collecting encrypted files in an afternoon. Connectors, white-label branding, and the same audit trail across every send.