— Specifics, not adjectives

Security & trust

How FileSendX protects your files at every layer — encryption, authentication, access control, data residency, and disclosure.

Encryption.

A · TRANSPORT

TLS 1.3 en transit

All HTTP traffic is forced over TLS 1.3 with HSTS preloading. No plaintext fallback is possible — even an attacker on the network can't downgrade the connection.

B · STORAGE

AES-256 au repos

Files are stored on S3-compatible EU object storage with server-side AES-256 encryption. Even with physical disk access, the data is unreadable.

C · LINKS

URL de téléchargement pré-signées

Download links are not direct S3 URLs — we authorize the request, then mint a one-hour presigned URL and 302 the user to it. Links can't be replayed after the window closes.

D · PASSWORDS

Password-protected files

File passwords are hashed server-side. We can't read them, even if compelled. The recipient enters the password before the download starts.

Authentication.

Two-factor authentication

Available on every plan, including Free. Works with Google Authenticator, Authy, 1Password, Bitwarden, Microsoft Authenticator, and any other standard authenticator app.

Brute-force protection

Login attempts are rate-limited. Repeated failures lock the account temporarily; every attempt is recorded with timestamp and source IP.

Strong password policy

Minimum 12 characters with mixed case, digits, and symbols. Passwords are hashed; we never log them in plaintext.

Single sign-on (SSO)

Standards-compliant SAML on every paid plan. Connect Okta, Microsoft Entra ID, Google Workspace, Keycloak, Auth0, OneLogin, and any major identity provider.

Auto-provisioning (SCIM)

On every paid plan: your IdP creates and removes FileSendX accounts automatically. Offboarding happens the moment your IdP updates.

Access control and audit.

Role-based access control

Two roles per team: member and admin. Members can send and download files; admins additionally manage teammates, billing, SSO/SCIM, and the audit log.

Journal d'audit

Every login, logout, role change, invitation, file send, and admin action is recorded with timestamp and source IP. Available to admins from the team settings.

Destruction après lecture

Default for every transfer. Files are wiped from object storage within two hours of the first successful download. The cleanup runs every five minutes.

Expiring links

7 days on Free, 30 days on Starter and Pro. After expiry the file is deleted from object storage and the database row is removed — recovery is impossible by design.

Data residency.

FileSendX runs entirely inside the European Union. Your files are stored on EU object storage in France — never copied outside the EU, never cached on US infrastructure, never subject to the US CLOUD Act.

Payments are processed by Stripe in Ireland. We provide a complete data-processing agreement and sub-processor list on request — email contact@dynamic-foundries.com.

GDPR.

Account holders can exercise GDPR rights — access, rectification, erasure, portability, objection, restriction — by emailing contact@dynamic-foundries.com with the subject "Data Protection Request". We respond within 30 days.

Full retention details, sub-processor list, and legal basis per data category are in the privacy policy. Read the privacy policy →

Responsible disclosure.

If you've found a security issue, please email contact@dynamic-foundries.com with the subject "Security disclosure". We acknowledge reports within 48 hours and aim to ship a fix within 30 days for high-severity issues.

Please do not test against live user accounts other than your own. If you need a clean test account, ask and we'll provision one.

— Accountability

A French SASU you can hold accountable

Your data, EU jurisdiction. No CLOUD Act, no transatlantic risk.