CONBOOL
  • Blog
  • Documentation
  • Partners
  • Contact
Get started
CONBOOL

Secure and automated email security for businesses - simple, centralized and reliable.

© Copyright 2026 Conbool. All rights reserved.

Awards
  • OMR Leader Badge für E-Mail-Sicherheit
Member of
  • Bitkom Mitglied – Digitalverband
  • BSI Allianz für Cyber-Sicherheit – Mitglied
About us
  • Blog
  • FAQ
  • Partners
  • Contact
Product
  • SecureMail
  • MailGuard
  • Disclaimer
  • Documentation
Add-ins
  • Disclaimer
  • SecureMail
  • SecureFiles
Legal
  • Terms of Service
  • Privacy Policy
  • Legal Notice
Feature · Secure Inbox

Receive filessecurely.No account required.

Every employee gets a personal upload link. Clients, patients, applicants, and suppliers send files encrypted, no account, no software, no email size limits. GDPR-compliant, hosted in the EU.

Request a demo
Go to product page
SecureFiles
EU hosting · monthly cancelable

Incoming files are the unsolved problem

Sending is easy. Receiving is the drama. Four reasons why nobody is satisfied today.

Email attachments get rejected

Your inbox caps at 25 MB. The client sends the contract three times, each time it lands in the bounce report.

WeTransfer is GDPR-risky

Your customer sends via WeTransfer, the file caches in the US. You receive it, but legally you're in a grey zone.

OneDrive shares fail on accounts

The applicant has no Microsoft account. The permission check fails. You call back and forth, or ask for another email resend.

FTP servers are a maintenance nightmare

IT doesn't want to maintain more FTP credentials. Patches, upgrades, access protocols, too much overhead for a file upload.

ihrefirma.de/sendto/max-mueller
MM
Dateien an Max Müller senden
Ihre Firma GmbH · Verschlüsselte Übertragung
Datei hier ablegen
oder klicken zum Auswählen
gutachten-2026.pdf14 MB
videokonferenz.mp41,8 GB62%
EU-Hosting · Ende-zu-Ende-verschlüsseltDSGVO-konform
Highlight · Secure Inbox

The personal upload link your externals actually complete

Every employee gets their own upload link. Clients, patients and applicants upload files right in the browser, no account, no software. Encrypted, logged, hosted in the EU.

No account required for externals, no Microsoft login, no WeTransfer detour.

End-to-end encryption from the browser, virus scanning before the file reaches your inbox.

Own subdomain and branding possible, the link feels like part of your company.

Three steps to secure receipt

The SecureFiles Secure Inbox makes uploads as simple as a WeTransfer share, but GDPR-compliant and without US cloud.

1. Share the link

Copy your personal upload link from SecureFiles and put it in your email signature, website, or a client letter.

2. External uploads

The client opens the link in a browser. No account needed. Select file, optionally set a password, upload. Encrypted in transit, malware-scanned.

3. You receive

You get a signed email notification. File is ready to pick up in SecureFiles. Audit log shows origin, IP hash, timestamp.

Everything a secure inbox needs

No form builder, no branching workflow. A personal link, the rest is security craftsmanship.

Personal upload link

Every employee has their own link, bindable to role, team, or department. No central collection inbox, clear attribution from the first upload.

End-to-end encrypted

Upload stream secured by TLS, data at rest AES-256, optional zero-knowledge with a client-side key.

Malware scan before release

Every uploaded file is scanned before delivery. Infected uploads go to quarantine, not your inbox.

Audit log per GDPR Art. 30

Who uploaded what when, including IP hash, user agent, and file size. Origin verifiable any time.

No account for externals

The client needs no Microsoft account, no Dropbox login, no Tresorit registration. Open link, upload, done.

Branded from a single source

Upload page in your logo, your colors, with your imprint. The client sees your brand, not ours.

Secure Inbox in comparison

What the usual workarounds don't deliver, and we do, in the standard.

 
SecureFiles
Typical workarounds
Account required for externals
No
Usually yes (OneDrive, Dropbox, Tresorit)
End-to-end encryption
Yes, optional client-side
TLS only
Virus scan before delivery
Malware scan by default
Rarely, often post-hoc
GDPR European hosting
Yes
Often US cloud
Audit log with IP hash
Standard
Limited or unavailable
Own branding
Included
Upcharge or unavailable

As of 2026. Comparison statements about third-party vendors are based on publicly available sources at publication time. Without warranty of continued accuracy.

FAQ: Secure Inbox

What is a secure inbox?
A secure inbox is the counterpart of secure sending: instead of you sending files to externals, externals get a way to deliver files to you encrypted. With SecureFiles, every employee gets a personal upload link. The external opens the link, uploads the file, you get a notification. Encrypted, malware-scanned, GDPR-compliant.
Do externals need an account with you?
No. That's exactly the point. The client, patient, or applicant opens the link in a browser and uploads the file. No registration, no software install, no OAuth chain with Microsoft or Google. Optionally, the employee can set a password the external enters before upload, for sensitive contexts.
How large can uploaded files be?
No hard per-file size cap. CAD drawings, DICOM imaging, video recordings, and database exports are receivable without the external needing a split workflow.
Is the Secure Inbox GDPR-compliant?
Yes. Upload infrastructure is in the EU, TLS in-transit and AES-256 at-rest are standard. Every file is auditable via the audit log (GDPR Art. 30), IP addresses are hashed, retention is configurable per tenant. A DPA template is available on request.
Are uploaded files scanned for malware?
Yes. Every upload goes through a malware scan before the file is released to the receiving employee. Infected files go to quarantine automatically, you get a notification, the original file never reaches you.
How long are received files kept?
Retention is configured per tenant, default is 10 days, selectable between 7, 10, and 30 days. After expiry the file is deleted automatically. For longer retention needs, move the file to your records during the retention window.
Which industries benefit most from the Secure Inbox?
Any industry where externals submit confidential documents: law firms (client contracts), medical practices (MRI results, patient documents), HR (applicant references, health certificates), procurement (CAD drawings from suppliers), tax advisors (receipts from clients), insurers (damage photos). Industries handling GDPR Art. 9 categories gain the most.
How does this differ from a client portal?
A classic client portal is a persistent dashboard with login, folder structure, and ongoing relationship. The Secure Inbox is lighter: a one-time upload flow without the external registering or managing files. Perfect for ad-hoc receipt; for ongoing collaboration we recommend our data room solution (in planning).

Verwandte Lösungen

WeTransfer-Alternative

DSGVO-konformer Dateiversand aus der EU, ohne CLOUD-Act-Risiko.

Cryptshare-Alternative

Modulare deutsche Alternative mit echtem Zero-Knowledge.

FTP-Alternative

Sicherer Dateitransfer statt FTP — Outlook-Add-in, Audit-Log, NIS-2.

DSGVO-konformer Dateiversand

Verschlüsselter Dateiversand nach Art. 32 DSGVO und NIS-2.

Große Dateien per Outlook

Outlook-Anhang zu groß? Direkt aus Outlook verschlüsselt versenden.

Launch your Secure Inbox.

30-minute demo. Free pilot phase. Your clients will love it.

Request a demoEverything about SecureFiles

Full audit log: uploader, IP hash, timestamp, automatic retention.