Securing a file transfer: the complete checklist
Encryption, password, link lifespan, tracking, antivirus: the 7 checks to run before sending a sensitive file.
“Is it secure?” is the wrong question — too vague to have an answer. The right version: secure against what? Interception, unwanted access, a leak long after the fact, a booby-trapped file? Each risk has its countermeasure. Here are the seven checks that cover the essentials, applicable to any service.
1-2. Transport and storage
1. Encryption in transit is the non-negotiable minimum: the connection must be HTTPS/TLS across the entire journey. It’s standard today — but do verify it for older tools (legacy FTP, for instance, transmits everything in the clear).
2. Encryption at rest protects files stored on the servers. The next level up: encryption where you hold the key. At TransferNow, passphrase-based SSE-C encryption (depending on the plan) makes files unreadable without your key — including to our own teams.
3-5. Access: password, lifetime, revocation
3. A password on the download turns an interceptable link into an unusable one. The golden rule: send it through a different channel than the link (text message, phone call) — otherwise both get intercepted together.
4. A limited lifetime shrinks the exposure window: a link that expires after 7 days won’t linger in a hacked mailbox two years later. We devoted a full article to choosing that duration.
5. Revocation is your insurance against mistakes: wrong recipient, wrong file — you must be able to deactivate the link immediately. It’s the structural advantage of the link over the attachment, which can never be recalled.
6-7. The proof: tracking and antivirus
6. Download tracking — who retrieved what, and when — serves two purposes: proof of receipt (contractual, regulatory) and anomaly detection (an unexpected download stands out).
7. Antivirus scanning protects your recipients: a serious service scans files before making the link available. It’s also what makes a link safer than an attachment for the person on the receiving end.
The recap checklist
- Encryption in transit (TLS) — always.
- Encryption at rest — personal key (SSE-C) for sensitive files.
- A password, sent through a different channel.
- A limited lifetime, suited to the context.
- Revocation possible at any time.
- Named download tracking.
- Antivirus scanning before the files are made available.
TransferNow covers all seven — including the first four on the free plan. The details of our approach are on the security page.
Frequently asked questions
Is a password enough to secure a transfer?
It’s a necessary layer but not a sufficient one: combine it with encryption in transit, a limited link lifetime and download tracking. And send it through a different channel than the link.
What is SSE-C encryption?
Encryption at rest whose key derives from a passphrase only you know: without it, the files are unreadable — including to the hosting provider. TransferNow offers it depending on the plan.
How do I know whether a file transfer service is secure?
Check seven points: encryption in transit (TLS), encryption at rest, a password on the download, a limited link lifetime, the ability to revoke, download tracking and antivirus scanning. TransferNow covers the first four on the free plan.
Why send the password through a different channel than the link?
Because if the message carrying the link is intercepted, a password sitting right next to it is intercepted too — both layers fall together. Sent by text or given over the phone, the password stays effective even if the link leaks.
Are transferred files scanned for viruses?
At TransferNow, yes: every file is scanned by an antivirus engine before being made available for download. It’s one of the reasons a link is safer than an attachment for the person receiving it.
5 GB per transfer for free, no sign-up