AES-256 encryption · ENS Medium · Data in the EU

Secure file transfer. No WeTransfer, no FTP.

Your team sends an encrypted link that expires when you decide, asks for a password when it has to and logs every download. You can revoke it in one click. And the file does not end up in someone else's cloud: it stays in the case record and, if you want, triggers the process.

No card required Nothing for the recipient to install Data stays in the EU
Secure link
Active
Fileaudit-2026.zip · 1.8 GB
Expiresin 7 days · 3 downloads max.
AccessCode to the recipient's mobile
Antivirus✓ Clean
Downloads1 of 3 · 29/09 09:14 · 81.44.x.x
Encryption
✓ AES-256
Revoke
1 click
Case record
Filed

Every transfer records who opened it, when and from where. And it stops the moment you want it to.

25 MB
The limit that blocks you
The Gmail attachment cap; 35 MB by default in Exchange Online. That is why your team goes looking elsewhere.
3 days
How long a free link lasts
On the free WeTransfer plan. Here you set the expiry, transfer by transfer.
0
Steps for the recipient
They open the link and download. No account, no app, no FTP client.
The problem

Files already leave your company. You just cannot see which way

When the official channel is no use, people improvise. And what they improvise, you never see.

Consumer services

Public links circulating through email and chats, with no way of knowing who opens them or when they are deleted, on a personal account that has no contract with you.

Legacy FTP

A server set up by someone who left years ago, with shared accounts, passwords that never change and no useful log on the day it has to be audited.

The same old attachment

It goes to whoever autocompleted in the "To" field, gets forwarded without control and sits in the recipient's mailbox forever. Sending to the wrong person is one of the most frequently notified breaches.

Personal cloud and USB sticks

An employee's private account or a memory stick in a pocket. When that person leaves, your company's documents leave with them.

How it works

Drag, set the rules, send

For the sender it is as easy as the service they were using. For you, it stops being invisible.

1

You drag the file in

From the browser, from your phone or from the case record itself. The file is encrypted on upload and scanned by antivirus before the link even exists.

2

Your rules are applied

Expiry, maximum number of downloads, a password or code for the recipient, view-only, watermarking. Company policy applies itself; it does not depend on everyone remembering.

3

You send it and you see everything

The recipient downloads without registering. You see who opened it, when and from where, you revoke the link in one click, and the file stays in the case record with its retention period.

Control

What you get to decide on every transfer

As a default for the whole company, or transfer by transfer when the case calls for it.

Encryption end to end

TLS 1.3 in transit and AES-256 at rest, with keys in an HSM. The data stays in the EU. The technical detail is on the security page.

Expiry and download limit

Hours, days or a single download. Once the deadline passes the link stops existing; it does not keep circulating through forwarded emails.

Password and one-time code

Recipient verification by email or SMS so the link is worthless if it ends up in the wrong hands. It fits with your SSO and two-factor for internal users.

Antivirus on upload

Every file is scanned before the link is published, in both directions. What comes in through the intake inbox is scanned too.

Content rules

Block extensions, set size caps, require a mandatory password for certain document types and get a warning when sensitive patterns appear. Every block is logged.

View-only and watermarking

For sensitive documentation: it is viewed in the browser without downloading, with a watermark identifying whoever is looking at it.

Audit log

Who sent what, to whom, when it was opened and from which IP address. Exportable for an audit, an inspection or an incident.

Immediate revocation

Sent to the wrong person? One click and the link stops working, even though the email is already in the recipient's inbox.

SFTP, M2M and REST API

For the exchanges an FTP server handles between systems today: same controls, same log, without maintaining a server of your own. See integrations.

Receiving, not just sending

An inbox so people can send you documentation without the chaos

Half the problem is not sending, it is receiving. Today the paperwork for a new supplier, an insurance claim or a grant application lands in three different mailboxes, in emails with attachments somebody has to download by hand.

With the intake inbox you give them a page with your branding, the third party uploads their files without having an account, and what they upload arrives classified in the right case record. From there it is just another process: it is reviewed, approved, signed and filed.

See an inbox built for your case
Examples that are already a workflow
  • Supplier onboarding. They upload incorporation documents, tax clearance certificates and insurance; the workflow validates, chases what is missing and completes the onboarding.
  • KYC files. The customer provides identification and beneficial ownership through an encrypted channel, not over WhatsApp.
  • Claims and complaints. Photos and reports from a phone, with acknowledgement and traceability, straight into the case record.
  • Invoices and delivery notes. They come in, are read with AI and start the invoice approval.
  • Candidates and onboarding. HR documentation collected in one place, with its retention period applied from day one.
Comparison

Against what you are using today

What changes is not convenience, it is what you can prove afterwards.

Criterion Dokuflex secure transfer Consumer service In-house FTP Email attachment
SizeFree of the email limitCapped by planHigh25–35 MB
Link expiryYou set it, per transferFixed on the free planNot applicableNever: it stays in the mailbox
Recipient verificationPassword or one-time codePaid plans onlyAn account, often sharedNone
Revoking what you sentYes, in one clickLimitedBy deleting from the serverNo
Log of who downloadsComplete and exportablePartialTechnical logs, barely usableNo
Antivirus and content rulesYes, in both directionsNoOnly if you bolt it onWhatever the mail server does
Where the file ends upIn your case record, with retentionIn the provider's cloudIn a loose folderIn mailboxes you do not control
Triggers a processYes, it is a step in the workflowNoWith custom scriptsNo
The difference

Not one more tool: the very same case record

A transfer tool leaves the file in its own cloud. Here the file is already where it will be needed.

It arrives and it starts

The file starts the workflow

What lands in the inbox creates the case record and launches the Dokuflex BPM workflow: review, approval and next step, with deadlines and owners.

It leaves the workflow

Sending as just another action

The report, the contract or the payroll batch is generated and sent as a secure link when a condition is met. Nobody prepares transfers by hand.

Notify and sign

With evidence when you need it

If you have to prove the sending, certified email adds the evidence certificate; if you need agreement, eIDAS electronic signature runs in the same workflow.

AI on intake

Classifies what you receive

Dokuflex AI reads the document that arrives, classifies it, extracts its data and creates a validation task when confidence falls below the threshold.

Compliance

What you will be asked for when you have to prove it

An auditor does not ask whether you have a tool. They ask how information leaves the company, who has downloaded it and with what measures in place. An encrypted channel with access control and an exportable log answers all three questions with data.

Every reference is linked to its official source. This page is not legal advice: compliance also depends on your policies and on how you use the tool.

Requires technical and organisational measures appropriate to the risk, and expressly names encryption and the ability to ensure ongoing confidentiality and integrity. Sending documentation containing personal data through a consumer service is hard to defend against that yardstick. And if things go wrong, the 72-hour breach workflow is the next step.

Its risk-management measures include policies on cryptography and encryption, security in acquisition and the use of secure communications. For entities in scope, the channel files leave through is part of the perimeter. See also NIS2 and DORA incident notification.

In Spain, for anyone working with the public sector, the measures protecting communications and information require encryption, access control and traceability. Dokuflex is certified at MEDIUM category; the ENS document management system sets out the detail.

For financial entities, it requires protecting data in transit and at rest and governing ICT third-party providers. A corporate channel with a contract, a DPA and an audit log is the exact opposite of every team picking its own service.

Secure file transfer for business (MFT)

Dokuflex secure file transfer covers what is expected of a managed file transfer solution: TLS 1.3 and AES-256 encryption, recipient authentication, expiry and a download limit, antivirus, content rules, an exportable audit log and hosting in the European Union. It replaces consumer services, legacy FTP servers and email attachments in companies that need to prove how their information leaves the building.

A WeTransfer and corporate FTP alternative

Against a consumer service it brings control and traceability: immediate revocation, recipient verification, retention defined by document type and a data processing agreement. Against an in-house FTP it removes the server you have to patch, the shared accounts and the logs nobody knows how to read, while keeping system-to-system exchange over SFTP and an API. We set it out in detail in the guide to dropping WeTransfer at work.

Receiving documentation from customers and suppliers

The intake inbox lets third parties upload documentation without having an account, with antivirus and content rules applied on the way in. What arrives is classified with AI, filed in the case record and can start a supplier onboarding, KYC, claims or invoice approval process inside the same BPM platform.

FAQ

What we get asked most

What is secure file transfer and how is it different from WeTransfer?+

It is a corporate channel for sending and receiving files with encryption, access control and traceability. The difference from a consumer service such as WeTransfer is control: you decide how long the link lasts, how many downloads it allows, whether it asks for a password or a code, who can open it and from where; you can revoke it at any time and every access is logged. On top of that the file stays in your case record, not in the cloud of a third party you have no contract with.

Does the recipient have to register or install anything?+

No. They get a link and download it from the browser. If you switch verification on, they are asked for a password or a one-time code sent to their email or mobile, but there is no registration and nothing to install.

How large a file can I send?+

The transfer does not go through email, so it is not affected by attachment limits (25 MB in Gmail, 35 MB by default in Exchange Online). The maximum size per transfer and the total storage are set by your plan; for high volumes or system-to-system transfers you use SFTP or the API instead of the browser.

Can I tell whether the recipient has downloaded the file?+

Yes. The audit log records every opening and download with date, time and IP address, and you can be notified when it happens. If you also need to prove to a third party that you sent something and what it contained, combine it with certified email, which adds the evidence certificate.

Can I stop information going out that should not?+

Yes, with content rules. You can block file extensions, cap the size, require certain document types to always go out with a password and a short expiry, and warn or block when a file contains sensitive patterns. Every blocked attempt is logged so you can review it.

Is it suitable for receiving documentation from customers and suppliers?+

Yes. The intake inbox is a page with your branding where a third party uploads documents without having an account. What they upload is classified, filed in the right case record and can start a process: supplier onboarding, a KYC file, an insurance claim, an application or a complaint.

Does it help with the GDPR, NIS2 and DORA?+

It helps with the part it covers. Article 32 of the GDPR requires appropriate technical measures such as encryption and the ability to ensure confidentiality; the NIS2 Directive asks for policies on cryptography and the use of secure communications among its risk-management measures; in Spain, the ENS requires protecting communications and leaving traceability for public-sector work. An encrypted channel with access control and an audit log is direct evidence of those measures. Overall compliance also depends on your policies and on how you use it.

Where are the files stored?+

On Dokuflex infrastructure in the European Union (Frankfurt, Madrid and Ireland), with TLS 1.3 encryption in transit and AES-256 at rest. For regulated sectors there is a dedicated private cloud or on-premise option. The detail is on the security page.

Next step

Stop finding out later how your files left

Create your account and send your first link with expiry and an audit log today. Or book 20 minutes and we build the channel and the intake inbox for your real case with you.