Security

Private by design

Your files travel sealed, take the shortest possible path, and leave nothing behind. Not because of a setting you found — because of how BIShare is built.

Keys never leave your devices

How an end-to-end encrypted transfer works

Keys never leave your devices
X25519AES-256-GCM

Device A encrypts the file, the encrypted data travels across the network, and only Device B can decrypt it. The encryption keys never leave either device.

Device A

Sender — encrypts

Key stays here

Device B

Receiver — decrypts

Key stays here
What the network sees
01

Sealed on your device

The file is encrypted before a single byte leaves.

02

Ciphertext in transit

The network only ever carries scrambled noise.

03

Unlocked on arrival

Only the receiving device holds the matching key.

End-to-end encryption

Locked before it leaves. Unlocked on arrival.

Only the two devices in a transfer can read the files moving between them. Here is what happens under the hood — in plain words, with the technology named once.

X25519

A secret agreed in silence

Before anything moves, both devices agree on a shared secret without ever sending it across the network. Someone recording every packet of that handshake still ends up with nothing usable.

PER-FILE KEYS

Every file gets its own key

Each transfer is sealed with a fresh key of its own. Even in the worst imaginable case, one key could only ever open one file — never your history, never the next transfer.

AES-256-GCM

Sealed and tamper-evident

Files are scrambled with the same cipher class that protects banking and government traffic — with a built-in seal. If a single byte is altered in transit, the transfer is rejected.

Local-first

Your network is the whole journey.

When two devices share the same Wi-Fi or hotspot, files travel straight between them. There is no upload step, no middleman, and no copy anywhere else — because there is no server in the path at all.

  • Nearby transfers never touch a server — not ours, not anyone's
  • Works completely offline: Wi-Fi or a phone hotspot is enough
  • Nothing stored in the cloud means nothing to leak from it
  • Files exist in exactly two places: the sender and the receiver
LANDIRECT
Same network

A file travels directly from your phone to your laptop over your own network.

No server is contacted. The transfer starts and ends on your own network.

Remote shares

Protected in transit. Gone in 24 hours.

When the other person is on a different network, your file takes a short, guarded detour through secure cloud storage. It is encrypted on the way there, encrypted while it waits, and deleted on schedule — every time.

  • Encrypted in transit and encrypted at rest
  • Deleted automatically after 24 hours — no action needed
  • One-time links self-destruct after the first download
  • We never scan, index, or look at what you share
REMOTEENCRYPTED
Link active
17h

holiday-album.zip

0.9 GB · X4K-9PM

Time remaining

Encrypted in transit

Sealed on the way up and on the way down.

Encrypted at rest

Stored scrambled while it waits to be picked up.

Deleted after 24 hours

Automatically, whether or not it was downloaded.

Just as important

What we don't do

Privacy is mostly about restraint. These aren't settings you have to find — they're how BIShare works, by default and always.

Never

No tracking

No behavioral profiles, no advertising identifiers, no following you around the internet.

Never

No ads

BIShare is a tool, not an ad network. Your attention is not the product.

Never

No selling data

We don't sell, rent, or trade your data. There is no data broker on the other end.

Never

No file scanning

We never open, scan, or analyze what you transfer. Your files are your business.

Responsible disclosure

Found a weakness? Tell us first.

Security claims are only as good as the scrutiny they survive. If you discover a vulnerability in BIShare, email us with the steps to reproduce it. We read every report, and good-faith research is always welcome.