Skip to content
Home Features Secure File Transfer
Send & Receive

Send any file, to anyone, end-to-end encrypted

The core SendSafely product. Encrypt files up to 100GB on the sender's device, share a one-time secure link, and let recipients verify identity and download, with no account required on the other end.

One product, two flows

Send a file out, or collect a file in

Every SendSafely user can do both. A simple compose page lets you send encrypted files to anyone with an email address, and a personal URL lets anyone upload encrypted files to you.

Send Item

Send. Verify. Decrypt.

Drag files into the SendSafely web app, or Outlook and Gmail. The browser encrypts each file with OpenPGP on your device before a single byte uploads. The link you share carries half the key in its URL fragment.

1
Compose & attach

Add recipients, an optional message, and any files up to 100GB. Set expiration and SMS verification per recipient.

2
Encrypt locally

Files are encrypted in your browser with OpenPGP. SendSafely sees ciphertext only. A secure link to share with the recipient is generated. 

3
Recipient verifies identity

You share the secure link. A one-time passcode is sent to the recipient by email or SMS to verify identity.

4
Recipient decrypts in browser

The key is reassembled and files are decrypted on their device. Every access is logged.

Receive

Anyone can send you a file.

Every SendSafely user gets a personal URL anyone can use to send them files securely, with or without a SendSafely account. The sender's browser encrypts before upload. The file lands in your portal, audit-logged.

1
Share your personal URL

Paste it in an email, a contract, or a vendor onboarding form. No app, no account, no install required.

2
Sender encrypts client-side

The sender drops files into your hosted upload page. Their browser handles encryption before the files are sent.

3
Package lands in your portal

You're notified the moment the upload completes. The audit log captures the sender, files, IP, and timestamp.

4
You decrypt in your browser

Files decrypt locally on download. The plaintext never touches a SendSafely server.

Send Item, up close

The Send Item composer. Encryption is not a checkbox

Every file added is encrypted in your browser before upload. The recipients and selected security controls are metadata. The plaintext does not exist anywhere except on your machine.

app.sendsafely.com/send/?package=new
Recipients
alex.kim@partner.example× legal@partner.example×
Secure message
Hi Alex, Attached are the signed Q1 contracts and the updated DPA. The package expires in 7 days. Reply through SendSafely if you need anything else. Thanks, The Operations team

Drop files to encrypt and upload

files up to 100GB · encrypted in this browser tab

Q1-contracts-signed.pdf
12.4 MB · End-to-end encrypted
12.4 MB
Sealed
DPA-v3-supporting-docs.zip
apparent size 84.0 MB · encrypting
42% of 84.0 MB
Encrypting
Send options

Expire in 7 days

Configurable per send. Audit trail preserved after deletion.

SMS verification on

One-time passcode sent to recipient mobile for high-assurance sends.

Restrict save & print

For PDFs and images. Document watermarking with recipient email.

Notify on download

Read notifications and geographic location data per access.

Encrypt and send Save draft
Recipient experience

What the other side sees. No account, no software

The recipient opens the secure link, verifies identity with a one-time passcode, and downloads. The cryptographic work runs in their browser. SendSafely never holds the full decryption key.

portal.sendsafely.com/receive/?packageCode=XYZ123#keyCode=7f3e_b91a

Verify it's you

We just emailed a 6-digit code to alex.kim@partner.example. Enter it below to unlock the secure package. The code expires in 10 minutes.

4
8
2
9
OTP via email · SMS available Verify and decrypt

Package contents

From operations@your-company.example · 2 files · expires in 7 days · sealed

Q1-contracts-signed.pdf
12.4 MB · ciphertext on disk · decrypted on open
Download
DPA-v3-supporting-docs.zip
84.0 MB · ciphertext on disk · decrypted on open
Download
decryption key reassembled in this browser
How it stacks up

Email attachments and consumer file shares weren't built for this

Compare what regulated teams need with what they actually get from email and consumer sharing. SendSafely is the encryption layer the rest of your stack is missing.

Requirement
Option A Email attachment
Option B Consumer file share
SendSafely Send & Receive
End-to-end encryption Plaintext never reaches a provider server
Transport only
At-rest, provider-managed
OpenPGP, client-side
File size limit What you can actually send
10–25 MB typical
Varies by plan
Up to 100 GB
Recipient identity verification Proof of who actually opened the file
None
None
OTP via email or SMS
Full audit trail Sender, recipient, IP, timestamp for every access
Mail headers only
Limited, admin-only
Per-package, SIEM-ready
Expiration and revocation Time-bound access, recallable on demand
Forever, by default
Manual delete
Per-send expiration, revoke any time
Recipient account required Friction for the other side
No
Often required
No · one-click verify
Compliance posture Reports a regulator will accept
None inherent
Varies, often consumer-grade
SOC 2 Type 2, HIPAA, PCI, GDPR
Inside Send & Receive

Everything you need to securely send and receive sensitive files.

Built into the product - not bolted on. Security features that are easy to use and satisfy the compliance requirements of regulated organizations.

Files up to 100 GB

No file type restrictions. Large transfers stream client-side encrypted and resume on connection drops.

Automatic expiration

Files self-delete on a configurable schedule. The audit trail is preserved long after the bytes are gone.

SMS verification

One-time passcodes delivered to recipient mobile numbers for high-assurance sends. 

Guest SSO

External recipients can authenticate via your own identity provider instead of OTP. Business and Enterprise.

Personal Receive URL

Each user gets their own URL anyone can use to send them encrypted files securely, with or without an account.

Access tracking

Read notifications with timestamps and IP addresses. Revoke access at any time, or add new recipients after sending.

Restrict save & watermark

Block file save and print for PDFs and images. Watermarking with recipient email overlay on every page.

Audit log + SIEM export

Every send, open, and download captured with timestamps. Programmatic Audit Log API on Enterprise; export to AWS S3.

Split-key architecture

Files are encrypted before they reach any server

Files in Send & Receive are encrypted on the sender's device with OpenPGP before upload. SendSafely sees ciphertext only. The decryption key is split between the server and a token in the secure link, so nobody, not even SendSafely, can read the contents on its own.

Audited annually. SendSafely maintains the certifications regulated industries require.

Compliance & certifications
SOC 2 Type 2 HIPAA PCI DSS GDPR CCPA
Client-side OpenPGP
Files are encrypted on the device before they ever leave it.
Split-key architecture
The decryption key is split so no single party—including SendSafely—can decrypt file contents on its own.
Full audit trail
Every send, recipient open, identity check, and download is logged with timestamps for compliance reporting.
Get started

Encrypt the files your team is already sending.

See Send & Receive in the SendSafely demo, or start a free trial. Files up to 100GB, end-to-end encrypted, no recipient account required.