Contact DEC
Language: IT EN
End-to-end encrypted file transfer

SecureShare New

Confidential documents stay confidential. Even from us.

Files are encrypted in the sender's browser, with a password that never reaches us, and decrypted in the recipient's browser. Our server holds ciphertext alone: it cannot read the contents, and it cannot hand them to anyone else.

Zero bytes of plaintext on our servers
OpenPGP encryption in the browser
Links that expire and can be revoked
Deployable on your own infrastructure
SecureShare
Transfer status
ENCRYPT
Encrypted on your device
DELIVER
Ciphertext only
CONTROL
Expiry and revocation
PROVE
Audit log and receipts

Confidential document transfers: limitations of general-purpose tools

Email, general-purpose transfer services, USB sticks, portals — none of them was designed with confidentiality in mind.

Email attachments

They sit in both parties' mailboxes and backups, often for years. No expiry, no revocation, no say in who forwards them on.

General-purpose transfer services

The provider can, technically, read what you sent. And anyone holding the link can download it, without limits and without leaving a usable trace.

USB sticks and external drives

They get lost, left behind, copied. No record of who opened what, and no way of getting the document back.

Awkward portals

If the recipient has to create an account and learn an interface, the document ends up attached to an email anyway.

The outcome is always the same: no proof of delivery, no control after sending, and a liability that stays entirely with you — in front of your client, your patient and the regulator.

How it works

The trust boundary is drawn sharply: encryption happens on the device, and the server only ever sees ciphertext.

On the sender's device

  • You pick the file, and it never leaves the device unencrypted
  • A 24-character password is generated locally, or you choose your own
  • Encryption runs block by block, using OpenPGP, in the browser or in the app
  • File names, folder paths and notes can be encrypted too
  • The recipient decrypts on their own device, with the same password

On the server

  • Only encrypted, unreadable blocks ever arrive
  • Expiry, limits and access rules are enforced
  • Links are issued, suspended and revoked
  • Every event lands in the audit log
  • No keys, no passwords, no content

We cannot read your files. We cannot recover them. This is not a technical shortcoming we have yet to fix — it is the design decision that makes the promise checkable.

0 byte
of plaintext content ever reach our servers
24
characters in the password generated for each transfer
2 GiB
per transfer in the standard configuration extendable up to 5 GiB
1 link
for each recipient, revocable one by one

Your files cannot be used to train artificial intelligence models

This is not a contractual clause you have to take on trust — it is a technical consequence. Files are encrypted on your device before they leave it, so we never receive the content in the clear and cannot read it, whether to train a model or for anything else. The promise covers the contents of your files. Making a transfer work still requires minimal metadata about accounts, recipients, rules, delivery and audit, and we say so openly.

Control does not end when you hit send

The document stays yours even after it has been delivered.

Time-based expiry

The link stops working after the hours or days you set. You can extend it or close it early at any point, and the recipient can ask you for more time.

Download allowance

From one to a million, or unlimited. Only a download that completes and decrypts in full is counted — a failed attempt or a wrong password costs you nothing.

Immediate revocation

A single action puts the document out of reach, even if the link has already been forwarded to others.

One link per recipient

Every recipient gets their own private link. You can revoke one without touching the others, and see how many times each of them has downloaded.

Network and country

Restrict access to IP addresses, corporate networks, or a list of permitted or blocked countries. The EU, EEA and EFTA presets write the individual country codes into the transfer, so a future change of membership cannot quietly alter a rule that is already live.

Recipient identity

You can require access from a verified account, mailbox verification with a one-time code, or a passkey that the recipient registers after their first verification and reuses from then on.

Files, folders and transfers that survive interruption

Confidentiality and convenience can coexist.

One file, several files or a whole folder

Names, paths, types and sizes live only inside the metadata encrypted under your password. The recipient can pull down a single document without fetching everything else.

A local preview before saving

Text, PNG, JPEG, WebP and PDF can be inspected after cryptographic verification and before you decide where to save them. The preview runs entirely on the device — there is no server-side rendering at all.

Uploads that resume from the point of interruption

Encrypted blocks travel in parallel and failed attempts are retried automatically. If the page closes, reselecting the same file resumes the transfer and skips the blocks already accepted.

Evidence and audit

Every delivery leaves a verifiable trail, ready for the client, the case file and the audit.

A tamper-evident log

Each event is chained to the one before it by a cryptographic fingerprint, which makes deletions, insertions and edits detectable. The log stays the authoritative record, and can be exported to your own security tooling or a SIEM.

A signed delivery receipt

If you ask for it, the recipient records whether they accept or refuse the document, with a comment and by a deadline. That declaration is sealed into a signed receipt anyone can verify independently.

Download history

Date and time in UTC, outcome, IP address, operating system and browser, country code where available. Exportable to CSV for the case file or an internal audit.

Collecting documents from clients

A collection portal under your own brand, without asking anyone to register.

1

Portal creation

A title, instructions, a deadline of up to 90 days, and the fields you need: case number, contact person, consents.

2

Invitation delivery

To the address you specify, with the message in Italian or English and your branding on it. By default we ask the person to prove they control that mailbox, though you can turn verification off.

3

Client upload

Files are encrypted in their browser before they go anywhere. No account to create, no app to install.

4

Structured document receipt

Documents land in your archive, with a notification and a record of who sent them.

It replaces asking for documents by email: no plaintext attachments sitting in mailboxes, no files scattered through reply chains, no manual chasing. Close the request and the documents collected are revoked and scheduled for deletion.

Built for organisations too

What you need once SecureShare stops being a personal tool and becomes an internal service.

Identity and provisioning

Sign-in through your own identity provider over OIDC, user and group provisioning via SCIM 2.0, and multi-factor authentication with TOTP apps, passkeys, or both.

Policies that cannot be talked around

Maximum lifetime, download counts and security profiles are set at instance, team or individual level. Where they disagree the strictest always wins: a lower level can never loosen the one above it.

Automation and native clients

Beyond the browser there are applications for macOS, Windows, Linux, iOS and Android, a command line and an API with revocable tokens. None of these routes offers a way to upload a file unencrypted.

Who it is for

For people who exchange documents whose confidentiality is not up for negotiation.

Law firms and professionals

Pleadings, expert reports, corporate paperwork and material covered by professional privilege. Proof of delivery for each counterparty, and access withdrawn the moment the engagement ends.

Healthcare providers

Reports, imaging and clinical records sent to patients and colleagues. The content is unreadable to the service provider, and the link expires automatically.

Corporates, M&A and finance

Accounts, due diligence, contracts and personnel data. Network and country limits, team-level rules, and access that closes when the deal does.

Family offices and private wealth

Estate and succession documents shared between a very small number of people, with personal links, no permanent copies, and a record of who saw what.

Deployment options

The same application and the same confidentiality model, whichever way suits you.

Installed on your own infrastructure

On your own server or your own cloud provider, in Italy or elsewhere. Automatic HTTPS, application backups, and guided updates you can roll back if you need to.

Run by us

Coming soon. A service operated by Digital Equipment Communication, with no infrastructure for you to run. Same application, same confidentiality model.

Under your own brand

White-label: your logo, name, legal details, and the look of the download pages and emails. Your clients see you, not us.

The encrypted files can live on a disk in your own server, on a dedicated encrypted volume, or in S3-compatible object storage — AWS, MinIO, Cloudflare R2, Backblaze B2. The choice is yours, and it stays yours.

Limits of the service

Three points we would rather put in writing while you are still evaluating.

We cannot recover a lost password

There is no key escrow and no emergency administrator override. If the password is lost the file is gone — and that is precisely why we cannot read it either.

We do not inspect what you send

You cannot run antivirus or automatic classification against a file you cannot read. Scanning has to happen on the device before sending, or after the download.

A receipt is not a qualified signature

Our receipts show that a particular link was used, that the download completed, and that the recipient recorded a decision. They are not a qualified electronic signature, and they do not prove that a human being read the document.

Next steps

SecureShare is in its launch phase: it is available for deployment on your infrastructure, under your own brand, and will soon also be offered as a managed service. A demonstration based on your use cases is available on request.