Share sensitive files.
Never lose control.

SecureShare is the enterprise platform for encrypted file storage, sharing, and governance — strong cryptography, granular access control, and a tamper-evident audit trail in one deployable platform.

End-to-end encryption · MFA & SSO (OIDC, LDAP) · Tamper-evident audit · Self-hosted & air-gapped

SecureShare file manager — encrypted files and folders with sharing controls

The SecureShare file manager — encrypted storage, sharing, and upload requests in one place.

XChaCha20-Poly1305 encryption Zero-knowledge option Per-tenant key isolation MFA + SSO (OIDC, LDAP) Audit event webhooks Air-gapped deployment
The problem

Sharing files shouldn't mean losing control of them

The tools most teams use were built for convenience, not control. Once a file leaves your hands, you rarely know who opened it, when it expires, or whether it can be recovered, revoked, or proven untouched.

Data the provider can read

Consumer clouds and email hold your plaintext. SecureShare offers true end-to-end encryption where even the operator can't read it.

Links that live forever

Shared links rarely expire and can't be pulled back. SecureShare gives you expiration, download limits, and instant revocation.

No reliable record

Most tools can't tell you who accessed what. SecureShare keeps a complete, tamper-evident audit trail of every action.

Regulated industries — healthcare, finance, legal, government — can't accept those trade-offs. They need to share data and retain control, visibility, and provability. SecureShare is built for exactly that intersection.

Built on three principles

Encryption, control, and accountability

Encryption by default

Every file is protected with modern authenticated encryption. Choose transparent server-side, or password-protected client-side (zero-knowledge) encryption.

Control that survives the share

Expiring links, download limits, password protection, granular permissions, and instant revocation — sharing a file never means losing control of it.

Accountable governance

Retention, legal hold, and a tamper-evident audit log help compliance and legal teams show what happened — for GDPR, NIS2, DORA, and beyond.

How it works

Four steps to governed file sharing

01

Encrypt

Upload to your tenant and pick the encryption that fits the sensitivity — transparent server-side, or password-protected client-side (zero-knowledge).

02

Organize

Structure files in volumes and folders, apply tags and retention policies. Governance rules attach automatically by classification.

03

Share

Share internally with granular permissions, or externally with expiring, password-protected, revocable links — every share is logged.

04

Prove

Every action lands in a tamper-evident audit trail — who, what, when, and from where — exportable to your SIEM and regulators.

Platform

Everything you need, under one audit trail

Storage, sharing, identity, compliance, and administration — unified in a single multi-tenant platform.

Secure sharing

Share with anyone, keep control of everything

Internal permission-based sharing that inherits through folders, plus public links that stay under your command.

  • Expiration dates & download limits
  • Independent password protection
  • Instant revocation & access tracking
  • Password verified before any decryption

SHARE LINK

secureshare.io/s/9fA2…7kQ


Expiresin 7 days
Downloads left3 of 5
Password✓ required
SecureShare File Requests — manage passwordless upload requests sent to external parties
Upload requests

Collect files securely — without giving out accounts

Sometimes the file needs to come to you. SecureShare's Inbox generates a request link any external party can use to send files directly into your encrypted storage.

  • Passwordless, account-free uploads
  • Lands encrypted in the folder you choose
  • Full audit recording on every upload
  • Ideal for intake, onboarding, disclosures
Identity & access

Meets your identity infrastructure where it lives

Federated SSO, multi-factor authentication, and a granular RBAC model with hierarchical access control lists.

  • OIDC SSO (Google, Entra, Okta, Keycloak…)
  • LDAP / Active Directory with TLS
  • TOTP MFA, session fingerprinting, device alerts
  • Adaptive brute-force protection & instant revocation
Single sign-on (OIDC)
MFA challenge (TOTP)
New-device login alert
Role-based permissions
Productivity & collaboration

Security that doesn't slow people down

SecureShare pairs its encryption and compliance core with the organizational tools teams expect — so locking files down never means losing track of them.

Full-text search

Fast, per-tenant search across your files — encryption never makes anything harder to find.

Unlimited file size

No caps on upload size — move multi-gigabyte files without splitting or workarounds.

Volumes, folders & tags

Top-level storage spaces with their own access control, quota, and retention — plus folders, tags, and favorites.

Trash with restore

Deletions are recoverable from a per-volume trash until they're purged.

Notifications

In-app and email alerts on uploads, downloads, shares, and security events — with per-category preferences.

Contacts & groups

User- and tenant-scoped contacts and groups make recurring sharing and upload requests fast.

Uploads and downloads are chunked and resumable — large files survive flaky connections — and everything runs in a modern browser with no client software to install.

Encryption architecture

Modern cryptography, your choice of trust model

Files are encrypted with XChaCha20-Poly1305 authenticated encryption; password keys are derived with Argon2id. Each organization — and each file — matches the model to the sensitivity of the data.

1

Transparent server-side

Files are encrypted automatically at rest under a per-tenant key hierarchy. Frictionless for users, strong at-rest protection for admins. Ideal for general business data.

2

Password-protected, client-side

When a password is set, the file is encrypted in the browser before it ever reaches the server. The platform stores only ciphertext and never sees the password or plaintext — true zero-knowledge confidentiality, with an optional administrative recovery path. Ideal for your most sensitive material.

Hierarchical key management

Keys protecting keys

A layered hierarchy limits the blast radius of any single exposure and enables rotation without re-encrypting data wholesale.

  • Master key from env, AWS KMS, or OpenBao — never on disk in plaintext
  • Versioned, rotatable per-tenant KEK — rotation re-wraps in the background, no downtime
  • Unique per-file DEK — one file's compromise never affects another
Platform Master Keyenv · AWS KMS · OpenBao
encrypts ↓
Tenant KEKversioned · rotatable · per-tenant
encrypts ↓
Per-File DEKunique random key per file
encrypts ↓
File Contentsauthenticated, per-block
Compliance & audit

Governance and audit, built in

Retention, immutability, legal hold, and a tamper-evident audit trail — technical controls that support your compliance and legal workflows.

Early access: Retention policies, legal hold, and WORM immutability are currently an early-access preview under active development — behavior and configuration may change before general availability.

Retention policies

Automated classification rules, event-based disposition, and human review & approval before deletion.

WORM immutability

Governance and compliance modes for unalterable, long-term record-keeping — pair with S3 Object Lock.

Legal hold

Freeze files for litigation — retention clock stops, deletion blocked, every action recorded with reason and approver.

Tamper-evident audit

Cryptographic integrity checkpoints, SIEM webhooks, ClickHouse analytics, and configurable long-term retention.

Note: SecureShare provides the technical controls that support compliance. Achieving certification under any specific framework depends on your organization's policies, processes, and deployment configuration.
See the GDPR · NIS2 · DORA · ISO 27001 control mapping
Multi-tenancy & administration

Built multi-tenant, with a full control plane

Strict isolation per tenant, and a complete administrative toolset — equally suited to a single enterprise, a managed service provider, or a SaaS offering.

Strict tenant isolation

One tenant can never see another's data

Every tenant's data, keys, users, and configuration are isolated. Tenants are resolved by domain, each has its own cryptographic key hierarchy, and access is filtered by tenant at every layer.

Administrative control plane
  • User management — provision, disable, force-logout, reset, remove
  • Roles & granular permissions
  • Tenant settings — security, storage, features, branding, email, localization
  • Quota management per tenant and per user
  • Email templates, volume management, and license validation
  • Platform statistics — usage, storage, sharing, and request metrics
Deployment

Run it your way — SaaS, on-premises, or air-gapped

Delivered as containers that validate their security-critical configuration at startup. Deploy as managed SaaS or inside your own infrastructure — down to fully disconnected networks.

SaaS

Managed by BlackShield. Nothing to run — the quickest path to production.

On-premises

Deploy in your own cloud or data center for full data control and residency.

Air-gapped

Runs in isolated, disconnected environments with no external dependencies.

Storage options

S3-compatible object storage or local filesystem — selectable per tenant.

Key management

Master key from an environment secret, AWS KMS, or OpenBao (Vault-compatible).

Browser-only access

No client software to install. Any modern web browser is all users need.

Solutions

Built for regulated industries

For organizations that must share sensitive data and prove control, visibility, and retention.

Healthcare

Store and share sensitive healthcare documents with strong encryption, full audit trails, and access controls that support GDPR obligations for sensitive health data.

Finance

Safeguard statements, disclosures, and case files with per-tenant key isolation, tamper-evident audit, and long-term record retention.

Government

Air-gapped deployment, strict tenant isolation, and federated identity for sensitive public-sector data.

Why SecureShare

One platform instead of three or four

Encryption, control, and compliance that organizations usually assemble from separate products — unified, under one audit trail, with one set of keys you control.

Capability Consumer cloud Generic enterprise SecureShare
Strong at-rest encryptionSometimesYesYes
End-to-end (zero-knowledge) optionRareRareYes
Per-tenant key isolation & rotationNoLimitedYes
Expiring / limited / revocable linksLimitedYesYes
Passwordless external upload requestsNoSometimesYes
Retention + legal hold + WORM (early access)NoSometimesYes
Tamper-evident audit + SIEMNoSometimesYes
Multi-tenant by designNoSometimesYes
Self-hosted / air-gapped optionNoSometimesYes

See SecureShare protect your most sensitive files

Book a walkthrough with our team, or talk to us about a self-hosted or air-gapped deployment.