Implemented Security Controls

Security at Transfilio

Layered controls protect accounts, uploads, share links, and downloads throughout the transfer lifecycle.

HTTPS Transport Two-Factor Authentication Access-Controlled Links Audit Events

Data Protection

Protection is applied at the transport, account, storage, and sharing boundaries.

In Transit

  • HTTPS is used for production browser and API traffic
  • Secure cookies and browser security headers
  • Rate limits protect authentication and API endpoints

Storage Safeguards

  • Configurable local or S3-compatible storage backends
  • Validated storage paths prevent directory traversal
  • Deletion removes both file records and stored objects

Share Controls

  • Optional password protection for share links
  • Expiry dates and atomic download limits
  • Optional IP allowlists and download notifications

Account Protection

  • Passwords are hashed with bcrypt
  • TOTP two-factor authentication with recovery codes
  • Configurable login lockout and session inactivity limits

Infrastructure

The application uses well-defined service boundaries that can be configured per deployment.

Phoenix Application

Server-side authorization and validation for browser and API workflows

File Storage

Local or S3-compatible storage selected by deployment configuration

PostgreSQL

Relational records, constraints, and transactions for application state

Background Jobs

Durable jobs for notifications, cleanup, exports, and maintenance

Access Controls

Fine-grained controls over who can access, share, and manage your files.

Authentication

  • Passwords hashed with bcrypt
  • OAuth2 social login via Google and GitHub
  • Signed, secure browser sessions
  • Signed email verification and password-reset tokens

Role-based Access Control (RBAC)

Two account roles with server-enforced authorization boundaries:

Project Owner User

Share Link Security

  • Password protection on every share link
  • Configurable download limits per link
  • Automatic expiry dates
  • IP restrictions to allowlisted addresses

API Security

  • HMAC-signed webhook payloads
  • Rate limiting on authenticated API endpoints
  • Per-plan monthly quotas enforced by the API
  • Hashed API keys with rotation and revocation

Verifiable Controls

These statements describe controls present in the application today, without claiming third-party certification.

Audit Logging

Insert-only audit events for important transfer, share, account, and administrative actions.

Data Lifecycle

Configurable retention, share expiry, account export, and deletion workflows.

Privacy Tools

Self-service data export and account deletion controls support privacy requests.

Account Security

Two-factor authentication, recovery codes, login lockout, and session inactivity controls.

File Integrity

SHA-256 checksums can verify uploaded content and detect mismatches.

API Protection

Hashed API keys, key rotation, request throttling, quotas, and signed webhook payloads.

Vulnerability Disclosure

We believe in coordinated vulnerability disclosure and work transparently with security researchers to keep Transfilio safe for everyone.

Security Contact

Report security vulnerabilities directly to our security team.

support@transfilio.com

Bug Bounty

Our formal bug bounty program is coming soon. We will reward researchers who responsibly disclose critical and high severity vulnerabilities.

Responsible Disclosure Policy

Please include clear reproduction steps and give us a reasonable amount of time to investigate and remediate before public disclosure. Reports are reviewed and prioritized according to impact.

Ready to transfer files securely?

Join thousands of teams who trust Transfilio with their most sensitive files.