Sandra for confidential work

    An attachment is a copy you no longer control

    Payroll, contracts, financials, personnel records. Sandra moves them through private expiring links instead of attachments and open folders, with end-to-end encryption one tap away when a file must stay sealed. And never any AI training on your data.

    TLS 1.3 in transit
    AES-256 at rest
    Optional end-to-end encryption
    EU infrastructure

    The problem

    Sensitive files leak through habit, not hackers

    The moment a sensitive document leaves as an attachment, you have lost track of it. It can be forwarded in one click, saved to a personal laptop, or sit in an inbox that gets compromised two years from now.

    General-purpose drives add permissions on top, but permissions sprawl. Access granted for one quarter quietly lasts forever, and nobody audits the folder again.

    Sandra’s model is simpler: a private link, an expiry date, and visibility on the download. When the transfer is done, the door closes.

    How teams use Sandra

    Send. Collect. Seal.

    01

    Outbound

    Send under your terms

    Share financials, agreements, board materials, and personnel documents through links that expire on your schedule. Add a password on Pro and check whether the recipient downloaded, when, and from where, instead of hoping the right person opened it.

    02

    Inbound

    Collect without exposure

    Request documents through a private upload link instead of asking people to email them: tax records, signed agreements, onboarding paperwork, due diligence material. The sender needs no account, and nothing sensitive transits an inbox on its way to you.

    03

    Sealed

    When a file must stay unreadable

    For the most sensitive transfers, switch on end-to-end encryption. The file is encrypted in your browser before upload with AES-256-GCM, and the decryption key stays in the link, never on our servers. Nobody in between can open it, including Sandra.

    Security

    Answers for your security review

    The questions a security officer or a cautious counterparty will ask, answered exactly as the product works today.

    In transit
    TLS 1.3 on every upload and download.
    At rest
    AES-256 on stored files, transfers and Vault alike.
    End-to-end option
    AES-256-GCM applied in your browser before upload. The decryption key travels in the link fragment and is never sent to our servers. One tap, on every plan including Free.
    Link expiry
    Every transfer link expires on a schedule you set. Expired files are deleted from transfer storage.
    Access controls
    Password-protected links and download visibility on Pro, so you know when a file was retrieved.
    Content policy
    No scanning, no profiling, no ads, and no AI training on your files. This is a founding constraint of the product, not a setting.
    Hosting
    EU infrastructure for core storage, with GDPR-oriented practices published in the Privacy Policy.

    Common questions

    Asked before the first confidential transfer

    More detail in the full FAQ and the Privacy Policy.

    What does end-to-end encryption change in practice?

    With E2EE on, the file is encrypted in your browser before upload using AES-256-GCM. The decryption key stays in the link itself and never reaches Sandra’s servers, so nobody on our side can read the file. It is a one-tap toggle, available on every plan.

    Can I see whether a file was downloaded?

    Yes. Pro plans include download visibility: when your files were accessed and from where, so a sensitive send is never a shot in the dark.

    What happens when a link expires?

    Its files are deleted from transfer storage. Nothing lingers in a forgotten folder. Documents you need to retain belong in encrypted Vault storage, under your control.

    Is any of this data analyzed, profiled, or used for AI?

    No. Sandra does not scan file contents, build content profiles, serve ads, or train AI models on your data. That constraint is the reason the product exists.

    Where are the files hosted?

    Core storage runs on EU infrastructure and Sandra follows GDPR-oriented practices. The details are published in the Privacy Policy.

    Does the recipient need an account?

    No. Recipients open a private download page in the browser. The only thing they need is the link, plus the password if you set one.

    Get started

    Share work that speaks for itself.

    Built for professionals who need secure, reliable, and elegant file delivery.

    No credit card required · 500GB free transfers