Encrypted in your browser · Built for business

Files only you and your recipient can open. Not us. Not anyone.

Encrypted file transfer under your own branded space, stored in the EU. Your clients see you, not us. Everything is encrypted in your browser before it leaves the device, so we hold ciphertext and never need the key.

AES-256-GCM
EU data residency
Subject to UK GDPR
acme.nullsend.io runs in your browser
Edit this, then run the demo. It encrypts whatever you type.

With the file-transfer tools most people reach for, your files arrive on their servers readable, and what happens next comes down to a policy. And policies change. We took that question off the table. The protection is in the architecture, not a promise we could quietly revise.

What we cannot do

The things we cannot do, by design.

Nullsend’s architecture means certain things are not just restricted by our own policy, they are constrained by design. That is the entire product.

01

We can’t read your files

Files are encrypted in your browser before upload. Our servers see only ciphertext.

ciphertext only
02

We can’t train AI on them

You can’t train on what you can’t see. No model, ours or anyone else’s, gets your data.

nothing readable
03

We can’t hand over readable files

A legal request returns ciphertext and metadata, not readable content, because we never hold the key.

nothing to surrender
04

We can’t preview them

No thumbnails. No previews. No virus scanning. These trade-offs are the point.

no plaintext access
05

We can’t recover them

Lose the link, lose the file, for good. By design, because anything else is a backdoor.

no escrow
06

We can’t change our mind

The protection lives in the architecture, not in a Terms of Service we could revise next year.

fixed by maths
How it works

Five steps. One encryption key. It never touches our servers.

Scroll. The diagram walks the whole journey of a single transfer: the file, the ciphertext, and the key that stays out of our hands. On the normal share path the key is never transmitted; verify it: RFC 3986 §3.5 (Fragment).

01 · Encrypt

In your browser

When you drop a file in, your browser generates a random 256-bit AES key and encrypts each chunk locally. The plaintext never leaves your device.

02 · Upload

Ciphertext only

Encrypted chunks stream directly to EU-resident storage. Our servers store ciphertext and metadata. We see what you uploaded, not what is in it.

03 · Share

Key in the URL fragment

The decryption key lives after the # in the share URL. By web standards, fragments never reach the server. Watch it go around our storage, never through it.

04 · Receive

Decrypt on arrival

The recipient’s browser reads the key from the fragment and decrypts locally. Only the two devices that need the key ever hold it.

05 · Expire

Removed on schedule

Transfers are set to expire. After the window, the encrypted file is removed from storage. No manual cleanup, nothing left behind.

SENDER · BROWSER settlement-v4.pdf AES-256-GCM #k=9f2c41ab77d0 generated on your device plaintext never leaves NULLSEND · EU 0x9F 2C 41 .. ciphertext only no key, ever removed after expiry RECIPIENT · BROWSER 0x9F 2C 41 AB .. #k=9f2c41ab77d0 read from the fragment decrypted, locally 0x9F2C41AB.. 0x9F2C41AB.. #k=9f2c41ab77d0 around our storage, never through it
The architecture

The architecture behind the guarantee.

Everything you would expect from a serious file-transfer tool, with the privacy parts built into how it works rather than promised in a policy.

End-to-end

We hold only ciphertext

AES-256-GCM in WebCrypto. Industry-standard authenticated encryption, no custom crypto and nothing rolled ourselves. Our servers see what you uploaded, never what is in it.

Auto-expiry
6d23h59m58s

Files remove themselves

The encrypted file is removed automatically after 7 days. No manual cleanup.

EU residency

Stored in the EU

Ciphertext stored in EU-Central. A DPA is available before signup.

No account

Recipients just need the link

Anyone you send to opens and downloads in their browser. No Nullsend account, no sign-up.

Per plan

Room to send

Transfer size scales with your tier, from 3 GB on Free up to 100 GB.

Pricing

Start free. Scale when you grow.
14-day money-back.

Nullsend is built for businesses. Start free with a card on file, and move up as your storage and team grow. You are the customer, not the product: we are funded by subscriptions, never by advertising or selling data.

Free

For getting started.

£0/mo
  • 10 GB storage
  • 3 GB per transfer
  • 1 user
  • 7-day expiry
  • Debit or credit card required
Choose Free
Speeder

For solo practitioners.

£19/mo
  • 50 GB storage
  • 5 GB per transfer
  • 3 users
  • 7-day expiry
  • Debit or credit card required
Choose Speeder
Most popular
Falcon

For agencies and small firms.

£49/mo
  • 250 GB storage
  • 20 GB per transfer
  • 10 users
  • 7-day expiry
  • Debit or credit card required
Choose Falcon
Cruiser

For mid-size practices.

£99/mo
  • 1 TB storage
  • 100 GB per transfer
  • 20 users
  • 7-day expiry
  • Debit or credit card required
Choose Cruiser

Ex-VAT. UK and EU billing only at launch. Flat per tier, overage at £0.05/GB, no surprise renewals. Full pricing

Enterprise

Need it on your own domain?

Nullsend Enterprise puts your firm’s brand, custom domain, and sender email on the front, with our encryption underneath and a discreet “powered by Nullsend” your clients can trust.

See Nullsend Enterprise
Mobile

Nullsend on mobile

iOS and Android apps in development. The same browser-side encryption, in your pocket. We will let you know the moment they land.

nullsend
New transfer
contract-v4.pdf
2.4 MB · encrypted
Send toalice@client.com
Expires7 days
PasswordOn
Send securely
powered by Nullsend · encrypted in the EU

Set up your branded space in under a minute.

14-day money-back on any tier. Encrypted in the browser from the first upload. No card needed to try the flow.

Get started

Or talk to us about Enterprise.

That #fragment stayed in your browser. Fragments are never sent to a server. That is the whole idea.