Layered controls protect accounts, uploads, share links, and downloads throughout the transfer lifecycle.
Protection is applied at the transport, account, storage, and sharing boundaries.
The application uses well-defined service boundaries that can be configured per deployment.
Server-side authorization and validation for browser and API workflows
Local or S3-compatible storage selected by deployment configuration
Relational records, constraints, and transactions for application state
Durable jobs for notifications, cleanup, exports, and maintenance
Fine-grained controls over who can access, share, and manage your files.
Two account roles with server-enforced authorization boundaries:
These statements describe controls present in the application today, without claiming third-party certification.
Insert-only audit events for important transfer, share, account, and administrative actions.
Configurable retention, share expiry, account export, and deletion workflows.
Self-service data export and account deletion controls support privacy requests.
Two-factor authentication, recovery codes, login lockout, and session inactivity controls.
SHA-256 checksums can verify uploaded content and detect mismatches.
Hashed API keys, key rotation, request throttling, quotas, and signed webhook payloads.
We believe in coordinated vulnerability disclosure and work transparently with security researchers to keep Transfilio safe for everyone.
Report security vulnerabilities directly to our security team.
support@transfilio.comOur formal bug bounty program is coming soon. We will reward researchers who responsibly disclose critical and high severity vulnerabilities.
Please include clear reproduction steps and give us a reasonable amount of time to investigate and remediate before public disclosure. Reports are reviewed and prioritized according to impact.
Join thousands of teams who trust Transfilio with their most sensitive files.