Data Flow Diagram

Version 1.0 — July 2026. The heavy line is the file: it never touches SecureSend.

Sender's browser AES-256-GCM encryption happens HERE, client-side Recipient's browser decryption happens HERE no account required ENCRYPTED FILE — any channel the sender already uses never sent to SecureSend SecureSend (Cloudflare Workers + Durable Objects) holds: wrapped one-time key · token/PIN hashes · metadata atomic release-and-destroy on correct PIN · 5 wrong PINs = permanent lockout Business: per-org append-only audit trail (metadata only, 24 months) never holds: file bytes · plaintext PINs · keys after release admin access: Cloudflare Zero Trust · dashboards: Google Sign-In seal: metadata in, one-time key out (once) open: link token + PIN in, key out exactly once, then burned Resend / Twilio delivery emails / SMS: link, PIN, label, branding — never file content Stripe payments, VAT invoices; card data never touches SecureSend Google Sign-In optional dashboard auth: verified email only

Orange: one-time key escrow (a few hundred bytes of metadata, one key, released once). Green dashes: the encrypted file itself — it travels sender-to-recipient by email attachment, drive link, USB stick, anything — and never passes through SecureSend. Grey: supporting metadata flows to subprocessors listed at /legal/subprocessors.