Trust & transparency

Security model

SecureTransfer encrypts files in your browser before upload. The server stores encrypted blobs, but never receives the decryption key.

Short version: files are encrypted in your browser before upload. SecureTransfer stores encrypted blobs and transfer metadata, but the decryption key is kept in the URL fragment and is not sent to the server.

What is protected

What the server can see

SecureTransfer needs limited operational data to run transfers. The server may see or store:

The server should not receive file contents, decryption keys, plaintext text shares, or plaintext key/value shares.

Security controls

Limitations

Responsible disclosure

To report a vulnerability, contact Clevero AB through clevero.se.