SECURITY, EXPLAINED

DioTrans cannot read
your files

This page explains why administrators cannot view file contents in normal operations, and how to choose the encryption mode that fits your use.

Files are encrypted with AES-256-GCM in the browser and only encrypted data is sent to S3/R2
Files are encrypted in the browser, and only encrypted data is sent to storage.

No plaintext on the transfer path

01 / CLIENT

Encrypted in the browser

Files are encrypted with AES-256-GCM using the browser’s Web Crypto API before upload.

02 / STORAGE

Stored encrypted

Encrypted data is stored in the S3/R2 you chose, or in DioTrans storage.

03 / RECIPIENT

Decrypted in the recipient’s browser

After email verification, the encrypted data is decrypted locally in the recipient’s browser.

The transfer detail screen showing the end-to-end encryption notice
Transfers show their encryption state. Files on the server stay encrypted at all times.

Choose between two modes

Selecting “Protect with a passphrase” on the transfer screen enables true end-to-end encryption (passphrase mode).

The transfer screen with the passphrase protection checkbox under Security Options
“Security Options” on the transfer screen. When checked, recipients must enter the passphrase.
STANDARD

The practical default

The encryption key is protected and stored by the service. A good fit for organizational use, though the operator could theoretically decrypt the key.

  • Key management is handled by the service
  • No passphrase sharing with recipients
  • Use with an understanding of the operator’s theoretical access
PASSPHRASE

Stronger secrecy

The passphrase is never sent to the server; the encryption key is wrapped with a key derived from the passphrase.

  • Nobody on the server side, including the operator, can decrypt
  • Share the passphrase through another secure channel
  • If lost, the files cannot be recovered

See “Encryption and security” in the manual for details.

Verify recipients before handing over files

Notification emails never contain a download URL. Recipients confirm their email address and enter a 6-digit verification code before they can download. Codes expire and have a limited number of attempts.

Email verification screen asking for the recipient address
Recipients enter the address that received the notification.
Email verification screen with a 6-digit code field
They enter the 6-digit code from the email. Forwarding the link does not let others download without the code.
!

What “administrators cannot view” means depends on the encryption mode. Check the difference between standard and passphrase modes before putting the service into production.

!

What the operator cannot view: the contents of transferred files (they are encrypted) and passphrases set by users in passphrase mode. Personal information in records is anonymized when an account is deleted, and records are removed within a set period after the contract ends. See the Privacy Policy and Data processing and storage locations (Japanese) for storage regions and retention.

Records administrators can view

DioTrans keeps operation records to maintain security and prevent abuse. The operator and organization administrators can view these records for secure operations and investigations. File contents are encrypted and cannot be viewed from the records.

The transfer log with date, action, subject, actor, and recipient columns
Transfer logs. Creation, notification, verification, download, and other events are listed.
TRANSFER LOGS

Transfer logs

History of transfer creation, uploads, notifications, recipient verification, downloads, and expiry. Includes subjects, actor email addresses, IP addresses, and user agents.

ACCESS LOGS

Download access logs

Verification of download token access, number of files fetched, and verdicts on signs of abuse such as bulk access from a single IP. Used to detect and block unauthorized access.

LOGIN EVENTS

Login history

Login time, authentication method, and IP address. Users are also notified on each log-in, so unusual log-ins can be noticed quickly.

ABUSE REPORTS

Abuse reports

The contents and status of reports submitted through the abuse reporting channel (Japanese). Kept for investigation.

After cancellation, your information is not used

If you cancel a paid plan, you can keep using the service until the end of the current billing period. After account deletion is processed, the deleted information is no longer used to provide the service. Only the records needed for secure organization management and legal compliance are kept, with personal information anonymized.

Information Treatment after account deletion
Account information Name, email address, credentials, and other account information are deleted, and the Diotrans account itself is removed.
Files you sent and transfer data Encrypted files, transfer metadata, and recipient information are deleted. If your storage is your own S3/R2, data DioTrans created for the transfer is deleted.
Personal contacts and consent records Your personal address book and consent records managed by DioTrans are deleted.
Login history Login history tied to your account is deleted.
Transfer and download audit logs Kept for secure organization management, security investigation, and abuse response. Email addresses, IP addresses, and user agents are anonymized and deleted within two years after the contract ends.
Abuse reports May be kept for investigation and legal response. Reporter information is anonymized and deleted within two years after the contract ends.
D1 backups Data from before deletion may remain in Cloudflare D1 Time Travel restore points for up to 30 days.
Information belonging to an organization If other members remain in the organization, organization settings and other members’ data are not deleted. When the whole organization ends, organization logs are anonymized and deleted after the retention period.

See the Privacy Policy (Japanese) for details on what is deleted, retention periods, backups, and third-party services.