Encrypted end to end.
Verified at every access. Logged every time.
Every principle below is architecture, not configuration. AES-256 encryption at rest and in transit. OTP identity verification at every access. Dynamic watermarking on every page. A complete, exportable audit trail. No AI model ever touches your files. No third-party plugin ever accesses them.
No AI, Ever
No AI model, no LLM, no machine learning system ever reads, summarizes, indexes, or trains on your files. Not for analytics. Not for “smart features.” Not for anything.
This is the single principle that separates FileLink from every other file-sharing platform. Dropbox summarizes your files with AI. Google Drive indexes them. DocSend markets AI-powered document organization. We don't.
Your files are never sent to an AI API. They are never processed by a model. They are never used as training data. This is not a setting you configure — it is the architecture.
No Third-Party Tool Risk
No embedded plugins. No third-party storage layers. No silent data-sharing agreements. When you share a file through FileLink, it goes through FileLink — and nothing else.
Other platforms embed third-party viewers, analytics SDKs, and storage intermediaries. Each one is a potential attack surface and a potential privacy leak. FileLink eliminates that entire category of risk.
Nothing Installed, Nothing Left Behind
The sender works in their browser. The recipient works in their browser. No app to install. No plugin to download. No software to maintain.
Files are streamed to a secure in-browser viewer — never copied to the recipient's device. When the session ends, zero bytes remain. Revocation is real: there is no local copy to keep after you pull access.
Encryption
Every file is encrypted on your device before it ever reaches our servers, and it stays encrypted while stored. Only a recipient who passes OTP verification can trigger decryption — and that happens server-side, on demand, for the duration of the viewing session only.
A unique 256-bit key is generated in your browser for each file. The encrypted file and its IV are stored; the key is held separately and is only retrieved by the serve-file service after the recipient has passed OTP. The key is never exposed to the recipient's browser.
Dynamic Watermarking
Every document view is watermarked with the recipient's identity, tying any leaked copy back to who had access. Combined with the audit trail, “we don't know how this got out” becomes a traceable, answerable question.
You Stay in Control
Revoke access instantly — even after the file has been viewed. Schedule expiry in advance. Change permissions on the fly. Every action is logged in a real-time audit trail with IP, location, device, and timestamp.
You decide who sees, what they can do, and when access ends. Not the platform. Not the recipient. You.
Infrastructure
Everything above is FileLink's own application-level architecture. Underneath it, FileLink runs on AWS infrastructure certified to ISO 27001, SOC 1, SOC 2, SOC 3, and PCI DSS — independently audited, global-standard infrastructure security that FileLink's own controls are built on top of.