Secure file transfer
Encrypted before it leaves your device.
Secure file transfer is the movement of files over an encrypted channel, protected in transit and at rest, so only the sender and the recipient can read them. Most services stop at the label: they scan contents, index for search, or store files indefinitely. Sandra works differently.
Every transfer is protected by TLS 1.3 in transit and AES-256 at rest. Toggle E2EE on the transfer form, every plan including Free, to encrypt with AES-256-GCM in your browser before upload. With that on, we are, by design, unable to read your files. Not as a promise, as a technical fact.
Updated July 16, 2026
How it works
How secure is Sandra, exactly?
Here is what happens when you drop a file on Sandra with E2EE on. Your browser encrypts the file locally using AES-256-GCM, the same encryption standard used by banks and government agencies. The encrypted file is uploaded. The decryption key is embedded in the shareable link.
Sandra's servers never receive the key. They receive an encrypted blob they cannot open, process it, and serve it. When you share the link, you are sharing the only copy of the key that exists.
This is called zero-knowledge file transfer: with E2EE enabled, we know nothing about your file contents because the architecture makes it impossible for us to. Available on every plan, including Free.
- 1Your browser
- A unique AES-256-GCM key is generated locally. The file is encrypted on your device, chunk by chunk, before a single byte is uploaded.
- 2Sandra's servers
- The key never reaches us. What we store, process, and serve is ciphertext we cannot open. Unreadable by design, not by policy.
- 3Recipient's browser
- The link carries the key. The recipient's browser decrypts the file locally. No account, no app, nothing to install.
- 4After expiry
- When the link expires or the download limit is reached, the encrypted blob is permanently deleted. No archive, no cold storage.
How Sandra's end-to-end encryption works: a unique AES-256-GCM key is generated in the sender's browser, the file is encrypted before upload, Sandra stores an unreadable blob, and the decryption key travels inside the link straight to the recipient's browser.
The protocols
Which protocol does secure file transfer use?
Four approaches cover almost every secure transfer you will encounter. They solve different problems.
- SFTP
- File transfer over SSH. Server-to-server automation between IT teams: both sides manage credentials and infrastructure.
- FTPS
- Legacy FTP wrapped in TLS. Kept alive by older enterprise systems that already speak FTP.
- HTTPS (TLS 1.3)
- The web's encrypted channel. Anything with a browser can use it, with nothing to install on either side.
- MFT
- Managed file transfer platforms: enterprise suites layering audit, scheduling, and governance over the protocols above.
Sandra uses HTTPS with TLS 1.3 for transport, AES-256 at rest, and optional AES-256-GCM end-to-end encryption applied in the browser. If your counterparty requires an SFTP endpoint, Sandra is not that. If you need people to send and receive securely in a browser, with no credentials, no client software, and no IT setup on their side, that is exactly what Sandra is.
Security
Every layer, active by default
Not locked behind a plan. Stated exactly as it works today.
- E2EE, one tap
- Enable the E2EE toggle on the transfer form and your browser encrypts the file with AES-256-GCM before upload. We receive a locked box. We never have the key. Every plan, including Free.
- Zero-knowledge
- With E2EE on, Sandra's servers process encrypted data they mathematically cannot read. Privacy by design, not by policy.
- Auto-expiry
- Set an expiry date or download limit. Files are permanently deleted afterward. No residual copies.
- No file scanning
- We never open, analyze, or scan your files. Your content remains private from the moment it leaves your device.
- No account
- Secure transfers without an identity trail. No email, no password, nothing stored about who you are.
- Password option
- Add a password to any transfer link. Recipients must enter it before downloading, an extra layer of access control.
Who it serves
When confidentiality is not optional
Legal & compliance
Contracts, NDAs, case files, audit reports
Share privileged material with client-side encryption. No third party can intercept or read the contents.
Healthcare & medical
Health records and diagnostic files
Transmit sensitive medical data with a level of encryption appropriate for confidential health information.
Finance & accounting
Payroll exports, tax records, financial statements
Bank-grade encryption on every transfer, with expiry and download visibility.
What makes a file transfer truly secure?
A truly secure file transfer combines TLS in transit, encryption at rest, and the option of client-side end-to-end encryption (files encrypted before upload, with the provider never seeing the decryption key), auto-expiring links, and no file scanning or tracking. Sandra ships all of these: TLS 1.3 and AES-256-at-rest by default, plus a one-tap E2EE toggle on every transfer, every plan.
How does Sandra's secure file transfer work?
Every transfer goes over TLS 1.3 and is stored encrypted at rest with AES-256. When you toggle the 'E2E encrypted' switch on the transfer form, your browser additionally encrypts each chunk with AES-256-GCM before upload; the decryption key is embedded in the download link's URL fragment and never reaches Sandra's servers. With E2EE on, our infrastructure receives data it mathematically cannot read.
Is secure file transfer free with Sandra?
Yes. Secure transfers up to 5 GB are completely free with no account required. Every transfer is protected by TLS 1.3 in transit and AES-256 at rest, and AES-256-GCM client-side end-to-end encryption is available as a one-tap toggle on every transfer, on every plan, including Free.
Can I use Sandra for confidential business documents?
Yes. For confidential documents (legal contracts, financial data, medical files), enable the E2EE toggle on the transfer form. Files are encrypted in your browser before upload and Sandra cannot read them. Combined with password-protected links and short expiry, it covers most B2B confidentiality requirements. Files are deleted after expiry.
What encryption does Sandra use for file transfers?
Sandra uses AES-256-GCM, the same standard used by financial institutions and governments worldwide. Encryption happens in the browser before upload, and the key is embedded in the transfer link and never touches our servers.
Encrypted in your browser. Gone after expiry.
Free up to 5 GB, no account, no tracking. End-to-end encryption on every plan.
Start your secure transfer