DEV Community

Cover image for Sharing Confidential Documents Online? Start With an Expiry Date
Alisha Albert
Alisha Albert

Posted on

Sharing Confidential Documents Online? Start With an Expiry Date

Most of us send a sensitive document the same way we send everything else: as an email attachment. A signed contract to a lawyer. Tax paperwork to an accountant. Medical records to a clinic. We attach the file, type "as discussed," and hit send without thinking twice about it.

The problem is that an email attachment never really goes away. It sits in your sent folder. It sits in the recipient's inbox. It gets forwarded, downloaded onto shared drives, backed up to servers you will never hear about. Months later, long after everyone has forgotten about it, copies of your passport scan or financial statement are still sitting in inboxes that are only as secure as the weakest password protecting them.

You cannot fix that with a better password. You need a different way of sharing.

What actually makes document sharing safe

Security guides tend to throw a long checklist at you, but most of it boils down to three things.

1. Limit how long the document is available. A link that works forever is a liability. The moment the recipient has the document, there is no reason for it to still be out there. Set an expiry. Short ones — an hour, a day — for things that are time-sensitive. A few days at most for everything else.

2. Keep it off email. Once a file travels as an attachment, you lose control of it. You cannot revoke it, expire it, or even know where it ended up. A share link at least keeps the document in one place until the recipient grabs it.

3. Send access details separately. If you password-protect a PDF (which is a good habit for anything with a signature or ID number in it), do not put the password in the same email as the file. Send the link one way, the code another way. It takes thirty extra seconds and it closes the simplest attack there is: someone getting into one account and getting both.

A lighter way to do it

For a lot of everyday confidential documents, you do not need an enterprise data room. You need something between "email attachment" and "corporate security portal."

That is where view-once file sharing earns its keep. You open the site in your browser — no account, nothing to install — drop in the file, and pick how long the share should live: one hour, a day, three days, or a week. You get a short code and a QR, and the document deletes itself when the clock runs out. The file stays unlisted and encrypted while it is up.

It also fits the small realities of confidential sharing. Need your accountant to get a 200 MB folder of scanned receipts? Files go through as-is, up to 250 MB each, with no compression quietly mangling your scans. Need your lawyer to see the signed contract right now? A view-once share can delete itself the moment it is opened, so the document exists exactly as long as it needs to and not a minute longer.

A short routine that actually works

Here is the routine I would suggest for anything sensitive:

  • Before sending: ask whether it needs to live forever. If not, give it an expiry. Default to short.
  • While sending: use a share link instead of an attachment, and keep the code or password in a separate message from the link itself.
  • After sending: if the tool lets the share delete itself after viewing, turn that on. If not, check back and take the link down once the recipient confirms they have it.

None of this is complicated, and that is the point. The reason confidential documents leak is rarely a sophisticated hack. It is an old attachment in a forgotten inbox, or a link that someone shared three months ago and never turned off. Expiry dates and separate channels do not sound dramatic, but they close the gaps that actually get people in trouble.

The next time you are about to attach a document you would not want posted publicly, pause for the thirty seconds it takes to send confidential files with an expiring link instead. Your future self — the one not digging through sent folders wondering where that file ended up — will be glad you did.

Top comments (0)