SELINA.ai
Sign in

Secure File Sharing for Business: A Buyer's Guide Before Your Next Audit

If you're evaluating secure file sharing for business ahead of a compliance review or client audit, the worst thing you can do is pick a vendor based on a marketing page that says "bank-level encryption." Every serious vendor says that. It tells you almost nothing. What matters is key custody architecture, governance depth, audit-trail fidelity, and whether the platform actually reduces your exploitable surface area or just adds another one. This guide is built to help you ask the right questions, ignore the noise, and walk into that audit with a defensible stack.

Key Takeaways

Why Is "Encryption" Not Enough to Evaluate a File-Sharing Vendor?

Because every vendor worth considering already uses AES-256 for data at rest and TLS 1.2+ for data in transit. Encryption strength alone is not a buying criterion, since these ciphers are table stakes. The real question is who holds the keys, and what that means for your risk posture when an auditor, a subpoena, or a breach notification shows up.

There are three architectures you'll encounter, and vendors sometimes blur the lines between them:

  1. Provider-managed encryption. The vendor encrypts your data and holds the keys. They can decrypt it without your involvement. Most legacy file-sharing tools work this way. It is the simplest to operate and the hardest to defend in a compliance review where data sovereignty matters.
  2. Customer-managed keys (CMK or BYOK). The vendor still handles encryption and decryption operations, but you control the key through a KMS. If you revoke the key, the vendor loses access. This is better, but the vendor's infrastructure still sees plaintext during processing.
  3. Zero-knowledge encryption. The vendor structurally cannot decrypt your data. Encryption and decryption happen on the client side. The provider never sees plaintext and never holds the key. Sophisticated buyers now need to distinguish true zero-knowledge platforms from customer-managed-key platforms, because both are often marketed under the same "end-to-end encryption" label.

The sorting question is simple: ask the vendor, "Can you technically decrypt my data without my involvement?" A "yes" means provider-managed. A "we can if you give us your KMS key" means customer-managed. A structural "no" means zero-knowledge. Write down their answer. You will want it on file.

What Should I Actually Look for Before a Compliance Review?

Start with what your auditor will ask for, then work backward to tool requirements. The specifics vary by framework (SOC 2, HIPAA, GDPR, ISO 27001), but certain things come up every time: access controls, audit logging, data residency, vendor risk documentation, and evidence that your tools enforce your policies rather than merely suggesting them.

Access Controls and Least Privilege

Your file-sharing tool should support granular permissions (read, write, download, reshare) at the folder and file level, not just at the account level. If you are sharing a due-diligence folder with outside counsel, the analyst who uploaded the documents and the partner reviewing them should not have the same permission set. Role-based access control (RBAC) is the minimum. Attribute-based access control (ABAC) is better for complex sharing patterns.

Audit Logging That Actually Holds Up

The log needs to capture who accessed what, when, from where, and what they did with it. "User logged in" is not useful. "User downloaded file X from folder Y at timestamp Z from IP address W" is useful. Look for tamper-evident or append-only logs. If the vendor lets an admin delete log entries, your auditor will notice.

Data Residency and Processing Location

If you share files with EU counterparts or clients, you need to know where data is stored and where it is processed. European data protection authorities assessed nearly €1.2 billion in GDPR fines in 2025, and personal data breach reports to supervisory authorities rose roughly 22% year over year. The enforcement environment is not theoretical. Your file-sharing vendor should be able to tell you, in writing, which regions host your data and whether any processing happens outside those regions.

Vendor Risk Documentation

You need a signed Data Processing Agreement (DPA) if GDPR applies, and a signed Business Associate Agreement (BAA) if HIPAA applies. HIPAA requires that any system used to share protected health information enforce access controls, audit logging, integrity controls, transmission security, and a signed BAA with the vendor. Free consumer tools do not meet these requirements out of the box. If you are using a consumer-tier plan for regulated data, stop.

Why Do MFT Breaches Keep Happening, and What Does That Mean for My Vendor Choice?

Managed file transfer platforms have been breached three times in two years through zero-day vulnerabilities, each time by sophisticated attackers who moved faster than patches could be deployed. In mid-2023, Progress MOVEit Transfer was hit by a critical SQL injection zero-day exploited at scale by the Clop ransomware group, resulting in data theft affecting thousands of organizations worldwide. Earlier that year, Fortra's GoAnywhere MFT was exploited through a separate zero-day, again by Clop. Then in late 2024, attackers exploited a zero-day arbitrary file-write vulnerability in Cleo's LexiCom, VLTrader, and Harmony products, following the same playbook.

The pattern is clear: MFT platforms are high-value targets because they sit on the network perimeter, hold credentials for many external parties, and process large volumes of sensitive data through a single chokepoint. The lesson for a small or mid-size company is not "pick a different MFT vendor." The lesson is: reduce the number of internet-facing, credential-holding file-sharing surfaces you operate. Every additional tool with its own authentication layer, its own patch cycle, and its own attack surface is another thing an attacker can hit and an auditor can question.

When we built our own internal file-transfer tooling, the constraint we started from was not "make it feature-rich." It was "make it so the server never holds plaintext." SelinaSEND, our file-transfer feature, uses zero-knowledge, end-to-end encryption. The server facilitates the transfer. It cannot read the payload. That architectural decision eliminates an entire class of breach outcomes: even if an attacker compromises the transfer infrastructure, the files are ciphertext without the recipient's key.

How Does Shadow AI Change the File-Sharing Risk Picture?

Shadow AI is the 2026 version of the shadow IT problem you thought you solved in 2018, except worse, because once sensitive data is pasted into an AI tool it often cannot be retrieved or deleted. Shadow AI introduces security and compliance risk when employees use unapproved AI tools that move sensitive data outside organizational control, creating exposure across data leakage, audit gaps, and model-level attacks.

The numbers are stark. Organizations where AI significantly expanded the number of identities accessing data reported a 43% breach rate over the prior year, compared with 11% for organizations without that expansion. Meanwhile, only 20% of organizations fully monitor or govern employee use of shadow AI, and just 11% rate themselves fully ready for AI governance with enforced policies and continuous monitoring.

This is directly relevant to file sharing. Your employee downloads a contract from your secure file-sharing platform, copies a clause, pastes it into an unapproved AI tool to "summarize the key terms," and now that clause, possibly containing PII, deal terms, or privileged content, lives in a system you do not control, cannot audit, and may not even know exists.

What Are Auditors Asking About AI Now?

Compliance auditors in 2026 are requesting full AI tool inventories, including embedded AI features in sanctioned SaaS. Auditors now ask which AI tools process regulated data and where the corresponding DPAs or sub-processor agreements are. An absent DPA is flagged as an immediate GDPR finding and SOC 2 vendor-risk gap. If your file-sharing platform recently added an "AI summary" or "AI search" feature, and you do not have a DPA that covers the AI sub-processor, that is a finding waiting to happen.

The practical takeaway: any AI feature that touches your business documents needs to pass the same "can you technically access my data" test you apply to zero-knowledge encryption. Ask where the data goes during inference. Ask whether it is used for model training. Ask whether it is retained after the request completes. If the vendor cannot answer, the feature is a liability, not a convenience.

This is something we think about constantly with Selina. Selina is a privacy-focused AI assistant that remembers you across conversations, running on a stack of frontier models routed per task. Files and transfers through SelinaSEND are zero-knowledge encrypted. Memory is encrypted at rest but is not end-to-end encrypted, because a slice of each request reaches a frontier provider at inference. Non-content operational metadata is kept for a short retention window. We state these limits plainly because an audit-ready tool is one where the architecture is documented and defensible, not one where the marketing copy requires a decoder ring.

How Do I Evaluate Third-Party Risk from File-Sharing Tools?

Third-party and vendor-related exposure is growing faster than any other breach category. Third-party involvement in breaches doubled in a year to 30%, with supply-chain attacks costing an average of $4.91 million. An organization can harden its own systems and still get breached through an uncontrolled vendor.

Every file-sharing tool you use is a third party. Every external recipient you share with through that tool extends your trust boundary. The evaluation framework is straightforward:

What Does the Ransomware Shift Mean for File-Sharing Security?

Ransomware tactics have shifted from encryption-based extortion toward pure data theft plus leak threats. Ransomware appeared in 44% of breaches in 2025, up from 32% the prior year, the biggest single-year jump in Verizon's DBIR history. Roughly half of attacks now skip encryption entirely, simply stealing data and threatening to publish it. Backups can restore a lockout. Backups cannot un-leak a file.

This changes what "secure file sharing" needs to defend against. The traditional threat model was: attacker encrypts your files, you pay or restore from backup. The current threat model is: attacker exfiltrates your files, and now they have a copy of everything you shared through a tool that was "encrypted in transit" but stored plaintext at rest, or encrypted at rest with keys the provider (or the attacker, via the provider's compromised infrastructure) could access.

Zero-knowledge architecture is the structural mitigation here. If the server never holds plaintext, a server-side compromise yields ciphertext. The attacker gets encrypted blobs they cannot decrypt. This is not a theoretical distinction. It is the difference between a breach notification that says "encrypted data was accessed" and one that says "client contracts, financial statements, and employee records were exfiltrated in readable form."

How Do I Handle the Human-Error Problem?

95% of all cybersecurity data breaches are attributed to human error. 48% of companies reported an increase in insider attacks in 2026, and the average annual cost of insider incidents has exceeded $17 billion across industries. You are not going to train your way out of this. You need controls that make the wrong thing hard to do.

Specific controls that matter for file sharing:

What Questions Should I Bring to the Vendor Demo?

Here is a concrete list, ordered by how quickly the answers will disqualify a vendor:

  1. "Can your organization technically decrypt my data without my involvement?" (Sorts them into the three encryption categories above.)
  2. "Where is my data stored, and does any processing happen outside that region?"
  3. "Do you have a signed BAA/DPA available, and which sub-processors are covered?"
  4. "What is your contractual breach notification timeline?"
  5. "Does your platform have any AI features, and if so, where does inference happen, is data retained after the request, and is it used for training?"
  6. "Can I set per-file or per-folder access controls, link expiration, and download limits?"
  7. "Are audit logs tamper-evident, and can I export them for my own SIEM?"
  8. "What was your most recent security incident, and how did you respond?"

The last question is the one most vendors will try to dodge. The ones who answer it plainly are the ones worth talking to. A vendor with a clean CVE history and no incident response story is either very lucky or not being transparent.

How Should I Think About Consolidation vs. Best-of-Breed?

The MFT breach pattern (MOVEit, GoAnywhere, Cleo) points toward a consolidation argument: fewer internet-facing, credential-holding file-sharing surfaces means fewer things to patch, monitor, and explain to an auditor. If you are running Dropbox for internal collaboration, a separate MFT tool for client deliverables, WeTransfer for ad-hoc large files, and email attachments for everything else, you have four attack surfaces, four sets of access controls, four audit logs (or fewer, since some of those tools do not produce real audit logs), and four vendors to vet.

Consolidation does not mean picking one tool and forcing every use case into it. It means reducing to the minimum number of tools that cover your actual sharing patterns, with real overlap eliminated. Map your sharing patterns first. Internal collaboration, client delivery, large-file transfer, regulated-data exchange. Then see which tools cover which patterns with the controls you need. The goal is to walk into an audit with a short list of tools, each with a clear purpose, documented controls, and a signed agreement.

A Note on Debugging Encrypted Systems

One thing you lose with zero-knowledge or end-to-end encrypted file sharing: the ability to debug through the database. When we built encrypted-at-rest systems for Selina, we learned early that you cannot just query a column to figure out what went wrong. You debug through the application layer, because that is the only place where decrypted data exists. This adds development time. It makes certain support tickets harder to resolve. It is worth it, because the alternative is a system where a database compromise yields plaintext, and no architectural convenience justifies that trade.

If a vendor tells you their platform is zero-knowledge and also tells you their support team can "look into" the contents of your files to help resolve an issue, one of those statements is false.

What Regulatory Deadlines Should I Be Aware of in 2026?

Two are worth noting if your file-sharing tools touch AI-processed business documents. Colorado's AI Act becomes enforceable June 30, 2026, imposing obligations on deployers of "high-risk" AI systems, including impact assessments and disclosure requirements. California's AB 2013 already requires training-data disclosure from AI developers. If your file-sharing vendor recently added AI features, these laws may apply to your use of those features, and your auditor may ask about them.

The GDPR enforcement environment continues to tighten, with roughly 443 data breach reports filed with European supervisory authorities per day on average. If you share files with EU clients or process EU personal data, your file-sharing tool's data residency and sub-processor documentation is not optional. It is a finding waiting to be written.

The Checklist, Compressed

Before your next compliance review or client audit, confirm the following for every file-sharing tool in your stack:

If any of those checks fail, you have a gap. Better to find it now than to have an auditor find it for you.

If you want to see how we handle file transfers and AI memory in a way that is built for exactly this kind of scrutiny: start a free 7-day trial, no card required.

Frequently Asked Questions

Why isn't "bank-level encryption" a useful differentiator when choosing a file-sharing vendor?

Because every serious vendor already uses AES-256 at rest and TLS in transit, so encryption strength alone tells you nothing. What actually matters is who holds the keys, governance depth, and audit-trail fidelity.

What's the difference between provider-managed, customer-managed key, and zero-knowledge encryption?

Provider-managed means the vendor holds the keys and can decrypt your data without you; customer-managed keys (CMK/BYOK) let you control the key via a KMS, but the vendor's infrastructure still sees plaintext during processing; zero-knowledge means encryption/decryption happen client-side and the vendor structurally cannot decrypt your data. The sorting question to ask any vendor is: "Can you technically decrypt my data without my involvement?"

What should I look for in access controls and audit logs before a compliance review?

You need granular, folder- and file-level permissions (RBAC at minimum, ABAC for complex sharing), not just account-level access. Audit logs must be detailed (who, what, when, where, from what IP) and tamper-evident or append-only, since logs that admins can edit or delete will raise auditor concerns.

Why do MFT platforms keep getting breached, and what should smaller businesses do about it?

MFT platforms like MOVEit, GoAnywhere, and Cleo have been hit repeatedly by zero-day exploits because they sit on the network perimeter and hold credentials for many external parties, making them high-value targets. The lesson isn't to switch MFT vendors but to reduce the number of internet-facing, credential-holding file-sharing surfaces you operate overall.

How does "shadow AI" create new risks even if my file-sharing platform is secure?

Shadow AI risk arises when employees paste sensitive data from a secure platform into unapproved AI tools, moving that data into a system you can't audit, control, or delete from. Organizations with AI-expanded data access reported a 43% breach rate versus 11% for those without, yet only 20% fully monitor or govern shadow AI use.

Sources & References

Michael C.

Michael C.

Founder & Principal Engineer, Selina Labs

Michael builds Selina, a privacy-first AI that remembers you across conversations. He ships security-sensitive AI in production — real attacks, real fixes, measured in minutes and dollars — and writes about privacy, security, and LLMs from that seat. Top Rated Plus and expert-verified on Upwork.

Learn more about Selina.ai