Security and privacy

Clear controls. Finite data. No vague security theatre.

FileFast verifies senders, keeps transfer pages out of search, limits recipient access, and removes detailed analytics when they are no longer useful.

Access

Public, tracked and restricted transfers remain separate. Passwords are adaptively hashed and one-time codes expire.

Private delivery

Recipient, request and branded portal pages are noindex. Private object-storage files are served only after FileFast authorizes the request.

Account security

Authenticator MFA, one-use recovery codes and active-session revocation protect returning accounts.

Retention

We keep detail only while it has a job.

Network identifiers · 30 days
IP addresses, user agents, referrers and visitor session identifiers used for abuse checks and de-duplication are removed from transfer analytics after 30 days.
Pseudonymous actor hashes · 90 days
A one-way keyed hash helps distinguish repeated recipient activity without storing an email or IP address inside the event. The hash is cleared after 90 days.
Detailed analytics · up to 730 days
Detailed view, download and transfer events expire after two years. Aggregate file counters may remain, and billing, fraud or legal records follow their separate required retention.
Files and transfers · plan rules
Files expire according to the selected transfer setting and plan. A private recovery window may delay physical deletion, but it never republishes an expired or removed transfer.

Infrastructure claims stay specific

Production traffic uses HTTPS. Custom domains are activated only after certificate status is confirmed. Object storage is configured private; FileFast does not publish direct origin URLs for protected files.

Report something unsafe

Known-threat scanning and blocked-file rules reduce risk, but no scanner catches everything. Report a suspicious transfer so it can be reviewed and disabled.

Report abuse