CONBOOL
  • Blog
  • Documentation
  • Partners
  • Contact
Get started
CONBOOL

Secure and automated email security for businesses - simple, centralized and reliable.

© Copyright 2026 Conbool. All rights reserved.

Awards
  • OMR Leader Badge für E-Mail-Sicherheit
Member of
  • Bitkom Mitglied – Digitalverband
  • BSI Allianz für Cyber-Sicherheit – Mitglied
About us
  • Blog
  • FAQ
  • Partners
  • Contact
Product
  • SecureMail
  • MailGuard
  • Disclaimer
  • Documentation
Add-ins
  • Disclaimer
  • SecureMail
  • SecureFiles
Legal
  • Terms of Service
  • Privacy Policy
  • Legal Notice
New · Available now

Securefile transfer,without limits.

Send and receive encrypted, straight from Outlook. Hosted in the EU, GDPR-compliant, no US cloud. For teams exchanging sensitive data who'd rather not worry about it.

Request a demoLearn more

Sending files today vs. secure file transfer with SecureFiles.

Why 25 MB attachment caps, forced cloud logins and consumer filesharing aren't an answer to GDPR-compliant file exchange.

Without SecureFiles

  • 25 MB attachment limit caps every larger file.
  • Cloud shares force recipients to log in to the provider.
  • Consumer filesharing caches in the US. GDPR grey zone.
  • FTP requires CLI knowledge and plaintext passwords.
Sharing modes

Three ways to share files securely.

Every use case asks for a different kind of share. SecureFiles ships all three out of one product, without tier upcharges.

By email

To specific recipients

Encrypted transfer to named email addresses. Every recipient gets their own download budget. A reply channel can be enabled for return uploads.

Shared folder

Secure inbox

Your team creates a shared pool folder and invites externals by email. Clients, patients and suppliers deliver files without an account, without installing software.

Sicherheit

End-to-end encryption, malware scan and audit log by default

The security controls GDPR Art. 32 and NIS-2 demand run quietly in the background, no extra click.

Zero-Knowledge end-to-end

Optionally client-side encrypted, we cannot technically decrypt your data. Not derived from the password, true zero-knowledge.

securefiles.app/transfer/9f2a
Im Browser
vertrag.pdf
Klartext
Auf dem Server
ihrefirma.de/sendto/max-mueller
MM
Dateien an Max Müller senden
Ihre Firma GmbH · Verschlüsselte Übertragung
Datei hier ablegen
oder klicken zum Auswählen
gutachten-2026.pdf14 MB
Passwordless-Abruf

Secure file sharing without password ping-pong: passwordless retrieval for returning recipients

On the first retrieval, the recipient verifies with a password. For 12 months, their device remembers the trust relationship. The second, third, tenth transfer arrives without the password ping-pong, more secure than emailed passwords, more convenient than any alternative.

  • Device-bound trust (12 months)
  • Revocable by admin or user at any time
  • Rate-limited + IP-hashed against abuse
MacBook Pro · Chrome
vertraut seit 03. Feb. 2026
Neue E-Mail. Outlook
Senden
Anfügen
Signieren
SecureFiles
Anmax@kunde.de
BetreffVertragsentwurf + Baupläne

GDPR-compliant file transfer from the EU, NIS-2 ready

No marketing seals, just verifiable facts under GDPR Art. 32 and NIS-2 Art. 21.

GDPR Art. 32

Encryption, pseudonymization, integrity control. SecureFiles meets GDPR's technical and organizational measures by default.

NIS-2 ready

Audit log, access control, retention policies and incident response hooks cover the minimum requirements of Art. 21 NIS-2.

ISO-27001 infrastructure

Hosted on ISO-27001-certified Cloudflare EU infrastructure in the EU. Our product is not itself certified, we say that openly instead of buying seals.

SecureFiles vs. other secure file exchange providers

What others charge extra for, or can't do at all, SecureFiles ships by default.

 
SecureFilesRecommended
Other providers
Max. file size
No per-file size limit
Often 1–20 GB
Zero-Knowledge (E2E)
Yes, client-side encrypted

FAQ: secure file transfer with SecureFiles

What is SecureFiles?
SecureFiles is the secure way to send large files by email, including a secure inbox for external uploads. Files of any size are encrypted in transit, stored in the EU, and automatically deleted after the configured retention period. Integrated with Outlook (classic, new, and Web) as well as a web client.
How large can files be?
No hard per-file size limit, up to 50 files per transfer. That comfortably covers CAD drawings, video production, database exports, and medical imaging, up to multi-terabyte scenarios.
Is SecureFiles GDPR-compliant?
Yes. SecureFiles meets the technical and organizational measures of GDPR Art. 32 by default: encryption (in-transit + at-rest + optional zero-knowledge), access control, integrity control, processing control, and logging via audit log. A ready-to-sign DPA is available on request.
Enterprise-Ready

Fügt sich in Ihren Stack, nicht umgekehrt.

Native Integration in die Tools, die Ihr Team heute nutzt. Und die Compliance-Siegel, die Ihr Einkauf verlangt.

Microsoft 365
Exchange Online
Classic Outlook
COM Add-in
New Outlook
Web & Desktop
Entra ID

Ready for secure file transfer?

Set up in 5 minutes. Free pilot phase.

No lock-in, no CLOUD-Act exposure, hosted in the EU.

Start free trialContact
Discover WeTransfer alternativeCryptshare alternativeSend large files from Outlook
Externals can't securely send you files back.

With SecureFiles

  • Files of any size straight from Outlook, one click, done.
  • Recipient opens the link with no account, no software.
  • Hosted in the EU, end-to-end encrypted.
  • SSO via Entra ID, audit log per GDPR Art. 30.
  • Secure Inbox, externals send files back to you securely.
Open link

Public share

One link to distribute freely, perfect for press material, event recordings or product data sheets. Download-only with a hard total-download cap, optionally password-protected.

Client-side
AES-256
No key transmission
Even we only see ciphertext

Malware scan by default

Every file is scanned before release. While the scan runs, the transfer shows as 'being checked'. Infected uploads are rejected and never reach the recipient. No upcharge, no black box.

Audit log for every transfer

Who sent what when, who downloaded when. GDPR Art. 30 ready. IP hashing protects privacy.

Multi-tenant & Entra ID

Native Entra ID integration, SSO, group policies, tenant isolation from a single product. No separate IAM tool needed.

Cloud or on-premise

Pick the operating mode that fits your compliance profile. Fully managed GDPR cloud in the EU, or installed in your own data center.

Alltag

Secure file transfer straight from Outlook, for every team

From first click to final download, no portal, no login friction, no context switch.

Any file size

From 20 MB presentations to multi-terabyte CAD models. Performant, retry-capable, multipart upload. No hard per-file size limit.

Multipart-Upload
Chunked
Retry-fähig
Automatisch
Tier-Staffelung
Standard / Enterprise

Passwordless retrieval for returning recipients

Returning recipients skip password entry for 12 months. Device-bound trust, revocable, GDPR-compliant.

Outlook add-in

Seamless in classic and new Outlook. Desktop, Web, Mobile. One click, done.

Mail in your own tone

Notification emails to recipients are fully customizable: sender name, tone, wording, layout. The recipient sees your brand, not ours.

Retention from 1 hour to 365 days

Expiry periods configurable per tenant: from hours to years, optionally unlimited. Download limits per link. Automatic deletion after expiry.

af3b9c1d7e4f2a88b561c3d9f0e28a11c7b6f4e2d9c38b57a1
vertrag.pdf.enc
Chiffrat
AES-256 · Schlüssel bleibt bei IhnenZero-Knowledge
Zero-Knowledge

End-to-end encryption with true zero-knowledge

The file is encrypted in your browser before it reaches our server. The key never leaves your device, only the recipient can decrypt.

  • Client-side AES-256 encryption
  • Server only sees ciphertext, no plaintext
  • Key never leaves the sender's device
  • No key derived from the password (true zero-knowledge)
  • On lawful requests we can hand over only ciphertext
videokonferenz.mp41,8 GB62%
EU-Hosting · Ende-zu-Ende-verschlüsseltDSGVO-konform
Highlight · Sicherer Posteingang

Secure Inbox: receive files from clients, patients and suppliers securely

Sending is only half the job. With pool folders, every team creates a secure upload space and invites externals by email. Clients, patients, applicants or suppliers upload files encrypted, no account, no software install. The team gets a signed notification.

Law firm: clients upload contracts securely.

Medical practice: patients send MRI scans GDPR-compliant.

HR: applicants deliver references encrypted.

Procurement: suppliers hand over CAD drawings protected.

AKTIV
1
Erster Transfer
Passwort eingegeben
2
Transfer 2
Ohne Passwort · Device erkannt
3
Transfer 3
Ohne Passwort · Device erkannt
·
Transfer n
… für 12 Monate
Device-Trust9 Mon. verbleibend
2 Dateien sicher verpackt
Anhänge durch verschlüsselten Link ersetzt
vertrag-2026.pdf8 MB
baupläne-A1.dwg2,4 GB
Direkt in Outlook

Send large files straight from Outlook, no portal, no context switch

The SecureFiles add-in integrates with classic Outlook, new Outlook and Outlook on the Web. One click switches the attachment to an encrypted link, no new interface, no context switch.

  • Classic Outlook
  • New Outlook + Outlook on the Web
  • Central rollout via Microsoft 365 Admin Center

No CLOUD-Act risk

Data residency within EU jurisdiction. No US corporate parent, no extraterritorial disclosure obligations.

No, only TLS or server-side password derivation
Outlook add-in
Classic + New + Web
Partial, often with performance issues
Secure Inbox
Included
Separate product or unavailable
Virus scan by default
Integrated malware scan
Upcharge or black box
Passwordless retrieval
Passwordless retrieval (12-month device trust)
Not available
Hosting
EU jurisdiction
Often US or opaque
Entra ID / AD native
Out-of-the-box
Separate IAM product required
Where is my data stored?
In the EU am Main, on ISO-27001-certified EU cloud infrastructure with EU jurisdiction. No US corporate parent, no extraterritorial disclosure obligations (no CLOUD-Act risk). Our product is not itself ISO-27001-certified, the underlying infrastructure is.
What exactly does Zero-Knowledge mean?
In zero-knowledge mode, your browser encrypts the file before it reaches our server. The key is never transmitted. Even under lawful disclosure we could only hand over ciphertext, technically useless. Many providers market as E2E but derive the key server-side from the password. That isn't zero-knowledge. Ours is.
How does the passwordless retrieval work?
On the first download, the recipient verifies with a password. Their device receives a tenant-bound trust token, valid for 12 months. Follow-up transfers from the same sender to the same recipient on the same device arrive without a password. Safer than emailing passwords, more convenient than any alternative. Admin and user can revoke the token at any time.
Can I also receive files, not only send?
Yes. Pool folders let your team create a secure upload space and invite externals by email. Clients, patients, applicants or suppliers upload encrypted, no account, no software, no email size limit. Notifications run through SecureFiles, files are virus-scanned before release.
How does SecureFiles integrate with Outlook?
The SecureFiles add-in runs in classic Outlook (COM), new Outlook, and Outlook on the Web. It's rolled out centrally via Microsoft 365 Admin Center. Users work as usual, one click replaces the attachment with an encrypted link. No training required.
Is there a REST API?
A public REST API is planned for Q3 2026 (Phase 2). Today, we can already provide webhooks and CLI-based integrations on request.
How much does SecureFiles cost?
SecureFiles is billed per user per month, with a Standard and an Enterprise tier (the latter with a higher per-file size cap, plus extended branding and compliance features). Contact us for an individual quote.
SSO & Groups
Active Directory
Hybrid
Apple Mail
macOS & iOS
DSGVO Art. 32
NIS-2-ready
Europäisches Hosting
EU-Rechtsraum
Secure Inbox