Encryption and security
DioTrans encrypts files in your browser and sends only encrypted data to storage. This page explains how that works and how to use it safely.
1How encryption works
- Files are encrypted in your browser with AES-256-GCM before upload.
- An encryption key is generated in the browser for each transfer. Each file gets a random IV (initialization vector).
- Uploads use a presigned PUT URL, so the browser sends data directly to storage. DioTrans servers never receive plaintext files.
- Downloads use a presigned GET URL to fetch encrypted data, which the browser decrypts locally.
2standard mode and passphrase mode
| Item | standard mode (default) | passphrase mode (optional) |
|---|---|---|
| Encryption | AES-256-GCM. The key is generated in the browser. | Same, and the key is wrapped with a passphrase. |
| Passphrase | Not required. | Entered by the recipient (shared by the sender through another channel). |
| Server-side decryption | Because an encrypted key is stored, the operator could theoretically decrypt the files. | The passphrase is never sent to the server, so nobody — including the operator — can decrypt the files. |
| If the passphrase is lost | — | There is no way to restore the files. |
For highly confidential files, consider passphrase mode. Share the passphrase by phone or in person, through a channel other than email.
3Recipient verification
- Notification emails do not contain a direct download URL. Recipients verify their email address from the link and enter a 6-digit code.
- Verification codes expire and have a limited number of attempts. See Receiving files for details.
- Forwarding the link to someone else does not let them download without the code.
4Other measures
- Traffic is encrypted with HTTPS, and cookies are issued with secure settings.
- CSRF protection, rate limiting, security headers, and similar measures are in place.
- Files are deleted automatically from storage after their expiry.
For more about security, see Security on the public site (Japanese).
5Reporting vulnerabilities
If you find a vulnerability or security issue, contact [email protected]. Reproduction steps and the time you observed the issue help us investigate.
