Encrypted File Sharing · Client-Side · Zero-Knowledge

    Encrypted File Sharing,One Toggle Away.

    Most file-sharing tools bury encryption behind a paywall, a settings page, or vague documentation. Sandra puts AES-256-GCM end-to-end encryption one tap away on every transfer, on every plan , including Free. When you turn it on, your files are encrypted in your browser before upload.

    Free. No account required. AES-256-GCM. Auto-expiring. TLS 1.3 in transit, AES-256 at rest by default.

    No account needed · AES-256-GCM · Zero-knowledge · Auto-deletes

    Server-Side Encryption

    Provider encrypts files on their servers. They hold the keys. They can technically access your files. A subpoena, a breach, or a policy change, and your files are exposed.

    Sandra · Client-Side Encryption ✓

    Your device encrypts the file before upload. Sandra's servers receive encrypted data with no access to the key. We are mathematically unable to read your files. Not by policy. By design.

    What Encrypted File Sharing Actually Means

    Four steps. Each one a layer of protection. All of them automatic.

    Fig. 01 · End-to-end encryption
    1Your browser
    TLS 1.3
    Cannot read
    2Sandra's servers
    TLS 1.3
    3Recipient's browser
    The key travels in the link. It never touches Sandra's servers.
    1Your browser
    A unique AES-256-GCM key is generated locally. The file is encrypted on your device, chunk by chunk, before a single byte is uploaded.
    2Sandra's servers
    The key never reaches us. What we store, process, and serve is ciphertext we cannot open. Unreadable by design, not by policy.
    3Recipient's browser
    The link carries the key. The recipient's browser decrypts the file locally. No account, no app, nothing to install.
    4After expiry
    When the link expires or the download limit is reached, the encrypted blob is permanently deleted. No archive, no cold storage.

    How Sandra's end-to-end encryption works: a unique AES-256-GCM key is generated in the sender's browser, the file is encrypted before upload, Sandra stores an unreadable blob, and the decryption key travels inside the link straight to the recipient's browser.

    Encrypted and Ephemeral

    Sandra combines encryption with expiration. Your files don't just stay private, they disappear. Set an expiry time, a download limit, or both. After that, the file is gone. No cold storage. No archive. No residual copy waiting to be breached.

    Who Needs Encrypted File Sharing?

    Anyone who has ever wondered what happens to their files after sharing, and wanted a better answer.

    Developers

    Environment configs, API key archives, deployment packages: these deserve client-side encryption in transit, not just TLS.

    Designers & Creators

    Client deliverables contain proprietary work. Sharing over standard cloud links exposes them to platform scanning and indefinite storage.

    Journalists & Researchers

    Source materials, interview recordings, sensitive data: encrypted file sharing provides a meaningful layer of protection that standard tools don't offer.

    Individuals

    Passport scans, medical documents, financial statements: personal files that deserve real privacy, not just a terms of service that says they're "safe."

    Frequently Asked Questions

    What is encrypted file sharing?+

    Encrypted file sharing means your files are protected by cryptographic encryption during transfer and storage, so only the intended recipient can access them. Sandra protects every transfer with TLS 1.3 in transit and AES-256 at rest, and offers AES-256-GCM client-side end-to-end encryption as a one-tap toggle on the transfer form (every plan, Free included). When you turn it on, files are encrypted in your browser before upload so even Sandra's servers cannot read the contents.

    What's the difference between client-side and server-side encryption?+

    Server-side encryption means the provider encrypts files on their servers, but they hold the keys, meaning they can technically access your files. Client-side encryption means your device encrypts the file before it's uploaded. The provider never receives the key. Sandra uses client-side encryption.

    Is Sandra's encrypted file sharing free?+

    Yes. Encrypted file sharing is free with no account required. AES-256-GCM client-side encryption is available as a one-tap toggle on every transfer, on every plan, including free anonymous transfers. TLS 1.3 in transit and AES-256 at rest apply to every transfer regardless.

    Can the recipient decrypt the file without an account?+

    Yes. The decryption key is embedded in the transfer link. When the recipient opens the link, their browser automatically decrypts the file during download. No account, no app, no technical knowledge required.

    Do encrypted files on Sandra get stored permanently?+

    No. Sandra combines encryption with expiration. Every transfer link has a configurable expiry. When the link expires or the download limit is reached, the file is permanently deleted. No archive, no cold storage.

    Related Pages

    Share Your Files Encrypted

    AES-256-GCM. Client-side. No account needed. Your files are a locked box by the time they reach our servers.

    Share Files Now · It's Free

    Free up to 5 GB · Zero-knowledge · Auto-deletes after expiry