Skip to content
Home Company FAQ
FAQ

Common questions, answered straight

A reference for buyers, IT, and security teams evaluating SendSafely. For product how-tos and account help, visit our support knowledge base.

Security and encryption

How SendSafely protects your data

The architecture that keeps file contents out of reach, even from us.

What is SendSafely and what does it do?

SendSafely is an end-to-end encrypted data transfer platform built so sensitive data stays private. Data is encrypted on the sender's device before transmission, and only authorized recipients can decrypt and access it — SendSafely's servers see only the encrypted ciphertext.

  • Easy to use. Works in every major browser. No software to install, no encryption keys to manage, and recipients don't need a SendSafely account.
  • Compliant. Built to support HIPAA, GDPR, CCPA, and PCI DSS workflows.
  • Integrated. Native plug-ins for Gmail, Outlook, Slack, Intercom, Freshdesk, Zendesk, Salesforce, and a full REST API.
  • Enterprise-ready. SAML SSO, SCIM provisioning, admin reporting, custom branding, and audit logging.

Learn more about the SendSafely company founding story or visit our Trust Center.

What encryption does SendSafely use?

SendSafely uses the OpenPGP message format (RFC 4880) with AES-256 symmetric encryption. The decryption key is split between the sender and our servers using a model we call split-key architecture — neither half on its own can decrypt the file. Each package sent through SendSafely is encrypted using a unique AES key specific to only that package and that package only.

  1. Client Secret. A 256-bit random value generated locally in the sender's browser, embedded in the URL fragment of the secure link.
  2. Server Secret. A 256-bit random value generated and stored by SendSafely's servers, delivered to the recipient only after successful identity verification.
  3. Key derivation. The final AES-256 key is derived by combining both secrets (forming a 512-bit passphrase) using the OpenPGP Iterated and Salted S2K method. This happens entirely in the recipient's browser.

The result: SendSafely stores your content as encrypted ciphertext only and never stores the full key material required for decryption. This means that we (SendSafely) cannot decrypt your files or messages sent or received through the SendSafely platform. Please note - limited account metadata and audit logs do exist and may be subject to lawful requests.

Learn more about SendSafely's encryption and/or visit our Trust Center.

What types of data can I send with SendSafely?

Any file type. As long as the file fits within your plan's size limit, you can send it.

What size files can I send?

File-size limits vary by plan and product. See the Help Center for current organization plan limits and individual plan limits.

How is SendSafely different from other file transfer tools?

SendSafely uses a split-key, end-to-end encrypted architecture. The decryption key is generated client-side and split between the sender (Client Secret) and our servers (Server Secret), so no single party — including SendSafely — ever holds the full key.

Decryption happens in the recipient's browser, which means file contents never touch our infrastructure in plaintext. This is fundamentally different from consumer file-share services and legacy file-share platforms, where the provider holds keys (or the data) and is technically able to read it. SendSafely is built for regulated environments: granular access controls, detailed audit logging, and compliance-grade reporting.

Recipients also don't need an account. Secure links combine identity verification (one-time passcode by email or SMS) with browser-native decryption, so the experience is frictionless without sacrificing security.

Where are SendSafely's servers located?

SendSafely runs entirely on Amazon Web Services with multi-availability-zone architecture.

Default hosting

US East (Northern Virginia) with backup in EU West (Ireland). This applies to standard customers unless otherwise specified.

Optional regional hosting (Business and Enterprise plans)
  • United States: AWS regions in Virginia and Oregon
  • European Union: AWS regions in Ireland or Frankfurt — supports GDPR-aligned data residency
  • Australia: AWS Sydney region — common for the Australian Privacy Act
  • Custom AWS S3 buckets: Business and Enterprise customers can configure SendSafely to use their own buckets in the region of their choice
Plans and pricing

What you get on each plan

From a free individual plan to Enterprise with HALO, Actions, and Slack.

Is there a free trial of SendSafely?

Yes. Every new individual (non-business) signup includes a 14-day free Pro trial, limited to 2 GB per upload. No credit card required.

Organizations interested in business features — custom branding, SSO, API access, HALO, Actions, and advanced admin controls — can request an Enterprise trial. Contact sales@sendsafely.com or request a demo to get started.

What plans are available for individuals, teams, and enterprises?

SendSafely offers individual plans and organization plans. See the pricing page for current details.

Individual plans
  • Personal (Free). 50 MB per month, OpenPGP encryption, two-factor login, download tracking, expiration control.
  • Basic. 250 MB per month with all Personal features.
  • Pro. 100 GB per month with API access, Dropzones, platform integrations, and secure Workspaces.
Organization plans
  • Team. 5-25 users. Large encrypted transfer, Gmail and Outlook integration, company branding, Dropzones, Workspaces, SSO, SOC 2 Type 2, PCI DSS, GDPR and CCPA DPA.
  • Business. 8-50 users. Everything in Team plus premium white-label branding, ticketing integrations, advanced Workspace controls, watermarking, API access, geographic data storage, and advanced reporting.
  • Enterprise. Unlimited users. Everything in Business plus unlimited Dropzones and Workspaces, advanced audit logging, multi-region storage, SendSafely Actions, Slack integration, HALO, and dedicated success and onboarding.
Does SendSafely charge per user or per transfer?

Organization plans are priced per-organization with a user range, not per transfer. Each plan has a user band — for example Team covers 5-25 users, Business covers 8-50, and Enterprise is unlimited. API-driven automation pricing is available for high-volume use cases — contact sales@sendsafely.com for details.

Compliance

Audits, certifications, and regulated workflows

What we are certified for, where to find proof, and how we support regulated industries.

Is SendSafely HIPAA compliant?

Yes. SendSafely is designed to support compliance with HIPAA and is widely used by healthcare providers, payers, and health-tech companies to exchange protected health information. We offer Business Associate Agreements for Covered Entities and Business Associates on Enterprise plans.

Does SendSafely support GDPR and CCPA?

Yes. SendSafely is designed to help organizations meet both the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). The split-key architecture and end-to-end encryption align naturally with the privacy principles in both regulations.

We offer a Data Processing Addendum with EU Standard Contractual Clauses (Decision 2021/914), and EU hosting is available in Ireland or Frankfurt for data residency requirements.

Which certifications and standards does SendSafely maintain?
  • SOC 2 Type 2. Annual independent audits per the AICPA Trust Service Criteria. Reports are available to Business and Enterprise customers.
  • HIPAA. BAAs available on Enterprise plans.
  • PCI DSS. Payment Card Industry Data Security Standard compliance.
  • GDPR. DPA with EU Standard Contractual Clauses; EU hosting in Ireland or Frankfurt.
  • CCPA. Privacy controls aligned with California Consumer Privacy Act requirements.

Security documentation, SOC 2 Type 2 reports, and compliance questionnaires are available at sendsafely.safebase.us.

What reporting and audit logs are available to admins?

SendSafely captures detailed audit logs for every upload, download, identity verification, admin task, and user activity event. Logs are essential for HIPAA, GDPR, CCPA, and PCI DSS programs and can be integrated with your SIEM.

  • Advanced Reporting. Organization-wide activity reports on Business and Enterprise plans.
  • Audit Log API. Programmatic access to event logs with 90-day retention. Enterprise plan.
  • S3 Export. Long-term retention via export to your own AWS S3 bucket.
What are common use cases in regulated industries?

SendSafely is used across legal, financial services, healthcare, government, and education to transmit sensitive data while meeting HIPAA, GDPR, CCPA, PCI DSS, FINRA, and FERPA requirements.

Legal
  • Client document intake — contracts, IDs, case files — without exposing data to email or unencrypted cloud storage
  • Discovery and litigation file exchange between counsel, opposing counsel, and courts
  • Privileged communications protected from third-party platforms
Financial services
  • KYC and AML document collection — IDs, utility bills, income verification
  • Tax and financial reporting exchange aligned with SEC and FINRA
  • Loan and investment application intake via Dropzones or API
Healthcare
  • HIPAA-compliant patient record exchange — PHI, lab results, insurance documents
  • Medical intake and referrals without forcing patients to create accounts
  • Telehealth and specialist coordination with full audit trail
Integrations and API

Where SendSafely fits in your stack

Email, helpdesks, CRMs, AI chatbots, and developer APIs.

Can SendSafely be integrated with Microsoft Outlook or Gmail?

Yes. SendSafely offers native integrations for both Microsoft Outlook and Gmail. Users send encrypted files and messages directly from their inbox without changing existing email workflows. Outlook supports background uploads — the email sends automatically once the large file finishes uploading.

Enterprise customers can also use the SendSafely Serverless Email Gateway (SEG) for policy-based email encryption. The SEG integrates with Microsoft 365 and Google Workspace and runs in AWS Lambda, allowing organizations to automatically protect inbound or outbound email based on rules in their email platform or data loss prevention system.

Does SendSafely offer an API for developers?

Yes. SendSafely provides a full REST API with client libraries for Python, Java, .NET, and Node.js. The SDKs handle key generation, OpenPGP encryption, large-file segmentation, and server communication automatically — so secure file uploads, downloads, and recipient management can be wired into internal tools, support automation, or customer-facing portals.

API access requires Business plan or above. The Audit Log API requires Enterprise.

Can I embed SendSafely in my website or customer portal?

Yes. Two main paths, depending on how much control you want over the user experience.

1. Dropzone embeddable JavaScript widget
  • A prebuilt, customizable upload widget you can drop onto any web page.
  • Files are encrypted client-side before upload. External users — customers, applicants, claimants — submit files without creating an account.
2. Custom integration with our SDKs and REST API
  • Build a fully branded upload or data-transfer experience using SendSafely's client SDKs and REST API.
  • Embed secure file exchange into existing portals, customer dashboards, or business applications and integrate with your own ticketing, intake, or document-processing workflows.
How does SendSafely work with Salesforce, Zendesk, Freshdesk, and Intercom?

SendSafely has native integrations for Salesforce, Zendesk, Freshdesk, and Intercom that let agents collect and send encrypted files from inside the platforms they already use.

  • Zendesk. Agent App for in-workspace file management, Dropzone with Connector for external collection, and HALO for Zendesk Messenger.
  • Salesforce. Dropzone with Connector for case linking and HALO for Agentforce chats.
  • Freshdesk. Dropzone with Freshdesk Connector for file collection outside the support portal.
  • Intercom. End-to-end encrypted file collection within Intercom Messenger and Fin AI workflows, plus secure messaging for things like SSNs, API keys, and passwords.

Sensitive data — PHI, PII, payment details — stays encrypted and never enters the helpdesk's infrastructure in the clear. Automated expiration, access limits, and audit logging help with HIPAA, GDPR, and CCPA.

Can SendSafely be used by AI agents in automated workflows?

Yes. SendSafely can be wired into AI agent and bot workflows so the agent can request and route sensitive files — IDs, financial documents, PII — without ever decrypting them. Whether you're automating ticket triage, onboarding, compliance collection, or customer service, sensitive files never touch untrusted infrastructure, chatbot logs, or AI training data.

How does SendSafely integrate with AI chatbots?

HALO is the SendSafely product for AI chatbots. It's a security layer, not an AI product — it never performs inference, training, or content processing.

  • HALO Native. Deep integrations for Zendesk Messenger and Intercom Fin that feel like part of the existing UI.
  • HALO Send. Drop-in secure upload modal that appears inside the chat window. Drag-and-drop, files up to 100 GB, client-side encryption.
  • HALO Bridge. Standardized APIs for handoffs between AI and human agents. Works with Ada, Amazon Connect, Agentforce, Forethought, and other platforms.
  • SendSafely Actions. Triggers automated downstream tasks — ID verification, OCR, archival — on collected files.
  • REST API. Build custom flows to create packages, retrieve submissions, or trigger events from any chatbot or AI surface.

By default, the AI agent collects files but cannot access them. Only a handoff to a human agent or authorized backend can decrypt the contents. HALO is available on the SendSafely Enterprise plan.

Can I automate workflows in SendSafely?

Yes. SendSafely Actions is a low-code, no-code automation engine for encrypted workflows. Actions run in response to events in your SendSafely environment — a secure package being finalized, a Dropzone upload, or a Workspace file change — and they're configured through a point-and-click editor in the admin console.

Common Action workflows:

  • Anti-virus scanning. Scan every inbound file with your AV solution and delete quarantined files automatically.
  • Data loss prevention. Run outbound files through your DLP and block restricted content.
  • Document archival. Archive a copy of every encrypted package for compliance retention.
  • ID scanning and file renaming. Auto-process identification documents and rename with self-describing identifiers.
  • Document analysis. Analyze Dropzone uploads and route a copy to the appropriate Workspace.

External actions deploy inside the customer's AWS environment, so third-party tools can decrypt with API credentials within the customer's trust boundary. Actions are available on the Enterprise plan.

Account and recipients

What recipients see, and what you can control

The recipient experience, identity verification, and access controls for senders.

Can I send files to people without a SendSafely account?

Yes — and that's one of SendSafely's core features. Recipients do not need to register or log in. As long as they have the secure link and pass the identity verification you configured (one-time passcode by email or SMS), they can access the files in any modern browser, on any device.

How do recipients verify their identity?

Recipients click the secure link and verify with a one-time passcode sent by email or SMS. SMS verification is configurable per recipient. For external recipients who already use an identity provider, Guest SSO lets them authenticate via their IdP instead of a one-time passcode — available on Business and Enterprise plans.

Can I set expiration dates or revoke access to sent files?

Yes. You can set expiration dates and revoke access at any time. Additional access controls:

  • Access limits. Cap the number of times a recipient can view or download files.
  • View-only mode. Restrict downloads and allow in-browser preview only.
  • Watermarking. Overlay recipient email on sensitive PDFs and images for traceability.
  • File expiration. Automatic deletion of encrypted files after a configurable period. Audit trail preserved after deletion.
Does SendSafely support SSO and provisioning?

Yes. SAML SSO works with any SAML 2.0 identity provider, and Google Workspace is supported via OpenID Connect. SCIM provisioning via Okta automates user provisioning, deprovisioning, admin-rights management, and bulk operations. Guest SSO lets external recipients authenticate via an IdP, on Business and Enterprise plans.

Can recipients reply with files of their own?

Yes. Recipients of any item sent via SendSafely can reply back with files of their own through the same secure link, with the same end-to-end encryption. No account, no software install — and the original sender gets the response with full audit trail.

Sales and procurement questions

Plans, pricing, security reviews, Audit reports, or anything else a buyer or IT team needs before signing.

Email sales@sendsafely.com

Product and account help

How-to guides, admin docs, and troubleshooting for existing SendSafely users.

Visit the support center
Split-key architecture

Files are encrypted before they reach any server

Every file is encrypted on the sender's device using OpenPGP. SendSafely sees ciphertext only — the decryption key is split so nobody, not even SendSafely, can read the contents on its own.

Audited annually. SendSafely maintains the certifications regulated industries require.

Compliance & certifications
SOC 2 Type 2 HIPAA PCI DSS GDPR CCPA
Client-side OpenPGP
Files are encrypted on the device before they ever leave it.
Split-key architecture
The decryption key is split so no single party—including SendSafely—can decrypt file contents on its own.
Full audit trail
Every send, recipient open, identity check, and download is logged with timestamps for compliance reporting.
Get started

Bring encryption into the tools your team already uses.

See how SendSafely fits into email, helpdesks, AI chatbots, and custom workflows.