A reference for buyers, IT, and security teams evaluating SendSafely. For product how-tos and account help, visit our support knowledge base.
The architecture that keeps file contents out of reach, even from us.
SendSafely is an end-to-end encrypted data transfer platform built so sensitive data stays private. Data is encrypted on the sender's device before transmission, and only authorized recipients can decrypt and access it — SendSafely's servers see only the encrypted ciphertext.
Learn more about the SendSafely company founding story or visit our Trust Center.
SendSafely uses the OpenPGP message format (RFC 4880) with AES-256 symmetric encryption. The decryption key is split between the sender and our servers using a model we call split-key architecture — neither half on its own can decrypt the file. Each package sent through SendSafely is encrypted using a unique AES key specific to only that package and that package only.
The result: SendSafely stores your content as encrypted ciphertext only and never stores the full key material required for decryption. This means that we (SendSafely) cannot decrypt your files or messages sent or received through the SendSafely platform. Please note - limited account metadata and audit logs do exist and may be subject to lawful requests.
Learn more about SendSafely's encryption and/or visit our Trust Center.
Any file type. As long as the file fits within your plan's size limit, you can send it.
File-size limits vary by plan and product. See the Help Center for current organization plan limits and individual plan limits.
SendSafely uses a split-key, end-to-end encrypted architecture. The decryption key is generated client-side and split between the sender (Client Secret) and our servers (Server Secret), so no single party — including SendSafely — ever holds the full key.
Decryption happens in the recipient's browser, which means file contents never touch our infrastructure in plaintext. This is fundamentally different from consumer file-share services and legacy file-share platforms, where the provider holds keys (or the data) and is technically able to read it. SendSafely is built for regulated environments: granular access controls, detailed audit logging, and compliance-grade reporting.
Recipients also don't need an account. Secure links combine identity verification (one-time passcode by email or SMS) with browser-native decryption, so the experience is frictionless without sacrificing security.
SendSafely runs entirely on Amazon Web Services with multi-availability-zone architecture.
US East (Northern Virginia) with backup in EU West (Ireland). This applies to standard customers unless otherwise specified.
From a free individual plan to Enterprise with HALO, Actions, and Slack.
Yes. Every new individual (non-business) signup includes a 14-day free Pro trial, limited to 2 GB per upload. No credit card required.
Organizations interested in business features — custom branding, SSO, API access, HALO, Actions, and advanced admin controls — can request an Enterprise trial. Contact sales@sendsafely.com or request a demo to get started.
SendSafely offers individual plans and organization plans. See the pricing page for current details.
Organization plans are priced per-organization with a user range, not per transfer. Each plan has a user band — for example Team covers 5-25 users, Business covers 8-50, and Enterprise is unlimited. API-driven automation pricing is available for high-volume use cases — contact sales@sendsafely.com for details.
What we are certified for, where to find proof, and how we support regulated industries.
Yes. SendSafely is designed to support compliance with HIPAA and is widely used by healthcare providers, payers, and health-tech companies to exchange protected health information. We offer Business Associate Agreements for Covered Entities and Business Associates on Enterprise plans.
Yes. SendSafely is designed to help organizations meet both the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). The split-key architecture and end-to-end encryption align naturally with the privacy principles in both regulations.
We offer a Data Processing Addendum with EU Standard Contractual Clauses (Decision 2021/914), and EU hosting is available in Ireland or Frankfurt for data residency requirements.
Security documentation, SOC 2 Type 2 reports, and compliance questionnaires are available at sendsafely.safebase.us.
SendSafely captures detailed audit logs for every upload, download, identity verification, admin task, and user activity event. Logs are essential for HIPAA, GDPR, CCPA, and PCI DSS programs and can be integrated with your SIEM.
SendSafely is used across legal, financial services, healthcare, government, and education to transmit sensitive data while meeting HIPAA, GDPR, CCPA, PCI DSS, FINRA, and FERPA requirements.
Email, helpdesks, CRMs, AI chatbots, and developer APIs.
Yes. SendSafely offers native integrations for both Microsoft Outlook and Gmail. Users send encrypted files and messages directly from their inbox without changing existing email workflows. Outlook supports background uploads — the email sends automatically once the large file finishes uploading.
Enterprise customers can also use the SendSafely Serverless Email Gateway (SEG) for policy-based email encryption. The SEG integrates with Microsoft 365 and Google Workspace and runs in AWS Lambda, allowing organizations to automatically protect inbound or outbound email based on rules in their email platform or data loss prevention system.
Yes. SendSafely provides a full REST API with client libraries for Python, Java, .NET, and Node.js. The SDKs handle key generation, OpenPGP encryption, large-file segmentation, and server communication automatically — so secure file uploads, downloads, and recipient management can be wired into internal tools, support automation, or customer-facing portals.
API access requires Business plan or above. The Audit Log API requires Enterprise.
Yes. Two main paths, depending on how much control you want over the user experience.
SendSafely has native integrations for Salesforce, Zendesk, Freshdesk, and Intercom that let agents collect and send encrypted files from inside the platforms they already use.
Sensitive data — PHI, PII, payment details — stays encrypted and never enters the helpdesk's infrastructure in the clear. Automated expiration, access limits, and audit logging help with HIPAA, GDPR, and CCPA.
Yes. SendSafely can be wired into AI agent and bot workflows so the agent can request and route sensitive files — IDs, financial documents, PII — without ever decrypting them. Whether you're automating ticket triage, onboarding, compliance collection, or customer service, sensitive files never touch untrusted infrastructure, chatbot logs, or AI training data.
HALO is the SendSafely product for AI chatbots. It's a security layer, not an AI product — it never performs inference, training, or content processing.
By default, the AI agent collects files but cannot access them. Only a handoff to a human agent or authorized backend can decrypt the contents. HALO is available on the SendSafely Enterprise plan.
Yes. SendSafely Actions is a low-code, no-code automation engine for encrypted workflows. Actions run in response to events in your SendSafely environment — a secure package being finalized, a Dropzone upload, or a Workspace file change — and they're configured through a point-and-click editor in the admin console.
Common Action workflows:
External actions deploy inside the customer's AWS environment, so third-party tools can decrypt with API credentials within the customer's trust boundary. Actions are available on the Enterprise plan.
The recipient experience, identity verification, and access controls for senders.
Yes — and that's one of SendSafely's core features. Recipients do not need to register or log in. As long as they have the secure link and pass the identity verification you configured (one-time passcode by email or SMS), they can access the files in any modern browser, on any device.
Recipients click the secure link and verify with a one-time passcode sent by email or SMS. SMS verification is configurable per recipient. For external recipients who already use an identity provider, Guest SSO lets them authenticate via their IdP instead of a one-time passcode — available on Business and Enterprise plans.
Yes. You can set expiration dates and revoke access at any time. Additional access controls:
Yes. SAML SSO works with any SAML 2.0 identity provider, and Google Workspace is supported via OpenID Connect. SCIM provisioning via Okta automates user provisioning, deprovisioning, admin-rights management, and bulk operations. Guest SSO lets external recipients authenticate via an IdP, on Business and Enterprise plans.
Yes. Recipients of any item sent via SendSafely can reply back with files of their own through the same secure link, with the same end-to-end encryption. No account, no software install — and the original sender gets the response with full audit trail.
Plans, pricing, security reviews, Audit reports, or anything else a buyer or IT team needs before signing.
Email sales@sendsafely.comHow-to guides, admin docs, and troubleshooting for existing SendSafely users.
Visit the support centerEvery file is encrypted on the sender's device using OpenPGP. SendSafely sees ciphertext only — the decryption key is split so nobody, not even SendSafely, can read the contents on its own.
Audited annually. SendSafely maintains the certifications regulated industries require.
See how SendSafely fits into email, helpdesks, AI chatbots, and custom workflows.