Files in. Files out.
Nothing left lying around.
A one-time locker, not an inbox. It forgets on purpose.
Encrypted in transit (HTTPS)Encrypted at rest (authenticated encryption)
This is a private file-exchange service. There is nothing to browse here and nothing to sign up for. You reach a file only through a link someone sent you, and each link opens exactly one thing.
Been sent a link?
Here is what should happen. If yours behaves differently, treat it with suspicion.
- You received a link to this domain ending in /u/… to send a file, or /d/… to collect one.
- You received a PIN by a different route - a phone call, a text, a separate message. A genuine sender never puts the link and the PIN in the same email.
- You open the link, enter the PIN, and send or collect one file.
- The link then stops working. Collected files are deleted immediately; anything not collected is deleted when the link expires.
What we do with a file while we have it
- Checked before it is stored. Every uploaded file is scanned for known malware. If the scanner cannot run, the upload is refused rather than accepted unchecked.
- Encrypted at rest with authenticated encryption, under a key held by the operator, on storage no web request can browse.
- Never opened or previewed. Files are stored and handed on, never parsed, rendered or executed.
- Deleted promptly - on collection, on expiry, or when the operator revokes the link.
- Logged - who created a link, and when a file was uploaded, collected or deleted.
Being straight with you: malware scanning catches known threats, so a clean result means "no known threats found", not a guarantee. Nothing here is a substitute for your own caution about what you send and to whom.
Not expecting this?
Do not enter a PIN if any of these apply:
- The link and the PIN arrived together in the same message.
- You were not told to expect a file by someone you already deal with.
- The message pressures you to hurry, or threatens a consequence.
- The address in your browser is not exactly this domain.
Check with the organisation that sent you the link using contact details you already have - from a previous email, an invoice, or their published website. Never the details in the suspicious message itself.
Operator? Sign in.