Enterprise 5 min readUpdated 2 October 2026

End-to-end encryption

End-to-end encryption keeps the contents of a transfer readable to you and your recipient, and to nobody else. WeTransfer Enterprise supports it, and workspace admins decide who can use it.

On a standard transfer, files are encrypted in transit and at rest. With end-to-end encryption, files are encrypted in the sender's browser before they are uploaded, and only the sender and the recipient hold the key. WeTransfer stores and delivers only encrypted data, so it can't read or preview the files, and it can't scan them for malware. The recipient needs the link and a separate encryption key to open them.

We can enable end-to-end encryption upon request on selected customers. Contact your account manager to check whether it's available for your workspace.

What end-to-end encryption protects

End-to-end encryption protects file contents. Only the sender and the recipient hold the key that unlocks them, and WeTransfer never receives that key.

It isn't the same as a transfer password. A password controls who can open the link. End-to-end encryption protects the file contents themselves, and only the sender and the recipient hold the key.

Who can use it

  • End-to-end encryption is an Enterprise add-on, enabled on request for selected customers.
  • Workspace admins choose which members can send end-to-end encrypted transfers, in Workspace Settings → Security → Encrypted transfers.
  • Only link transfers can be encrypted. Email transfers and file requests can't.
  • Encrypted transfers can still be protected with a password and access control.
WeTransfer workspace settings showing the Encrypted transfers permission and a Manage members button.
Admins choose which members can send encrypted transfers.

How it works

  1. The sender turns on Encrypted in the transfer options.
  2. The browser generates a random encryption key and encrypts the files with AES-256-GCM before anything is uploaded.
  3. Only the encrypted files leave the device. WeTransfer stores them without ever seeing the key.
  4. The sender shares the link and the encryption key through two separate channels.
  5. The recipient opens the link, enters the key, and their browser decrypts each file as it downloads.

Sending an encrypted transfer

  1. Add files and open the transfer options.
  2. Under Extra settings, tick Encrypted.
Transfer options panel with the Encrypted setting switched on.
Turn on Encrypted in the transfer options.
  1. Review the notice: files can't be previewed, and the recipient needs both the link and the key.
  2. Send the transfer.
  3. On the confirmation screen, copy the encryption key and the link. You must copy both before you finish.
  4. Share the link and the key separately, for example the link by email and the key through your password manager or a secure message.

Keep the key safe. It can't be recovered or regenerated.

Sender confirmation screen showing the encryption key and the link to share separately.
Copy the link and the encryption key, then share them separately.

Receiving an encrypted transfer

  1. Open the link.
  2. Paste the encryption key the sender shared with you and select Decrypt.
Recipient screen asking for the encryption key, with a Decrypt button.
The recipient enters the key to decrypt the files in their browser.
  1. Your browser decrypts the files and downloads them one at a time.
  2. Open the files as usual.

If the key is wrong or the transfer didn't arrive intact, you'll be asked for the key again. If your browser can't decrypt the files, open the link in an up-to-date desktop browser.

Standard transfer

End-to-end encrypted transfer

Encryption keysManaged by WeTransferHeld only by the sender and the recipient
Preview in the browserYesNo
Malware scanYesNo. The files are unreadable to our malware scanner.
Transfer typeLink or emailLink only
Editing, forwarding, and adding recipientsYesNo
DownloadsZIP or single filesOne file at a time, decrypted in the browser
Supported clientsAll, including the mobile appsUp-to-date desktop browsers
Standard transfers compared with end-to-end encrypted transfers

Keeping your encryption key safe

  • WeTransfer never sees the key, so nobody can recover it for you.
  • Share the link and the key through different channels, never in the same message.
  • Store the key in your password manager before you close the confirmation screen.
  • If you lose the key, the files are permanently inaccessible, even to WeTransfer.

Frequently asked questions

Can workspace admins read encrypted transfers?

No. Admins can see that a transfer exists and its details, but not the file contents.

Can I send an end-to-end encrypted transfer by email?

No. Encrypted transfers are link transfers only. You can still share the link by email, but the key must be shared separately.

Can recipients preview encrypted files?

No. Files are decrypted in the browser at download time, so previews and thumbnails aren't available. Recipients download one file at a time.

What happens if I lose the encryption key?

The files become permanently inaccessible. WeTransfer never sees the key, so it can't be recovered or regenerated.

Is end-to-end encryption the same as a password?

No. A password controls who can open the link. End-to-end encryption protects the file contents themselves, and only the sender and the recipient hold the key.

Was this helpful?

Questions?

Contact your account manager for any questions. If you're not yet an Enterprise customer, click the button to submit an enquiry.