White-label · end-to-end encrypted

Files only you and your recipient can open. Not us. Not anyone.

Encrypted file transfer under your own branded space, stored in the EU. Your clients see you, not us. Everything is encrypted in your browser before it leaves the device, so we hold ciphertext and never need the key.

AES-256-GCM
EU data residency
GDPR-compliant by architecture
acme.nullsend.io runs in your browser
Edit this, then run the demo. It encrypts whatever you type.

With the file-transfer tools most people reach for, your files arrive on their servers readable, and what happens next comes down to a policy. And policies change. We took that question off the table. The protection is in the architecture, not a promise we could quietly revise.

What we cannot do

The things we cannot do, by design.

Nullsend's architecture makes certain things cryptographically impossible, not just restricted by our own policy. That is the entire product.

01

We can't read your files

Files are encrypted in your browser before upload. Our servers see only ciphertext.

ciphertext only
02

We can't train AI on them

You can't train on what you can't see. No model, ours or anyone else's, gets your data.

nothing readable
03

We can't hand them over

A subpoena gets ciphertext and metadata. That is useless without the key, which we never have.

nothing to surrender
04

We can't preview them

No thumbnails. No previews. No virus scanning. These trade-offs are the point.

no plaintext access
05

We can't recover them

Lose the link, lose the file, for good. By design, because anything else is a backdoor.

no escrow
06

We can't change our mind

Architectural guarantees don't depend on a Terms of Service we could change next year.

fixed by maths
How it works

Three steps. One encryption key. None of them touch our servers.

The key is generated in your browser and lives in the share URL fragment. On the normal share path it is never transmitted to Nullsend. End to end, with the key only ever on the two devices that need it.

01 · encrypt

In your browser

When you drop a file in, your browser generates a random 256-bit AES key and encrypts each chunk locally. The plaintext never leaves your device.

02 · upload

Ciphertext only

Encrypted chunks stream directly to EU-resident storage. Our servers store ciphertext and metadata. We see what you uploaded, not what is in it.

03 · share

Key in the URL fragment

The decryption key lives after the # in the share URL. By web standards, fragments never reach the server. Share the URL; only the recipient can decrypt.

On the normal share path the key is never transmitted. Verify it: RFC 3986 §3.5.
End-to-end encryption flow File is encrypted in the sender's browser, ciphertext goes to Nullsend's storage, recipient downloads ciphertext and decrypts in their browser using the key from the URL fragment. SENDER · BROWSER file.pdf + AES-256 key → ciphertext ciphertext NULLSEND EU storage stores ciphertext no key, ever ciphertext RECIPIENT · BROWSER key from URL # → decrypt file.pdf key travels in the URL fragment, not through our server on this path
The architecture

The architecture behind the guarantee.

Everything you would expect from a serious file-transfer tool, with the privacy parts built into how it works rather than promised in a policy.

White-label

Your own branded space at yourfirm.nullsend.io, in your colours. Recipients land on a page that looks like yours.

AES-256-GCM

Industry-standard authenticated encryption. WebCrypto-native. No custom crypto, no rolled-our-own anything.

Auto-expiry

Files self-destruct on a schedule you set: 7, 30, 90 days, or on first download. No manual cleanup.

EU data residency

Ciphertext stored in EU-Central. GDPR-compliant by architecture. DPA available before signup.

Optional passwords

Add a recipient password for two-factor access. Stretched with Argon2id; we still can't see the key.

Team access

Admin, sender, and view-only roles. Per-user audit log of who sent what, never of what is in it.

Branded delivery

Notification emails carry your name and branding, sent from a Nullsend address. Your clients see you when the file lands.

Honest pricing

Flat monthly per tier. Overage at £0.05/GB. No tracking pixels, no upsells, no surprise renewals.

Pricing

Three tiers. No free plan.
14-day money-back.

Nullsend is B2B-only. There is no free tier because there is no advertising revenue, no data resale, and no other way for the lights to stay on. Pick a tier; pay monthly.

Speeder

For solo practitioners.

£19/mo
  • 50 GB storage
  • 5 GB per transfer
  • 3 users
Choose Speeder
Falcon

For agencies and small firms.

£49/mo
  • 250 GB storage
  • 20 GB per transfer
  • 10 users
Choose Falcon
Cruiser

For mid-size practices.

£99/mo
  • 1 TB storage
  • 100 GB per transfer
  • 50 users, 90-day retention
Choose Cruiser

Ex-VAT. UK and EU billing only at launch. Flat per tier, overage at £0.05/GB, no surprise renewals. Full pricing

Enterprise

Need it on your own domain?

Nullsend Enterprise puts your firm's brand, custom domain, and sender email on the front, with our encryption underneath and a discreet "powered by Nullsend" your clients can trust.

See Nullsend Enterprise
Mobile

Nullsend on mobile

iOS and Android apps in development. The same browser-side encryption, in your pocket. We will let you know the moment they land.

nullsend
New transfer
contract-v4.pdf
2.4 MB · encrypted
Send toalice@client.com
Expires7 days
PasswordOn
Send securely
powered by Nullsend · encrypted in the EU

Set up your branded space in under a minute.

14-day money-back on any tier. Encrypted in the browser from the first upload. No card needed to try the flow.

Get started

Or talk to us about Enterprise.