Securefile transfer,without limits.
Send and receive encrypted, straight from Outlook. Hosted in the EU, GDPR-compliant, no US cloud. For teams exchanging sensitive data who'd rather not worry about it.
What SecureFiles does
Large files, no more FTP.
Send, receive, document — click through the capabilities.
Send multi-GB files straight from Outlook.
Compose an email as usual — large attachments upload to storage automatically and are replaced by a download link. The recipient sees no difference.
- Multiple GB per file, no more mail server limits
- Smart switch: small attachments stay in the mail
- Add-in shows status and recipient access in real time
- Works in Outlook desktop, web and mobile
External parties upload files securely to you.
Send an upload link to clients, patients or applicants. They upload without an account, you see what arrived immediately.
- Upload link with expiry date and max size
- External parties need no Conbool account
- Virus and PDF inspection before your inbox
- Branding with your logo and domain
Recipients download without an account, without a password.
Instead of sender-set passwords, SecureFiles ships signed one-time links to the recipient address. Safer than passwords in the same mail, and friendlier.
- One-time links with configurable lifetime
- Optional: password as a second factor
- Revoke access any time — even after sending
- Recipient acknowledgement to you
Encrypted storage — hosting in Germany.
Data never leaves the EU. ISO-certified data centres in Germany, DPA included, no US cloud in the critical path.
- AES-256 encrypted at rest
- Hosted in Germany, run by a German company
- DPA included, no US sub-processor
- Customer-managed keys possible (BYOK)
Every download traceable — every file under control.
See who, when and from which IP downloaded a file. Retention and deletion deadlines are enforced automatically.
- Audit log with IP, user agent and timestamp
- Automatic deletion after retention (GDPR Art. 17)
- Reports for auditors and data protection
- Access revocable any time
Sending files today vs. secure file transfer with SecureFiles.
Why 25 MB attachment caps, forced cloud logins and consumer filesharing aren't an answer to GDPR-compliant file exchange.
Without SecureFiles
- 25 MB attachment limit caps every larger file.
- Cloud shares force recipients to log in to the provider.
- Consumer filesharing caches in the US. GDPR grey zone.
- FTP requires CLI knowledge and plaintext passwords.
- Externals can't securely send you files back.
With SecureFiles
- Files of any size straight from Outlook, one click, done.
- Recipient opens the link with no account, no software.
- Hosted in the EU, encrypted in transit and at rest.
- SSO via Entra ID, audit log per GDPR Art. 30.
- Secure Inbox, externals send files back to you securely.
Three ways to share files securely.
Every use case asks for a different kind of share. SecureFiles ships all three out of one product, without tier upcharges.
To specific recipients
Encrypted transfer to named email addresses. Every recipient gets their own download budget. A reply channel can be enabled for return uploads.
Shared file space
Your team creates a shared pool where internal and external participants upload and download over time. One shared file space per project or engagement, the secure alternative to SharePoint, without a Microsoft account for externals.
Public share
One link to distribute freely, perfect for press material, event recordings or product data sheets. Download-only with a hard total-download cap, optionally password-protected.
Encryption, malware scan and audit log by default
The security controls GDPR Art. 32 and NIS-2 demand run quietly in the background, no extra click. TLS 1.3 in transit, AES-256 at rest, key management in the EU. On request we set up an end-to-end mode in which the key stays in the browser; the server-side malware scan is then unavailable.
Encryption and storage sovereignty
TLS 1.3 in transit, AES-256 at rest, key management in the EU. If you want the files in your own storage, attach your own S3 bucket in Germany.
Malware scan by default
Every file is scanned before release. While the scan runs, the transfer shows as 'being checked'. Infected uploads are rejected and never reach the recipient. No upcharge, no black box.
Audit log for every transfer
Who sent what when, who downloaded when. GDPR Art. 30 ready. IP hashing protects privacy.
Multi-tenant & Entra ID
Native Entra ID integration, SSO, group policies, tenant isolation from a single product. No separate IAM tool needed.
Cloud or on-premise
Pick the operating mode that fits your compliance profile. Fully managed GDPR cloud in the EU, or installed in your own data center.
Secure file transfer straight from Outlook, for every team
From first click to final download, no portal, no login friction, no context switch.
Any file size
From 20 MB presentations to multi-terabyte CAD models. Performant, retry-capable, multipart upload. No hard per-file size limit.
Passwordless retrieval for returning recipients
Returning recipients skip password entry for 12 months. Device-bound trust, revocable, GDPR-compliant.
Outlook add-in
Seamless in classic and new Outlook. Desktop, Web, Mobile. One click, done.
Mail in your own tone
Notification emails to recipients are fully customizable: sender name, tone, wording, layout. The recipient sees your brand, not ours.
Retention from 1 hour to 365 days
Expiry periods configurable per tenant: from hours to years, optionally unlimited. Download limits per link. Automatic deletion after expiry.
Public share link
One link for everyone: ideal for press materials, event recordings, or product datasheets. Download-only, with a hard total download cap and tightened rate-limiting against abuse. Optional password.
Encrypted at rest, storage location your choice
TLS 1.3 in transit, AES-256 at rest. If you would rather the files did not sit with us, attach your own S3 bucket in Germany.
- TLS 1.3 for upload and download
- AES-256 at rest, key management in the EU
- Download runs directly between recipient and storage, no proxy in between
- Bring your own S3 bucket in Germany, residency checked per preset
- Provable deletion on expiry, every action in the audit log
Secure Inbox: receive files from clients, patients and suppliers securely
Sending is only half the job. With pool folders, every team creates a secure upload space and invites externals by email. Clients, patients, applicants or suppliers upload files encrypted, no account, no software install. The team gets a signed notification.
Law firm: clients upload contracts securely.
Medical practice: patients send MRI scans GDPR-compliant.
HR: applicants deliver references encrypted.
Procurement: suppliers hand over CAD drawings protected.
Request exactly the documents you need.
Instead of an empty upload field, you define a guided checklist: named documents, required or optional, with format rules. The recipient sees at a glance what is still missing and uploads document by document. No account, encrypted, virus-scanned.
- Guided checklist with groups plus required and optional documents.
- Reusable templates for onboarding, account opening or case files.
- Per-document review: accept or return with a note for correction.
- No account for external senders, GDPR-compliant, hosted in Europe.
Secure file sharing without password ping-pong: passwordless retrieval for returning recipients
On the first retrieval, the recipient verifies with a password. For 12 months, their device remembers the trust relationship. The second, third, tenth transfer arrives without the password ping-pong, more secure than emailed passwords, more convenient than any alternative.
- Device-bound trust (12 months)
- Revocable by admin or user at any time
- Rate-limited + IP-hashed against abuse
Send large files straight from Outlook, no portal, no context switch
The SecureFiles add-in integrates with classic Outlook, new Outlook and Outlook on the Web. One click switches the attachment to an encrypted link, no new interface, no context switch.
- Classic Outlook
- New Outlook + Outlook on the Web
- Central rollout via Microsoft 365 Admin Center
GDPR-compliant file transfer from the EU, NIS-2 ready
No marketing seals, just verifiable facts under GDPR Art. 32 and NIS-2 Art. 21.
GDPR Art. 32
Encryption, pseudonymization, integrity control. SecureFiles meets GDPR's technical and organizational measures by default.
NIS-2 ready
Audit log, access control, retention policies and incident response hooks cover the minimum requirements of Art. 21 NIS-2.
ISO-27001 infrastructure
Hosted on ISO-27001-certified Cloudflare EU infrastructure in the EU. Our product is not itself certified, we say that openly instead of buying seals.
No CLOUD-Act risk
Data residency within EU jurisdiction. No US corporate parent, no extraterritorial disclosure obligations.
SecureFiles vs. other secure file exchange providers
What others charge extra for, or can't do at all, SecureFiles ships by default.
SecureFilesRecommended | Other providers | |
|---|---|---|
| Max. file size | No per-file size limit | Often 1–20 GB |
| Bring your own storage | Yes, client-side encrypted | No, only TLS or server-side password derivation |
| Outlook add-in | Classic + New + Web | Partial, often with performance issues |
| Secure Inbox | Included | Separate product or unavailable |
| Virus scan by default | Integrated malware scan | Upcharge or black box |
| Passwordless retrieval | Passwordless retrieval (12-month device trust) | Not available |
| Hosting | EU jurisdiction | Often US or opaque |
| Entra ID / AD native | Out-of-the-box | Separate IAM product required |
FAQ: secure file transfer with SecureFiles
What is SecureFiles?
How large can files be?
Is SecureFiles GDPR-compliant?
Where is my data stored?
Who can access my files?
How does the passwordless retrieval work?
Can I also receive files, not only send?
How does SecureFiles integrate with Outlook?
Is there a REST API?
How much does SecureFiles cost?
It fits into your stack, not the other way round.
Native integration into the tools your team already uses, plus the compliance certificates your procurement asks for.
Ready for secure file transfer?
Set up in 5 minutes. Free pilot phase.
No lock-in, no CLOUD-Act exposure, hosted in the EU.