Review our cryptography. We rely on well-established, trusted algorithms and publish the technical details, so you can understand and validate how SendSafely works.
SendSafely is so easy to use, you won't even notice the cryptography at work behind the scenes. Here's a quick look at how Bob would securely send items to Alice using SendSafely. For a more technical overview, refer to our Security Overview page.
Bob creates an encryption key that will be used to protect the files he wants to send to Alice. The files are encrypted using that key before they are uploaded to SendSafely.
Bob sends Alice a secure link to SendSafely that also includes the Client Secret. The secret is embedded within the URL Anchor of the link, so that it won't be disclosed to the server when the link is clicked.
SendSafely will verify Alice's identity before allowing access to the files.
When Alice follows the link, her identity is verified by SendSafely using a one-time pass code to her email or phone. Once she is verified, the Server Secret and encrypted file is provided to her browser.
Alice's browser is able to re-compute the full key using the Server Secret and the Client Secret (read from the URL anchor) and decrypts the file.
Every file that moves through SendSafely is encrypted on the sender's device with OpenPGP. The platform sees ciphertext only.
SOC 2 Type 2 audited annually. EU customers can host in Ireland or Frankfurt. Independent edgescan testing year-round.
See the split-key flow in your own browser, or request the SOC 2 Type 2 report and talk to our team about your compliance requirements.