Home · Blog · Is a transfer link secure

Is a transfer link secure enough for client work?

The Kepla team · August 28, 2026 · 7 min read
A figure between tall stone columns in hard light
Workflow & Gear

Every file transfer service works the same way: it gives you a long unguessable URL and treats anyone holding it as authorised. That is weaker than a password and much stronger than most people assume. Understanding exactly what it does and does not protect is the difference between using it sensibly and either worrying about the wrong thing or not worrying at all.

01 · THE MODEL

The technical term is capability URL: the link is the permission. There is no login because the address itself is the secret. A well built one has enough randomness that guessing it is not a realistic attack, in the same way that guessing a password is not.

What that buys you: nobody browsing the service can find your transfer, there is no directory to enumerate, and the storage behind it is not publicly listable. What it does not buy you: any protection at all once the link is out of your hands. Forwarded, pasted into a group chat, or left in an inbox that later gets breached, and it works for whoever has it.

Two things turn that from a weakness into a manageable one. Expiry puts a ceiling on how long a leaked link stays useful. Deletion means that after expiry there is nothing to leak. A service that keeps files indefinitely has neither.

02 · THE RISK

Where the risk actually sits

In descending order of how likely it is to be what actually goes wrong:

Notice that four of the five are about how long the files exist, not about encryption. Retention is the security control that does the most work here, and it is the one photographers think about least.

03 · DUE DILIGENCE

Four questions to ask a service

Before a client's wedding goes through anything:

  1. When exactly are the files deleted, and can I choose? A named window is a commitment. "We may retain files" is not.
  2. Is the storage private, and is the download link time limited? The right answer is a signed URL that stops working, not a public bucket path that works forever.
  3. Who else touches the files? A privacy policy that names its sub-processors is doing the honest version of this. Vagueness here is the tell.
  4. What happens to my email address? Ask specifically whether it joins a marketing list. Plenty of free tools treat the delivery address as a lead.

For what it is worth, Kepla Free File Transfer answers those as: you choose one hour to three days and the files are deleted at that point with no grace period, the bucket is private and every download is a fresh signed link that cannot outlive the transfer, the sub-processors are named in the privacy policy, and sender addresses are kept in their own table and never added to any mailing list.

04 · RULES

Practical rules for client work

None of this requires a security policy document. Four habits cover it:

05 · COMMON QUESTIONS

FAQ

Is WeTransfer safe for client photos?

It is reasonably safe for ordinary work. Like every transfer service it uses a secret link as the permission, so anyone holding the link can download. The real controls are how long the link lives and when the files are deleted.

Can someone guess a file transfer link?

Not realistically, if the code is long and randomly generated. Guessing a well built transfer code is comparable to guessing a strong password. The practical risk is the link being forwarded or sitting in an inbox, not being guessed.

What happens if a client forwards my download link?

It works for whoever has it, on every transfer service. That is why expiry matters: it puts a hard ceiling on how long a forwarded link is useful, and after the files are deleted there is nothing to forward.

Are transferred files encrypted?

In transit, yes, on any service worth using. At rest depends on the provider. Ask instead when the files are deleted, because for this kind of work retention does more than encryption.

What is the most secure way to send photos to a client?

A private, time limited link with a short expiry, sent only to the client, with location metadata stripped from anything shot at a private address, and your own copies kept separately. Encryption is table stakes; retention is the control that matters.

FOUNDING COHORT · 100 SEATS

Never cull alone at 1 AM again.

Kepla for Mac clears the obvious misses from a card, names the reason on every frame it sets aside, and leaves the choosing to you. Nothing is ever deleted, moved or renamed. Free through the private preview · the first hundred photographers keep it at $99 a year.

Get Early Access
KEEP READING