End-to-end encryption, split-key architecture, detailed audit logs, and flexible retention controls help organizations meet the compliance requirements of regulated industries.
Protecting sensitive data isn't a feature you turn on. It's the foundation of the platform. End-to-end encryption, audit trails, access controls, and retention policies are built into the platform from the ground up.
Files are encrypted on the sender's device using OpenPGP and a 256-bit AES key derived from a 256-bit Server Secret and a 256-bit Client Secret. The Client Secret never reaches SendSafely. Nobody — not even SendSafely — can read your files.
Upload, download, admin, and user events are captured at the file level. Stream them into Splunk, Datadog, or your SIEM via the Audit Log API, or export to a private S3 bucket for long-term retention.
Recipients verify their identity through email PIN, SSO, or trusted-device keys before any file decrypts. Two-step login is supported across every account. Phishing a link doesn't get an attacker the contents.
Pin storage to the US (Virginia or Oregon), the EU (Ireland or Frankfurt), or Sydney — or bring your own AWS S3 bucket. Set automatic expiration on every package; audit trails are preserved after files are deleted.
Complete documentation is available in our Trust Center.
SendSafely is the encrypted file-exchange layer behind compliance programs at financial institutions, hospitals, law firms, insurers, and government contractors. Financial services carries the sector-specific mapping, and All In Credit Union shows GLBA and NIST 800-53 in practice.
KYC, AML, loan onboarding, and client document exchange under PCI DSS, FINRA, and GLBA.
HIPAA-covered PHI exchange — patient intake, referrals, lab results, and insurance claims.
Privileged discovery, opposing-counsel exchange, and client matter files with per-file audit trail.
Claims intake, adjuster file collection, and policyholder document portals — branded as your domain.
FERPA-protected student records and cross-institution exchange with full retention.
The encryption architecture, the AI-customer-service layer, and how regulated customers actually use SendSafely in production.
Walk us through your framework, your auditor's questions, and your data-residency constraints. We'll show you exactly which SendSafely controls map to each one — and where the SOC 2 report fits in.