— I. Encryption
Encryption.
A · TRANSPORT
TLS 1.3 en transit
All HTTP traffic is forced over TLS 1.3 with HSTS preloading. No plaintext fallback is possible — even an attacker on the network can't downgrade the connection.
B · STORAGE
AES-256 au repos
Files are stored on S3-compatible EU object storage with server-side AES-256 encryption. Even with physical disk access, the data is unreadable.
C · LINKS
URL de téléchargement pré-signées
Download links are not direct S3 URLs — we authorize the request, then mint a one-hour presigned URL and 302 the user to it. Links can't be replayed after the window closes.
D · PASSWORDS
Password-protected files
File passwords are hashed server-side. We can't read them, even if compelled. The recipient enters the password before the download starts.
— II. Authentication
Authentication.
Two-factor authentication
Available on every plan, including Free. Works with Google Authenticator, Authy, 1Password, Bitwarden, Microsoft Authenticator, and any other standard authenticator app.
Brute-force protection
Login attempts are rate-limited. Repeated failures lock the account temporarily; every attempt is recorded with timestamp and source IP.
Strong password policy
Minimum 12 characters with mixed case, digits, and symbols. Passwords are hashed; we never log them in plaintext.
Single sign-on (SSO)
Standards-compliant SAML on every paid plan. Connect Okta, Microsoft Entra ID, Google Workspace, Keycloak, Auth0, OneLogin, and any major identity provider.
Auto-provisioning (SCIM)
On every paid plan: your IdP creates and removes FileSendX accounts automatically. Offboarding happens the moment your IdP updates.
— III. Access control
Access control and audit.
Role-based access control
Two roles per team: member and admin. Members can send and download files; admins additionally manage teammates, billing, SSO/SCIM, and the audit log.
Journal d'audit
Every login, logout, role change, invitation, file send, and admin action is recorded with timestamp and source IP. Available to admins from the team settings.
Destruction après lecture
Default for every transfer. Files are wiped from object storage within two hours of the first successful download. The cleanup runs every five minutes.
Expiring links
7 days on Free, 30 days on Starter and Pro. After expiry the file is deleted from object storage and the database row is removed — recovery is impossible by design.
— IV. Residency
Data residency.
FileSendX runs entirely inside the European Union. Your files are stored on EU object storage in France — never copied outside the EU, never cached on US infrastructure, never subject to the US CLOUD Act.
Payments are processed by Stripe in Ireland. We provide a complete data-processing agreement and sub-processor list on request — email contact@dynamic-foundries.com.
— V. GDPR
GDPR.
Account holders can exercise GDPR rights — access, rectification, erasure, portability, objection, restriction — by emailing contact@dynamic-foundries.com with the subject "Data Protection Request". We respond within 30 days.
Full retention details, sub-processor list, and legal basis per data category are in the privacy policy. Read the privacy policy →
— VI. Disclosure
Responsible disclosure.
If you've found a security issue, please email contact@dynamic-foundries.com with the subject "Security disclosure". We acknowledge reports within 48 hours and aim to ship a fix within 30 days for high-severity issues.
Please do not test against live user accounts other than your own. If you need a clean test account, ask and we'll provision one.
A French SASU you can hold accountable
Your data, EU jurisdiction. No CLOUD Act, no transatlantic risk.