← Blog
File transfer6 min read

Encrypted file sharing vs WeTransfer: what is actually private?

A plain comparison of consumer transfer services and zero-knowledge sharing: who holds the keys, what a download password protects, and when each is fine.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Two different products wearing similar labels Consumer transfer services and zero-knowledge sharing tools both give you a link. They differ in one respect that determines everything else: whether the operator can open the file.

What "password protected" protects On a typical transfer service, a download password is a gate in front of a file the server can already read. It stops a stranger who finds the URL. It does not stop the service, its automated systems, an integration or anyone with legal access.

In a zero-knowledge system, the passphrase is part of deriving the key. There is no readable file behind the gate to protect in the first place.

What "encrypted" usually means Almost every service is encrypted in transit (TLS) and at rest (disk encryption). Both are worth having. Neither prevents the provider from reading your content, because the provider holds those keys.

Client-side encryption is the only model where plaintext exists solely on sender and recipient devices.

Expiry: convenience or control? A link that lives for a week is a convenience. A link that lives for hours is a control. The realistic threat is not cryptanalysis; it is a link forwarded to a group chat, pasted into a ticket, or rediscovered in an old email years later.

DRIVUNO caps public links at 24 hours, with the option to go shorter, limit views and revoke on the spot. For ongoing access, membership of an encrypted space replaces the link entirely.

Where consumer transfer still makes sense Public marketing assets, press kits, wallpapers, anything already destined for the open internet. There is no confidentiality to protect, and the free tier is genuinely convenient.

Where it stops making sense Client deliverables under NDA, unreleased creative work, source code, contracts, medical or legal documents, identity papers, salary data. For these, "the provider promises not to look" is a weaker guarantee than "the provider cannot look".

An honest comparison table in words - **Who can read the file:** consumer transfer — sender, recipient and the provider's systems. Zero-knowledge — sender and recipient only. - **Download password:** access check versus part of key derivation. - **Expiry:** typically days to weeks versus 24 hours maximum here. - **Revocation:** usually available on both; only meaningful when the operator also cannot read what remains. - **Recovery if you lose credentials:** support can help versus nobody can, including us. - **Scanning and advertising:** common on free consumer tiers versus impossible on ciphertext.

The rule of thumb If the file being read by a stranger would cost you money, a client or a reputation, the key belongs on your device.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Encrypted on your device · upload in 1 click
Upload