Encryption model
Files are encrypted on the client's device before upload. In the default Email them option FileSeal holds the key, so our servers can decrypt the files to build your download and email a working link. In Get a link (Most private) the key stays in the link and never reaches our servers, so we cannot read the files.
Client-Side Encryption
Enterprise Grade
AES-256-GCM encryption applied before files leave the client's device
Encrypted before upload
Enterprise
Encrypted before upload; choose Most private and the server never holds the key
File Validation
Advanced
File type and size validation, with integrity checking when files are decrypted
Secure Key Management
Professional
Unique encryption keys generated per upload session
Automatic Deletion
Standard
Files deleted from our servers after download, with integrity verification
GDPR Compliance
Legal
Built-in data protection by design and default
Encryption Standards
Algorithm
AES-256-GCM
Key Generation
Per seal
Transport
TLS
Storage
Encrypted at Rest
Security Practices
AES-256-GCM applied client-side before transmission, in the browser for web uploads and in the caller’s own process for API sends. In the optional "Most private" mode the key stays in the recipient’s link and never reaches FileSeal’s servers.
TLS on all connections.
Documents and account data stored in the UK; all sub-processors contracted to process within the UK or EEA.
Authenticated, role-based access on the principle of least privilege.
Links are single-use. Files are deleted from FileSeal’s servers after collection, and after the expiry you set by a cleanup job that runs every four hours.
Document collection, download and API send activity is logged.
Error monitoring with personal-data scrubbing.
File type and size validation on upload.
Compliance & Standards
GDPR
General Data Protection Regulation
Statement of measures available
ISO 27001
Information Security Management
Not held
SOC 2 Type II
Security and Availability (our hosting providers Vercel and Neon hold their own reports)
Not held
Cyber Essentials
UK Government Scheme
Roadmap
Security Resources
Encryption Guide
Technical details about our encryption
GDPR Compliance Statements
Download compliance statements and activity reports
Download GDPR Statement
Generate a statement of measures for your records
Security Questions
Contact our security team
Security FAQ
Common security questions
Full security model
How encryption, one-time links and deletion work
Data Processing Agreement
Published and incorporated into the Terms
Email them vs Get a link
The two delivery options in plain English
Activity Reports
Download a report of your requests and sends from Settings