Most "secure" sharing is access control on readable files. Here is the architecture of a share link that stays confidential even from the provider hosting it.
Three private surfaces. Same zero-knowledge architecture.
The architectural one: the file is ciphertext everywhere, and sharing means delivering a key to a specific person. A misconfiguration then exposes bytes nobody can read.
Three private surfaces. Same zero-knowledge architecture.