Included from Suite 1recipient plan

Securefile transfer,without limits.

Send and receive encrypted, straight from Outlook. Hosted in the EU, GDPR-compliant, no US cloud. For teams exchanging sensitive data who'd rather not worry about it.

What SecureFiles does

Large files, no more FTP.

Send, receive, document — click through the capabilities.

Send multi-GB files straight from Outlook.

Compose an email as usual — large attachments upload to storage automatically and are replaced by a download link. The recipient sees no difference.

  • Multiple GB per file, no more mail server limits
  • Smart switch: small attachments stay in the mail
  • Add-in shows status and recipient access in real time
  • Works in Outlook desktop, web and mobile

External parties upload files securely to you.

Send an upload link to clients, patients or applicants. They upload without an account, you see what arrived immediately.

  • Upload link with expiry date and max size
  • External parties need no Conbool account
  • Virus and PDF inspection before your inbox
  • Branding with your logo and domain

Recipients download without an account, without a password.

Instead of sender-set passwords, SecureFiles ships signed one-time links to the recipient address. Safer than passwords in the same mail, and friendlier.

  • One-time links with configurable lifetime
  • Optional: password as a second factor
  • Revoke access any time — even after sending
  • Recipient acknowledgement to you

Encrypted storage — hosting in Germany.

Data never leaves the EU. ISO-certified data centres in Germany, DPA included, no US cloud in the critical path.

  • AES-256 encrypted at rest
  • Hosted in Germany, run by a German company
  • DPA included, no US sub-processor
  • Customer-managed keys possible (BYOK)

Every download traceable — every file under control.

See who, when and from which IP downloaded a file. Retention and deletion deadlines are enforced automatically.

  • Audit log with IP, user agent and timestamp
  • Automatic deletion after retention (GDPR Art. 17)
  • Reports for auditors and data protection
  • Access revocable any time

Sending files today vs. secure file transfer with SecureFiles.

Why 25 MB attachment caps, forced cloud logins and consumer filesharing aren't an answer to GDPR-compliant file exchange.

Without SecureFiles

  • 25 MB attachment limit caps every larger file.
  • Cloud shares force recipients to log in to the provider.
  • Consumer filesharing caches in the US. GDPR grey zone.
  • FTP requires CLI knowledge and plaintext passwords.
  • Externals can't securely send you files back.

With SecureFiles

  • Files of any size straight from Outlook, one click, done.
  • Recipient opens the link with no account, no software.
  • Hosted in the EU, encrypted in transit and at rest.
  • SSO via Entra ID, audit log per GDPR Art. 30.
  • Secure Inbox, externals send files back to you securely.
Sharing modes

Three ways to share files securely.

Every use case asks for a different kind of share. SecureFiles ships all three out of one product, without tier upcharges.

By email

To specific recipients

Encrypted transfer to named email addresses. Every recipient gets their own download budget. A reply channel can be enabled for return uploads.

Shared pool

Shared file space

Your team creates a shared pool where internal and external participants upload and download over time. One shared file space per project or engagement, the secure alternative to SharePoint, without a Microsoft account for externals.

Open link

Public share

One link to distribute freely, perfect for press material, event recordings or product data sheets. Download-only with a hard total-download cap, optionally password-protected.

Sicherheit

Encryption, malware scan and audit log by default

The security controls GDPR Art. 32 and NIS-2 demand run quietly in the background, no extra click. TLS 1.3 in transit, AES-256 at rest, key management in the EU. On request we set up an end-to-end mode in which the key stays in the browser; the server-side malware scan is then unavailable.

Encryption and storage sovereignty

TLS 1.3 in transit, AES-256 at rest, key management in the EU. If you want the files in your own storage, attach your own S3 bucket in Germany.

Client-sideAES-256No key transmissionEven we only see ciphertext

Malware scan by default

Every file is scanned before release. While the scan runs, the transfer shows as 'being checked'. Infected uploads are rejected and never reach the recipient. No upcharge, no black box.

Audit log for every transfer

Who sent what when, who downloaded when. GDPR Art. 30 ready. IP hashing protects privacy.

Multi-tenant & Entra ID

Native Entra ID integration, SSO, group policies, tenant isolation from a single product. No separate IAM tool needed.

Cloud or on-premise

Pick the operating mode that fits your compliance profile. Fully managed GDPR cloud in the EU, or installed in your own data center.

Alltag

Secure file transfer straight from Outlook, for every team

From first click to final download, no portal, no login friction, no context switch.

Any file size

From 20 MB presentations to multi-terabyte CAD models. Performant, retry-capable, multipart upload. No hard per-file size limit.

Multipart-Upload
Chunked
Retry-fähig
Automatisch
Tier-Staffelung
Standard / Enterprise

Passwordless retrieval for returning recipients

Returning recipients skip password entry for 12 months. Device-bound trust, revocable, GDPR-compliant.

Outlook add-in

Seamless in classic and new Outlook. Desktop, Web, Mobile. One click, done.

Mail in your own tone

Notification emails to recipients are fully customizable: sender name, tone, wording, layout. The recipient sees your brand, not ours.

Retention from 1 hour to 365 days

Expiry periods configurable per tenant: from hours to years, optionally unlimited. Download limits per link. Automatic deletion after expiry.

Public share link

One link for everyone: ideal for press materials, event recordings, or product datasheets. Download-only, with a hard total download cap and tightened rate-limiting against abuse. Optional password.

securefiles.app/transfer/9f2a
Im Browser
vertrag.pdf
Klartext
Auf dem Server
af3b9c1d7e4f2a88b561c3d9f0e28a11c7b6f4e2d9c38b57a1
vertrag.pdf.enc
Chiffrat
AES-256 · Speicher wahlweise im eigenen BucketStored encrypted
Verschlüsselung

Encrypted at rest, storage location your choice

TLS 1.3 in transit, AES-256 at rest. If you would rather the files did not sit with us, attach your own S3 bucket in Germany.

  • TLS 1.3 for upload and download
  • AES-256 at rest, key management in the EU
  • Download runs directly between recipient and storage, no proxy in between
  • Bring your own S3 bucket in Germany, residency checked per preset
  • Provable deletion on expiry, every action in the audit log
ihrefirma.de/sendto/max-mueller
MM
Send files to Max Müller
Your Company Ltd · encrypted transfer
Datei hier ablegen
or click to choose
gutachten-2026.pdf14 MB
videokonferenz.mp41,8 GB62%
Hosted in the EU · encrypted in transit and at restDSGVO-konform
Highlight · Sicherer Posteingang

Secure Inbox: receive files from clients, patients and suppliers securely

Sending is only half the job. With pool folders, every team creates a secure upload space and invites externals by email. Clients, patients, applicants or suppliers upload files encrypted, no account, no software install. The team gets a signed notification.

Law firm: clients upload contracts securely.

Medical practice: patients send MRI scans GDPR-compliant.

HR: applicants deliver references encrypted.

Procurement: suppliers hand over CAD drawings protected.

Highlight · Strukturierte Anforderung

Request exactly the documents you need.

Instead of an empty upload field, you define a guided checklist: named documents, required or optional, with format rules. The recipient sees at a glance what is still missing and uploads document by document. No account, encrypted, virus-scanned.

  • Guided checklist with groups plus required and optional documents.
  • Reusable templates for onboarding, account opening or case files.
  • Per-document review: accept or return with a note for correction.
  • No account for external senders, GDPR-compliant, hosted in Europe.
ihrefirma.de/upload/kontoeroeffnung
Documents for opening an account
Your Company Ltd · 3 of 5 documents
Identität
Personalausweis Vorderseite
Personalausweis Rückseite
MeldebescheinigungPflicht
Einkommen
Gehaltsnachweis, 3 Monate
Aktueller KontoauszugPflicht
Encrypted · virus checked · hosted in the EUDSGVO-konform
Passwordless-Abruf

Secure file sharing without password ping-pong: passwordless retrieval for returning recipients

On the first retrieval, the recipient verifies with a password. For 12 months, their device remembers the trust relationship. The second, third, tenth transfer arrives without the password ping-pong, more secure than emailed passwords, more convenient than any alternative.

  • Device-bound trust (12 months)
  • Revocable by admin or user at any time
  • Rate-limited + IP-hashed against abuse
MacBook Pro · Chrome
vertraut seit 03. Feb. 2026
AKTIV
1
Erster Transfer
Passwort eingegeben
2
Transfer 2
Ohne Passwort · Device erkannt
3
Transfer 3
Ohne Passwort · Device erkannt
·
Transfer n
… für 12 Monate
Device-Trust9 Mon. verbleibend
Neue E-Mail. Outlook
Senden
Attach
Signieren
SecureFiles
Anmax@kunde.de
BetreffDraft contract + blueprints
2 Dateien sicher verpackt
Attachments replaced by an encrypted link
vertrag-2026.pdf8 MB
blueprints-A1.dwg2,4 GB
Direkt in Outlook

Send large files straight from Outlook, no portal, no context switch

The SecureFiles add-in integrates with classic Outlook, new Outlook and Outlook on the Web. One click switches the attachment to an encrypted link, no new interface, no context switch.

  • Classic Outlook
  • New Outlook + Outlook on the Web
  • Central rollout via Microsoft 365 Admin Center

GDPR-compliant file transfer from the EU, NIS-2 ready

No marketing seals, just verifiable facts under GDPR Art. 32 and NIS-2 Art. 21.

GDPR Art. 32

Encryption, pseudonymization, integrity control. SecureFiles meets GDPR's technical and organizational measures by default.

NIS-2 ready

Audit log, access control, retention policies and incident response hooks cover the minimum requirements of Art. 21 NIS-2.

ISO-27001 infrastructure

Hosted on ISO-27001-certified Cloudflare EU infrastructure in the EU. Our product is not itself certified, we say that openly instead of buying seals.

No CLOUD-Act risk

Data residency within EU jurisdiction. No US corporate parent, no extraterritorial disclosure obligations.

SecureFiles vs. other secure file exchange providers

What others charge extra for, or can't do at all, SecureFiles ships by default.

 
SecureFilesRecommended
Other providers
Max. file size
No per-file size limit
Often 1–20 GB
Bring your own storage
Yes, client-side encrypted
No, only TLS or server-side password derivation
Outlook add-in
Classic + New + Web
Partial, often with performance issues
Secure Inbox
Included
Separate product or unavailable
Virus scan by default
Integrated malware scan
Upcharge or black box
Passwordless retrieval
Passwordless retrieval (12-month device trust)
Not available
Hosting
EU jurisdiction
Often US or opaque
Entra ID / AD native
Out-of-the-box
Separate IAM product required

FAQ: secure file transfer with SecureFiles

What is SecureFiles?
SecureFiles is the secure way to send large files by email, including a secure inbox for external uploads. Files of any size are encrypted in transit, stored in the EU, and automatically deleted after the configured retention period. Integrated with Outlook (classic, new, and Web) as well as a web client.
How large can files be?
No hard per-file size limit, up to 50 files per transfer. That comfortably covers CAD drawings, video production, database exports, and medical imaging, up to multi-terabyte scenarios.
Is SecureFiles GDPR-compliant?
Yes. SecureFiles meets the technical and organizational measures of GDPR Art. 32 by default: encryption (in-transit TLS 1.3 + at-rest AES-256), access control, integrity control, processing control, and logging via audit log. A ready-to-sign DPA is available on request.
Where is my data stored?
In the EU am Main, on ISO-27001-certified EU cloud infrastructure with EU jurisdiction. No US corporate parent, no extraterritorial disclosure obligations (no CLOUD-Act risk). Our product is not itself ISO-27001-certified, the underlying infrastructure is.
Who can access my files?
Access is bound to the recipient. Every recipient gets their own link with its own download budget, optionally password protected and with an expiry date. The download runs directly between recipient and storage via a signed URL, file content never passes an intermediate proxy. Key management sits with us in the EU. If you would rather it did not, attach your own S3 bucket in Germany and the files stay in your infrastructure.
How does the passwordless retrieval work?
On the first download, the recipient verifies with a password. Their device receives a tenant-bound trust token, valid for 12 months. Follow-up transfers from the same sender to the same recipient on the same device arrive without a password. Safer than emailing passwords, more convenient than any alternative. Admin and user can revoke the token at any time.
Can I also receive files, not only send?
Yes. Pool folders let your team create a secure upload space and invite externals by email. Clients, patients, applicants or suppliers upload encrypted, no account, no software, no email size limit. Notifications run through SecureFiles, files are virus-scanned before release.
How does SecureFiles integrate with Outlook?
The SecureFiles add-in runs in classic Outlook (COM), new Outlook, and Outlook on the Web. It's rolled out centrally via Microsoft 365 Admin Center. Users work as usual, one click replaces the attachment with an encrypted link. No training required.
Is there a REST API?
A public REST API is planned for Q3 2026 (Phase 2). Today, we can already provide webhooks and CLI-based integrations on request.
How much does SecureFiles cost?
SecureFiles is billed per user per month, with a Standard and an Enterprise tier (the latter with a higher per-file size cap, plus extended branding and compliance features). Contact us for an individual quote.
Enterprise-Ready

It fits into your stack, not the other way round.

Native integration into the tools your team already uses, plus the compliance certificates your procurement asks for.

Microsoft 365
Exchange Online
Classic Outlook
COM Add-in
New Outlook
Web & Desktop
Entra ID
SSO & Groups
Active Directory
Hybrid
Apple Mail
macOS & iOS
DSGVO Art. 32
NIS-2-ready
Europäisches Hosting
EU-Rechtsraum

Ready for secure file transfer?

Set up in 5 minutes. Free pilot phase.

No lock-in, no CLOUD-Act exposure, hosted in the EU.