WispFile

Secure file transfer without cloud storage

By the WispFile team · Updated 24 September 2026

The most secure way to send a confidential file is the one that never creates an extra copy: send it directly to the recipient, end-to-end encrypted, with a key that only the two of you hold. A file parked in cloud storage, even encrypted, is a copy that someone else can be compelled, breached or mistaken into exposing. A direct transfer leaves only the sender’s and the receiver’s copies.

Key facts

  • Cloud providers encrypt at rest, but they hold the keys.
  • A direct transfer leaves no third copy to leak later.
  • WispFile encrypts each piece with AES-GCM; the 256-bit key never reaches its servers.
  • Add a password and a one-download limit for a second and third lock.

Why the stored copy is the weak point

Most leaks of shared files do not come from someone breaking encryption in transit. They come from copies that outlive their purpose: a share link that still works a year later, a folder shared with the wrong group, a vendor account that is breached, or an ex-employee’s access that was never removed. Every day a sensitive file sits in a shared folder is a day it can be found.

Standard cloud storage also encrypts with keys the provider holds. That lets them offer search, previews and recovery, and it means the provider can technically read your files and can be required to hand them over. That is a reasonable trade for working documents; it is an unnecessary one for a contract you just want the other party to receive.

Three ways to share a confidential file, compared

Email attachmentCloud share linkDirect, end-to-end encrypted
Copies left behindBoth mailboxes, backupsThe cloud copy, until deletedNone beyond sender and receiver
Who holds the keyMail providersThe cloud providerOnly the link holder
Link can be forwarded and reusedn/aOften, until revokedCan be limited to one download
Size limitAbout 20–25 MBYour storage quotaNone set
Recipient can download laterYesYesOnly while the sender is online

What “secure” should mean for a file transfer

  1. End-to-end encryption. The file is encrypted before it leaves your device, with a key the service never sees. Encryption “in transit” or “at rest” alone still leaves the provider able to read it.
  2. No stored copy. If nothing is kept, nothing can be breached, subpoenaed or forgotten later.
  3. Control over the link. A password sent separately, a one-download limit, and the ability to end the link immediately.
  4. Integrity. The recipient should get exactly what you sent. WispFile checks a SHA-256 fingerprint of every 256 KB piece before it is written.

How WispFile handles a confidential handover

When you add files, your browser creates a random 256-bit key and puts it in the link after the #. That part of a URL is never sent to a server by the browser, so WispFile cannot see it. The recipient’s browser connects directly to yours and each piece of the file is encrypted with AES-GCM before it leaves your device.

With a password, the link carries the key wrapped rather than the key itself; the password is stretched with PBKDF2 (600,000 iterations) in the browser and never sent anywhere. Choose “after 1 download” and the link stops working once it has been used. Press Stop sharing and it ends for good.

What WispFile does keep: file names and sizes (so the receiver can see what is on offer), and transfer statistics. The privacy page lists every field.

A checklist before you send

  • Confirm the recipient’s identity through a channel you already trust.
  • Add a password and share it by phone or a separate message, not with the link.
  • Set the link to expire after one download.
  • Stay online until they confirm it arrived, then stop sharing.
  • If your organisation has retention rules, record that the file was sent and to whom.

For regulated data, check your own obligations: a direct transfer removes the third-party copy, but it does not replace an organisation’s policy on who may receive what. For background on encryption standards, see NIST’s SP 800-38D on AES-GCM.

Frequently asked questions

What is the most secure way to send a confidential file?

Send it end-to-end encrypted, directly to the recipient, so no copy is stored on a third party’s servers; protect the link with a password shared through a different channel; and make the link work for one download only. That removes the stored copy, the readable copy and the reusable link.

Is cloud storage safe for confidential documents?

Major providers encrypt files at rest and in transit, but they hold the keys, so the provider (and anyone who compromises the account or the provider) can read the files. For ongoing collaboration that is often acceptable. For a one-off handover of a sensitive file, it leaves a copy behind that has no reason to exist.

Is email safe for sending sensitive documents?

Standard email is a poor choice: attachments are stored in both mailboxes (and often backups) indefinitely, and encryption between mail servers is not guaranteed end to end. Size limits of 20–25 MB also rule out most large files.

Does WispFile keep any record of what I sent?

WispFile stores the file names and sizes so the receiver can see what is on offer, and basic transfer statistics. It never stores the files or the key. The privacy page lists exactly what is kept and for how long.

Related guides

Send it directly now

Open WispFile, add your files and share the link. No account, nothing uploaded, nothing stored. Free.

Send files with WispFile