Private file transfer,
engineered for trust.

AES-GCM encrypted, WebRTC peer-to-peer. Your files are encrypted in your browser and delivered directly — never stored on our servers.

contract-signed.pdf

Ready to send securely

You
Encrypted · Direct
Recipient
Your file never touches our servers
No account required to receive
Link expires automatically within an hour
End-to-end encrypted
WebRTC peer-to-peer
Files never stored
No account to receive

How it works

Simple. Private. Direct.

Three steps from your file to your recipient — no accounts, no waiting, no server ever reading your files.

1

Drop your file

Select any file from your device. No registration, no upload limits, no waiting in a queue.

Any file type & size
2

Share the secure link

A one-time link is generated. The encryption key lives in the URL fragment — it never reaches us.

Zero-knowledge link
3

Direct encrypted transfer

Your recipient opens the link and the file streams directly, browser-to-browser. Encrypted the entire way.

Peer-to-peer · AES-GCM

Security architecture

Built with privacy by default,not as an afterthought.

Every technical decision in SaferDrop was made to minimize what we — or anyone else — could ever know about your files.

AES-256-GCM Encryption

Military-grade authenticated encryption. A unique key is generated for every transfer and never leaves your browser.

WebRTC Peer-to-Peer

Files stream browser-to-browser over WebRTC, peer-to-peer whenever the network allows. No relay ever sees your content — it stays encrypted end-to-end.

Zero Knowledge

The encryption key lives only in the URL fragment — a part the browser never sends to a server. We see nothing.

Ephemeral Links

Each link is a short-lived session for one recipient that expires automatically within an hour — then it's gone. No lingering access.

No Account Required

Recipients receive files without creating an account. No email, no tracking, no data collection on either side.

Integrity Verified

Every chunk is signed with a rolling SHA-256 chain hash. Tampering is detected and the transfer is aborted.

The secure way to send files

A secure file transfer that never touches a server

Most ways to send files securely still leave a readable copy somewhere — an attachment sitting on a mail server, or a cloud link pointing at a stored file. SaferDrop takes a different route. Your file is encrypted in your browser with AES-256-GCM and streams peer-to-peer straight to your recipient, so it is never uploaded to storage and no server ever holds a readable copy.

That makes it a genuine end-to-end encrypted file transfer: the decryption key lives only in the link's URL fragment, which browsers never send to us, and a separate PIN gates access. It works for everyday documents and for large files alike — no account, no install for the person receiving. New to the idea? Start with our guide on how to send files securely.

Privacy-first

Built for those who can't afford to trust blindly.

Some files can't afford to be seen. SaferDrop was built for exactly those moments — when the stakes are high enough that "probably secure" isn't good enough.

256-bit

AES-GCM key strength,
unique per transfer

0

Bytes stored on
our servers

100%

End-to-end encrypted,
every transfer

0

Accounts required
to receive files

Frequently asked questions

How do I send files securely?
Use a tool that encrypts the file in your browser before anything is sent and delivers it directly to the recipient, so no server keeps a readable copy. With SaferDrop you pick a file, share the generated link plus a one-time PIN over a separate channel, and the recipient decrypts it in their browser — no account, no install.
Is it safe to send files by email?
Plain email attachments aren't end-to-end encrypted: the file is copied across mail servers and lingers in inboxes. The safer pattern is to email a link to an end-to-end encrypted transfer instead of the file itself, and share the PIN separately.
Does SaferDrop store my files?
No. Files stream browser to browser over WebRTC and are never uploaded to a server. The encryption key stays in the link's URL fragment, which browsers never send to us, so there's no readable copy to leak and nothing for us to hand over.
Do recipients need an account to receive a file?
No. Recipients open the link in any modern browser and enter the PIN — no account, no install. Sending is free for files up to 100 MB, with 2 GB and folders on the Pro plan.

Ready to send your first file?

No account. Encrypted in your browser, streamed to your recipient — no server ever reads your files.