[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"BLOG_POST_en_file-transfer-without-end-to-end-encryption":3,"BLOG_SURROUND_en_file-transfer-without-end-to-end-encryption":340},{"id":4,"title":5,"authors":6,"body":9,"category":321,"date":322,"description":323,"extension":324,"image":325,"meta":326,"navigation":327,"path":328,"seo":329,"sitemap":333,"stem":334,"tags":335,"__hash__":339},"blog\u002Fblog\u002Fen\u002Ffile-transfer-without-end-to-end-encryption.md","Sending a file through a free transfer service: what you are really handing over",[7],{"name":8},"Emilien Mantel",{"type":10,"value":11,"toc":306},"minimark",[12,16,30,35,38,72,75,79,82,85,88,92,95,98,101,104,108,111,114,117,121,124,127,131,134,137,140,144,147,150,154,161,168,172,175,208,221,225,251,255,258,261],[13,14,15],"p",{},"The file is too large for an email. You open an online transfer service, drop the folder, type the recipient's\naddress, and off it goes. Two minutes, no account to create, often free. These services have become a reflex in almost\nevery company, including for documents that should never have travelled this way.",[13,17,18,19,23,24,29],{},"The problem is not the simplicity. It is what happens once the file is sent: on most of these services, it arrives\n",[20,21,22],"strong",{},"readable"," on their servers. It is encrypted in transit, often on their disks too, but the service holds the key. We\nexplained this difference in ",[25,26,28],"a",{"href":27},"\u002Fblog\u002Fencrypted-does-not-mean-end-to-end","our article on the three levels of encryption",".\nHere, we look at the practical consequences, through situations we come across with our customers.",[31,32,34],"h2",{"id":33},"what-really-happens-when-you-click-send","What really happens when you click \"Send\"",[13,36,37],{},"On a classic transfer service, without end-to-end encryption:",[39,40,41,48,54,60,66],"ol",{},[42,43,44,47],"li",{},[20,45,46],{},"The file leaves your computer in plaintext",", protected only by HTTPS while in transit.",[42,49,50,53],{},[20,51,52],{},"The service receives and stores it."," It can open it to generate a preview, scan it for viruses, index it, or hand\nit over to whoever makes a legal request.",[42,55,56,59],{},[20,57,58],{},"It also keeps all the context",": the file names, your address, the recipient's address, the accompanying message,\nthe date, the size. This information often says as much as the content itself.",[42,61,62,65],{},[20,63,64],{},"The recipient gets a link."," On most of these services, that link is enough to download the file, whoever clicks\non it.",[42,67,68,71],{},[20,69,70],{},"When it expires",", the link stops working. What becomes of the file in the service's backups and logs, you have no\nway of checking.",[13,73,74],{},"At none of these steps are you in control. You are trusting the service, its employees, its subcontractors, its\nsecurity, and its future terms of use.",[31,76,78],{"id":77},"case-1-the-accounting-firm-and-the-payslips","Case 1: the accounting firm and the payslips",[13,80,81],{},"An accounting firm runs payroll for a small company with forty employees. Every month, it sends the manager an archive\nwith the payslips, the payroll ledger and the social security filings. The archive weighs 30 MB, the mail server\nrejects it, and the accountant uses a free transfer service.",[13,83,84],{},"What the archive contains: the names, addresses, social security numbers, salaries, bank details and sick leave of\nforty people. In other words, exactly what a fraudster looks for to commit identity theft or a fake change of bank\ndetails.",[13,86,87],{},"Under the GDPR, the firm has just entrusted this data to a provider that can read it. That provider effectively becomes\na processor (Article 28), with no contract, no audit, sometimes without the firm even knowing in which country the files\nare stored. And Article 32 requires the firm to ensure a level of security appropriate to the risk. If these files\nleak, it is the firm that will have to explain it to the data protection authority and to its client.",[31,89,91],{"id":90},"case-2-the-lawyer-and-their-client","Case 2: the lawyer and their client",[13,93,94],{},"Between lawyers, and with the courts, the question is largely settled in France: submissions and case documents are\nexchanged over the RPVA, the profession's secure network, through the e-Barreau platform. But that network stops at\nthe door of the law firm. The client has no access to it. And it is between lawyers and their clients that the most\ndelicate documents circulate.",[13,96,97],{},"Take an employee challenging their dismissal before the employment tribunal. To prepare the case, they have to give\ntheir lawyer their payslips, their contract, years of work emails, sometimes medical certificates or recordings. The\nwhole thing weighs several hundred megabytes. They use the transfer service they know. In the other direction, the\nlawyer sends them their analysis of the case, draft submissions, the documents disclosed by the other side. The same\ngoes for the executive having a draft sale agreement reviewed, or the couple preparing a divorce.",[13,99,100],{},"In France, the law of 31 December 1971 (Article 66-5) places under professional secrecy the lawyer's advice and the\ncorrespondence exchanged between lawyer and client, and more broadly all the documents in the file. This secrecy\nprotects the client: what they entrust to their lawyer must not be readable by a third party. A transfer service that\ncan open the files has no reason to read them, and most of the time it does not. But it has the technical ability to,\nand so does anyone who gains access to its servers, or any authority, domestic or foreign, that asks for them.",[13,102,103],{},"The difficulty specific to this relationship is that the lawyer does not always choose the channel. The client sends\ntheir documents by whatever means they know, and the lawyer receives them without having had a say. The simplest way\nto stay in control is to offer the client, as soon as the case opens, an end-to-end encrypted drop-off channel, as easy\nfor them as a transfer service, rather than hoping they find one on their own.",[31,105,107],{"id":106},"case-3-human-resources-and-the-sensitive-file","Case 3: human resources and the sensitive file",[13,109,110],{},"An HR manager has to send the company's lawyer an employee's file as part of a dismissal procedure: appraisals, email\nexchanges, medical certificates, meeting minutes. They use the transfer service everyone in the company uses.",[13,112,113],{},"This file contains health data, which the GDPR classifies as sensitive data. It concerns a person in dispute with their\nemployer, who may one day ask what happened to their data. And the name of the archive, visible to the service in\nplaintext, is often as explicit as \"Dismissal_file_Martin.zip\". Without even opening the file, the service already knows\nwhat it is about.",[13,115,116],{},"Sending to the wrong recipient happens quickly: according to the CNIL, the French data protection authority, sending\ndata to the wrong person accounted for 13% of the breaches notified to it in 2025. With a classic transfer service, the\nlink goes out, and there is nothing to be done to take it back, other than deleting the transfer and hoping nobody has\nclicked yet.",[31,118,120],{"id":119},"case-4-the-engineering-firm-and-the-plans-of-a-sensitive-site","Case 4: the engineering firm and the plans of a sensitive site",[13,122,123],{},"An engineering firm is working on the extension of an industrial site: a factory, a logistics warehouse, a data centre.\nIt exchanges with subcontractors the building plans, the location of entrances, the electrical diagrams, the CCTV\nnetwork. The files are heavy, they go out through a transfer service, to dozens of recipients, for months.",[13,125,126],{},"These plans are of obvious value to anyone wanting to get into the site, or to a competitor. Yet they go through a\nservice whose host, storage country and retention policy you do not know. And because the links circulate between\ncompanies, by email or instant messaging, a single compromised mailbox among the dozens of recipients is enough to\nexpose every link that is still active.",[31,128,130],{"id":129},"case-5-the-agency-and-the-embargoed-campaign","Case 5: the agency and the embargoed campaign",[13,132,133],{},"A communications agency is preparing the launch of a product that will only be announced in three weeks. It sends the\nvisuals, videos and press kit to the client, then to the printer, then to the photo studio. Everything goes through a\ntransfer service, because it is the tool the whole industry uses.",[13,135,136],{},"In July 2025, one of the most widely used transfer services in the world changed its terms of use. The new version\nrequired users to grant it a worldwide, perpetual, transferable and sublicensable licence to their content, including\nfor training machine learning models. Faced with the reaction of photographers, designers and agencies, the service\nwithdrew the clause before it came into force. The corrected version still allows files to be used to \"improve the\nservice\".",[13,138,139],{},"The episode does not prove that any file was misused. It shows something else: when a service can read your files,\nwhat it is allowed to do with them depends on a text it can change. A service that cannot read them has nothing to\nchange.",[31,141,143],{"id":142},"the-overlooked-risk-fake-notifications","The overlooked risk: fake notifications",[13,145,146],{},"These services have a side effect that is rarely mentioned. After receiving so many \"You have received files, click to\ndownload\" emails, everyone has learned to click on them without a second thought. Attackers understood this long ago:\nfake file transfer notifications are among the most common phishing templates. The link leads to a fake login page\nthat harvests the password of the work mailbox.",[13,148,149],{},"A transfer service everyone uses for everything, with emails that all look alike, is ideal ground for this kind of\nattack. It is not the service's fault, but it is one more reason not to make \"clicking a download link received by\nemail\" a daily, automatic gesture.",[31,151,153],{"id":152},"but-i-put-a-password-on-my-transfers","\"But I put a password on my transfers\"",[13,155,156,157,160],{},"Some services let you protect a transfer with a password. That helps: the link alone is no longer enough, the password\nis needed too. But in most cases, this password protects ",[20,158,159],{},"access to the download",", not the file itself. The file\nremains stored in readable form by the service, which checks the password before serving it. The service, its\nadministrators, an attacker who gets in or an authority making a request still have access to it.",[13,162,163,164,167],{},"A useful password is one that is used to ",[20,165,166],{},"decrypt"," the file, on the recipient's device, and that the service never\nknows. The question to ask remains the same: if I forget this password, can the service still send me the file? If so,\nit can read it.",[31,169,171],{"id":170},"what-changes-with-end-to-end-encryption","What changes with end-to-end encryption",[13,173,174],{},"Let's go back over the five cases with an end-to-end encrypted transfer service. The file is encrypted on the sender's\ncomputer before it leaves, the service only stores unreadable content, and only the recipient can open it.",[176,177,178,184,190,196,202],"ul",{},[42,179,180,183],{},[20,181,182],{},"The service cannot read the files",", nor their names, nor the message that goes with them. The payslips, the\ndocuments entrusted to the lawyer, the HR file, the plans and the visuals remain unreadable on its side.",[42,185,186,189],{},[20,187,188],{},"A breach of the service only yields unreadable data."," That is the difference between a document leak and a leak\nof worthless encrypted blocks.",[42,191,192,195],{},[20,193,194],{},"A request from an authority to the service"," can only obtain what it holds: files it cannot open.",[42,197,198,201],{},[20,199,200],{},"The terms of use cannot change the picture."," A service that cannot read your files cannot use them either.",[42,203,204,207],{},[20,205,206],{},"You stay in control after sending",": expiry date, deactivating the link at any time, including after sending to\nthe wrong recipient.",[13,209,210,211,215,216,220],{},"This is how ",[25,212,214],{"href":213},"\u002Fproducts\u002Ftransfer","Retyc Transfer"," works. The recipient has nothing to install: they click, and the file\nis decrypted in their browser. And for the other direction, when you are the one expecting documents from a client or a\ncandidate, an encrypted ",[25,217,219],{"href":218},"\u002Fproducts\u002Fdeposit-box","drop box"," saves you from asking them to use the first transfer service\nthat comes along.",[31,222,224],{"id":223},"four-questions-before-sending-a-file","Four questions before sending a file",[39,226,227,233,239,245],{},[42,228,229,232],{},[20,230,231],{},"Would I be comfortable if this file were published tomorrow?"," If the answer is no, it should not go through a\nservice that can read it.",[42,234,235,238],{},[20,236,237],{},"Can the service open my file?"," If it shows a preview, or can send it back to you after a forgotten password, yes.",[42,240,241,244],{},[20,242,243],{},"What happens if the link is forwarded?"," If anyone can download with the link alone, your file is only as well\nprotected as the least secure mailbox among those that will receive it.",[42,246,247,250],{},[20,248,249],{},"Can I cut off access if I send it to the wrong person?"," If the only option is hoping nobody has clicked, that is\nnot an option.",[31,252,254],{"id":253},"in-short","In short",[13,256,257],{},"Consumer file transfer services solved a real problem: sending files too large for email. They were never designed to\nprotect those files from the service itself. For a holiday photo, that does not matter at all. For payslips, documents\nentrusted to a lawyer, an HR file or the plans of an industrial site, it engages the responsibility of the company\nsending them. Simplicity is not the problem, an end-to-end encrypted service is just as easy to use. The problem is\nhanding sensitive documents to someone who can read them, without really having decided to.",[13,259,260],{},"Sources:",[176,262,263,270,276,282,288,294,300],{},[42,264,265,266],{},"CNIL, 2025 annual report (in French): ",[267,268],"external-link",{"url":269},"https:\u002F\u002Fwww.cnil.fr\u002Ffr\u002Frapport-annuel-2025",[42,271,272,273],{},"Breakdown of breach causes (13% sent to the wrong recipient, in\nFrench): ",[267,274],{"url":275},"https:\u002F\u002Fnext.ink\u002F238330\u002Fla-cnil-confirme-un-record-de-fuites-de-donnees-en-2025-et-promet-plus-de-controles\u002F",[42,277,278,279],{},"French law no. 71-1130 of 31 December 1971, Article 66-5 (lawyers' professional secrecy, in\nFrench): ",[267,280],{"url":281},"https:\u002F\u002Fwww.legifrance.gouv.fr\u002Floda\u002Farticle_lc\u002FLEGIARTI000023780802",[42,283,284,285],{},"CNB, e-Barreau platform (electronic communication between lawyers and courts, in\nFrench): ",[267,286],{"url":287},"https:\u002F\u002Fassistance.cnb.avocat.fr\u002Fhc\u002Ffr\u002Fsections\u002F360003465960-e-Barreau",[42,289,290,291],{},"Change to a transfer service's terms of use, July 2025, legal analysis (in\nFrench): ",[267,292],{"url":293},"https:\u002F\u002Fwww.seban-associes.avocat.fr\u002Fwetransfer-et-lambiguite-contractuelle-a-lere-de-lintelligence-artificielle-une-mise-en-garde-necessaire\u002F",[42,295,296,297],{},"Withdrawal of the clause and corrected version (in\nFrench): ",[267,298],{"url":299},"https:\u002F\u002Fwww.archimag.com\u002Funivers-data\u002F2025\u002F07\u002F16\u002Fpropriete-intellectuelle-wetransfert-marche-arriere-usage-fichiers",[42,301,302,303],{},"Cybermalveillance.gouv.fr, phishing in 2025 (in\nFrench): ",[267,304],{"url":305},"https:\u002F\u002Fwww.cybermalveillance.gouv.fr\u002Ftous-nos-contenus\u002Factualites\u002Fhameconnage-phishing-ra26",{"title":307,"searchDepth":308,"depth":308,"links":309},"",2,[310,311,312,313,314,315,316,317,318,319,320],{"id":33,"depth":308,"text":34},{"id":77,"depth":308,"text":78},{"id":90,"depth":308,"text":91},{"id":106,"depth":308,"text":107},{"id":119,"depth":308,"text":120},{"id":129,"depth":308,"text":130},{"id":142,"depth":308,"text":143},{"id":152,"depth":308,"text":153},{"id":170,"depth":308,"text":171},{"id":223,"depth":308,"text":224},{"id":253,"depth":308,"text":254},"Security","2026-09-21","Drop a file, type an address, click \"Send\". Consumer file transfer services have become a reflex at work. Without end-to-end encryption, they see everything that goes through them. Five professional situations to understand what that means.","md",null,{},true,"\u002Fblog\u002Fen\u002Ffile-transfer-without-end-to-end-encryption",{"title":330,"description":331,"ogTitle":330,"ogDescription":332},"File transfer: the risks for a business","Forwardable links, files readable by the service, terms of use that change, fake download notifications: the risks of consumer file transfer services, illustrated by five professional cases (accounting, lawyers and their clients, HR, engineering firms, agencies).","Five professional situations where \"classic\" file transfer exposes more than you think.",{"loc":328},"blog\u002Fen\u002Ffile-transfer-without-end-to-end-encryption",[336,337,338],"file transfer","end-to-end encryption","GDPR","qgBOhMcfsthyFENNSC9BU4OI16T5A7fGSnv-i36oBTE",[341,346],{"title":342,"path":343,"stem":344,"description":345,"children":-1},"Anatomy of an encrypted upload in the browser","\u002Fblog\u002Fen\u002Fanatomy-of-an-encrypted-upload","blog\u002Fen\u002Fanatomy-of-an-encrypted-upload","A post-quantum key pair per transfer, 8 MB chunks encrypted one by one in a Web Worker, an API that refuses classic keys. What the browser does between the moment you drop a file and the moment the last byte leaves, with the code to show for it.",{"title":347,"path":348,"stem":349,"description":350,"children":-1},"Retyc and AI: connecting your agent to your transfers and datarooms with MCP","\u002Fblog\u002Fen\u002Fretyc-mcp-ai-agents","blog\u002Fen\u002Fretyc-mcp-ai-agents","Retyc embeds no AI. But your agent can drive Retyc: the command-line client exposes an MCP server that runs on your machine. What it enables, how to install it, what the agent sees and does not see, and the limits to know before using it."]