TransferNow

Security

Securing a file transfer: the complete checklist

Encryption, password, link lifespan, tracking, antivirus: the 7 checks to run before sending a sensitive file.

The TransferNow teamPublished on May 5, 20262 min read

“Is it secure?” is the wrong question — too vague to have an answer. The right version: secure against what? Interception, unwanted access, a leak long after the fact, a booby-trapped file? Each risk has its countermeasure. Here are the seven checks that cover the essentials, applicable to any service.

1-2. Transport and storage

1. Encryption in transit is the non-negotiable minimum: the connection must be HTTPS/TLS across the entire journey. It’s standard today — but do verify it for older tools (legacy FTP, for instance, transmits everything in the clear).

2. Encryption at rest protects files stored on the servers. The next level up: encryption where you hold the key. At TransferNow, passphrase-based SSE-C encryption (depending on the plan) makes files unreadable without your key — including to our own teams.

3-5. Access: password, lifetime, revocation

3. A password on the download turns an interceptable link into an unusable one. The golden rule: send it through a different channel than the link (text message, phone call) — otherwise both get intercepted together.

4. A limited lifetime shrinks the exposure window: a link that expires after 7 days won’t linger in a hacked mailbox two years later. We devoted a full article to choosing that duration.

5. Revocation is your insurance against mistakes: wrong recipient, wrong file — you must be able to deactivate the link immediately. It’s the structural advantage of the link over the attachment, which can never be recalled.

6-7. The proof: tracking and antivirus

6. Download tracking — who retrieved what, and when — serves two purposes: proof of receipt (contractual, regulatory) and anomaly detection (an unexpected download stands out).

7. Antivirus scanning protects your recipients: a serious service scans files before making the link available. It’s also what makes a link safer than an attachment for the person on the receiving end.

The recap checklist

  1. Encryption in transit (TLS) — always.
  2. Encryption at rest — personal key (SSE-C) for sensitive files.
  3. A password, sent through a different channel.
  4. A limited lifetime, suited to the context.
  5. Revocation possible at any time.
  6. Named download tracking.
  7. Antivirus scanning before the files are made available.

TransferNow covers all seven — including the first four on the free plan. The details of our approach are on the security page.

Frequently asked questions

Is a password enough to secure a transfer?

It’s a necessary layer but not a sufficient one: combine it with encryption in transit, a limited link lifetime and download tracking. And send it through a different channel than the link.

What is SSE-C encryption?

Encryption at rest whose key derives from a passphrase only you know: without it, the files are unreadable — including to the hosting provider. TransferNow offers it depending on the plan.

How do I know whether a file transfer service is secure?

Check seven points: encryption in transit (TLS), encryption at rest, a password on the download, a limited link lifetime, the ability to revoke, download tracking and antivirus scanning. TransferNow covers the first four on the free plan.

Why send the password through a different channel than the link?

Because if the message carrying the link is intercepted, a password sitting right next to it is intercepted too — both layers fall together. Sent by text or given over the phone, the password stays effective even if the link leaks.

Are transferred files scanned for viruses?

At TransferNow, yes: every file is scanned by an antivirus engine before being made available for download. It’s one of the reasons a link is safer than an attachment for the person receiving it.

5 GB per transfer for free, no sign-up

Transfer your files with complete confidence on TransferNow