CONTROLLED FILE TRANSFER

Deliver files from the storage you choose.

DioTrans encrypts files in the browser and delivers them from your AWS S3, Cloudflare R2, or DioTrans R2 storage. Set recipients, expiry, and authentication, and keep a record of every delivery.

Encrypted in the browser Choose your storage Expiring links

Free trial available (up to 28 days)

YOUR CONTROL LAYER
Files are encrypted in the browser and delivered to the storage you choose
Encrypted
before upload

01 Choose your storage

02 Encrypt in the browser

03 Files expire automatically

SCREEN TOUR

See the actual
screens

Step-by-step instructions are in the manual.

The new transfer screen with recipients, message, expiry, and files
Send. Set recipients, subject, expiry, and files on one screen. Files are encrypted here in your browser.
The pending transfers list with approve and reject buttons
Approve. In organizations that require approval, an administrator reviews transfers before recipients are notified.
The download screen where recipients decrypt and save files
Receive. Recipients verify by email, then decrypt in the browser. No account is required.

FEATURES

Everything needed
to deliver safely

Step-by-step instructions are in the manual.

STORAGE

Connect your storage

Connect AWS S3 or Cloudflare R2, verify with a connection test, and keep credentials encrypted at rest.

ACCESS

Verify recipients

A notification link plus a 6-digit email code ensures only the intended recipient can download.

EXPIRATION

Manage expiry and history

Files are deleted from storage after expiry. See who downloaded what in the transfer detail and logs.

TEAM

Work as a team

There is no user limit. Separate administrator and member roles, and invite people from user management.

ADDRESS BOOK

Use contacts

Save frequent recipients as personal or organization-shared contacts, with CSV import and export.

SSO / SMTP

Fit your organization

Configure external OIDC (SSO) and your organization SMTP, or use the built-in defaults.

HOW IT WORKS

From sender to recipient
in five steps

Every step is designed so plaintext never travels through DioTrans servers. Detailed steps are in the manual.

01

Set files and recipients

Choose files, recipients, a subject, a message, and a download expiry from 1 to 30 days.

The new transfer screen
In organizations that require approval, an administrator approves the transfer before it is sent.
02

Encrypt in the browser

Files are encrypted with AES-256-GCM in the sender’s browser. Only encrypted data is stored in your S3/R2 or DioTrans R2.

Files are encrypted in the browser and only encrypted data goes to storage
DioTrans servers never receive plaintext files.
03

Recipients open the notification

Recipients receive a notification email containing a verification link, never a direct download URL.

Email verification screen asking for the recipient address
Recipients enter their address to request a verification code.
04

Verify with a 6-digit code

Recipients enter the code sent to their inbox. The code expires quickly and has a limited number of attempts.

Email verification screen with a 6-digit code field
Verification codes are sent to the recipient’s email address.
05

Decrypt and save

The recipient’s browser fetches the encrypted data and decrypts it locally. Passphrase mode requires the passphrase shared through another channel.

The download screen
Google Chrome or Microsoft Edge is recommended for large files.

FOR TEAMS

Set up for
your organization

Creating an organization lets you invite members and share the same transfer features. Storage, identity, and email can be connected to fit your environment.

A diagram showing DioTrans used from the browser with your AWS S3 or Cloudflare R2, OIDC, and SMTP connected
MEMBERS

Members and roles

There is no user limit. Separate administrators and members, and invite people from user management.

STORAGE

Choose your storage

Use your own AWS S3 / Cloudflare R2, or let DioTrans R2 handle storage for you.

IDENTITY / MAIL

Identity and email

Connect your organization OIDC (SSO) and SMTP, or use the built-in defaults.

SECURITY, EXPLAINED

DioTrans cannot read
your files

DioTrans keeps as little information as possible, and lets you choose between operational convenience and stronger secrecy.

Administrators cannot view file contents in normal operations

Files are encrypted in the browser and are never sent to DioTrans servers in plaintext. Only encrypted data is stored in your chosen S3/R2 or DioTrans R2.

The Japan version is available today. Regional legal documents and EU service information will be added as each region becomes available. See Security for encryption details.

STANDARDEasier operations

Protected key management

The encryption key is protected and stored by the service. A practical default for organizations, but the operator could theoretically decrypt files.

Protected key→Recipient
PASSPHRASEStronger secrecy

Share a passphrase separately

The passphrase is never sent to the server, so nobody on the server side — including the operator — can decrypt. If lost, the files cannot be recovered.

Wrapped key→Recipient

START SMALL

Try it with a
free trial

Seven days free, extended by 21 days when you connect your own S3/R2 — up to 28 days. Files are limited to 3 MB during the trial.