Security
How we protect your files and data
End-to-End Encryption
When you password-protect a file, it's encrypted with AES-256-GCM before it leaves your browser. The encryption key is derived from your password, and we never have access to your unencrypted files.
- AES-256-GCM: Military-grade encryption algorithm
- Client-side encryption: Files are encrypted before upload
- Password-derived keys: Your password is never sent to our servers
- Salt and nonce: Unique values for each file prevent pattern analysis
Secure Storage
All files are stored with multiple layers of protection to ensure they remain secure and private.
- Encrypted at rest: Files are stored in encrypted form
- Access controls: Strict permissions prevent unauthorized access
- Secure deletion: Files are permanently erased when expired
- No file scanning: We never analyze or scan file contents
Transport Security
All communications between your browser and our servers are protected with modern security protocols.
- TLS 1.3: Latest encryption for data in transit
- HTTPS only: All connections require secure protocols
- Certificate pinning: Prevents man-in-the-middle attacks
- Secure headers: Additional HTTP security headers
Automatic Expiration
Files are automatically deleted based on your chosen expiration settings, ensuring no data persists longer than necessary.
- Time-based expiration: Files deleted after specified days
- Download-based expiration: Files deleted after download limit reached
- Secure deletion: Files overwritten before deletion
- No backups: Expired files are not backed up
Infrastructure Security
Our infrastructure is designed with security as a primary consideration.
- Regular updates: All software is kept up-to-date with security patches
- Network isolation: Services run in isolated environments
- DDoS protection: Protection against distributed denial-of-service attacks
- Intrusion detection: Monitoring for suspicious activity
Privacy Protection
We minimize data collection and protect your privacy at every step.
- Minimal logging: We log only what's necessary for operation
- No tracking: We don't use tracking cookies or analytics
- IP anonymization: IP addresses are anonymized in logs
- Data minimization: We collect only essential information
Security Best Practices
Tips for keeping your files secure when using GoFileBeam.
- Use strong passwords: For password-protected files, use unique, complex passwords
- Share links securely: Only share download links with intended recipients
- Set appropriate expiration: Choose expiration settings that match your needs
- Monitor downloads: Check download counts if you suspect unauthorized access
- Use HTTPS: Always access the service via HTTPS
Reporting Security Issues
We take security seriously and welcome responsible disclosure of security vulnerabilities.
If you discover a security vulnerability in GoFileBeam, please report it to us at security@gofilebeam.com. We will respond promptly and work with you to resolve the issue.
Please include detailed information about the vulnerability and steps to reproduce it. We appreciate your help in keeping our service secure for all users.