EN

Tem certeza de que deseja sair deste dispositivo?

Security Overview

Security Overview

Effective: 29 June 2026 Last updated: 29 June 2026
End-to-end encryptionResponsible disclosure

How Senderly protects your files and your account. This overview is a plain-language summary, not a security certification.

Contents
  1. 1. Encryption
  2. 2. Access control
  3. 3. Infrastructure
  4. 4. Monitoring & abuse prevention
  5. 5. Breach response
  6. 6. Responsible disclosure

1.Encryption

Files are end-to-end encrypted on your device before they are uploaded. The encryption key travels in the link fragment, which is never sent to our servers, so we cannot decrypt your files or read their names.

  • Encryption and decryption happen in your browser or app
  • We store only encrypted blobs — never plaintext
  • Optional password protection adds a second factor to a link
  • Connections are protected with TLS in transit

2.Access control

Account access uses email/password or Google/Apple sign-in. Sessions are managed with secure, short-lived tokens and a refresh mechanism. Device-to-device transfers add an extra authenticity check (a short verification phrase) to defend against interception.

3.Infrastructure

We build on hardened, widely-trusted infrastructure:

  • Cloudflare R2 — encrypted file storage with automatic deletion at expiry
  • Cloudflare Turnstile — bot protection without tracking users
  • Cloudflare TURN — relays device-to-device connections when a direct path isn't available

4.Monitoring & abuse prevention

We monitor for abuse and respond to valid reports. Because content is end-to-end encrypted, we act on reports and lawful requests rather than scanning file contents. Reported transfers can be disabled, and serious cases — such as child-safety material — are referred to the appropriate authorities.

You can report a transfer at any time via our report form.

5.Breach response

If we become aware of a security incident affecting your data, we will investigate promptly, take steps to contain it, and notify affected users and regulators where required by law and within applicable timeframes.

6.Responsible disclosure

We welcome reports from security researchers. If you believe you've found a vulnerability, please email security@senderly.me with details and steps to reproduce.

  • Give us a reasonable time to investigate and fix before public disclosure
  • Don't access, modify, or delete data that isn't yours
  • Don't run attacks that degrade the Service for others (e.g. DoS)
  • Act in good faith — we won't pursue good-faith research
We acknowledge valid reports and work with you on a fix.

Found a vulnerability? Email security@senderly.me — see Responsible Disclosure below.