Secure File Transfer Between Devices
End-to-end transport encryption with zero server file custody. Share sensitive documents and media without leaving copies on remote cloud drives.
Why Cloud Storage Poses Security Risks
When you upload sensitive files to traditional cloud file storage providers, those files are stored in remote database records and disk arrays. While providers may encrypt data at rest, they hold the master encryption keys, which exposes files to insider threats, accidental data leaks, automated content scanning, and subpoena requests.
Furthermore, forgotten shared links remain accessible on the internet for months or years, creating a lingering security risk if the URL is ever discovered or forwarded.
The WebRTC DTLS Encryption Standard
ShareOnline provides secure file transfer by eliminating intermediate file storage entirely. Direct peer-to-peer data channels use Datagram Transport Layer Security (DTLS) to encrypt all data packets in transit between participating browsers:
- Mandatory Transport Encryption: WebRTC requires encryption at the protocol level. Unencrypted data channels cannot be negotiated by modern browsers.
- Direct Browser-to-Browser Key Exchange: Encryption keys are negotiated directly between the sender and receiver during the DTLS handshake.
- Zero Server Custody: Because files stream directly between devices, ShareOnline servers never see, decrypt, or buffer the underlying file bytes.
Session Security and Ephemeral Room Codes
Each transfer session generates a high-entropy 6-digit room code and a unique connection URL. Sessions exist in memory only during active transfers and expire automatically after 15 minutes of inactivity. When either participant closes their browser tab, the session terminates immediately, leaving no persistent file artifact behind.
Honest Security Boundaries
While WebRTC provides robust transport encryption, security depends on proper operational practices:
- Recipient Verification: Ensure you share your room code or QR code only with the intended recipient. Anyone with access to the code can connect while the sender is waiting.
- Browser Security: Transfers rely on the security of the operating system and web browser on both endpoints. Keep browsers updated to avoid local memory exploits.
- Network Metadata: The signaling layer necessarily handles network addressing (ICE candidates) to negotiate the connection. While file content is encrypted, participants reveal their IP addresses to each other to establish direct peer connectivity.