Building a True Zero-Knowledge File Sharing Tool with Client-Side Encryption
Most “secure” file sharing tools still hold the encryption keys or can decrypt your files on their servers. I wanted something different — a tool where even I, as the operator, mathematically cannot access the contents.
So I built SendShield Files.
The Core Idea
Files are encrypted entirely in the browser before they ever leave the user’s device. The decryption key never reaches the server.
How it works
- The browser generates a random file key.
- The file is split into 16 MiB chunks and encrypted with AES-256-GCM using the Web Cryptography API.
- The decryption key is placed only in the URL fragment (
#key=...). - According to RFC 3986, the fragment is never sent to the server in the HTTP request.
- The server only stores ciphertext.
Result: zero-knowledge architecture. We cannot decrypt your files even if we wanted to.
Two Main Flows
1. Send a File
- Choose a file + optional expiration (10 minutes to 90 days).
- Optionally add an Argon2id passphrase.
- Browser encrypts → share the link (key stays in the fragment).
2. Request Files (Drop Portal)
- Create a request link.
- Uploaders encrypt files with your X25519 public key in their own browsers.
- Only you can decrypt the submissions.
- Useful when you need people to send you sensitive documents without sharing a password.
Crypto Choices
- AES-256-GCM — chunked encryption (16 MiB)
- Argon2id — passphrase wrapping
- X25519 — sealing for file requests
- Keys isolated in the URL fragment
The crypto library is open source if you want to review it:
https://github.com/SendShield-Files/crypto
Current Limitations
This is still early. Some things I’m aware of:
- Not self-hostable yet
- Large files depend on browser memory
- No team/workspace features
- UX can still be improved for non-technical users
Looking for Feedback
I launched it on Product Hunt today and would love honest feedback from developers, especially on:
- Any red flags in the crypto approach?
- Is the UX too friction-heavy for normal users?
- What would actually make you use this over existing tools?
Links:
- Product Hunt: https://producthunt.com/products/sendshield-files
- Site: https://sendshieldfiles.com
- Security details: https://sendshieldfiles.com/security
Thanks for reading. Brutal feedback is welcome.
Top comments (1)
tr.ee/dev-to