Security model

How AllFileGo keeps transfers secure

The sender must approve the receiver before file details are shared. Both devices can compare a security code, the connection is encrypted, and the receiver checks the completed file before saving it.

AllFileGo security controlsA control panel shows sender approval, matching security codes, encrypted transport, and final file verification.TRANSFER PROTECTIONChecks before, during, and after the transferSender approvalRequired before file details are sharedEncrypted connectionProtected by WebRTC in transitFile verificationChecked before completion is reportedMATCH THIS CODE384 219
Approval first. Verification last.Security checks cover the full transfer.
Security layers

Five checks help protect each transfer.

  1. 01Short-lived roomsPairing state expires automatically.
  2. 02Sender approvalNo file details are shared before approval.
  3. 03Matching security codeBoth devices show the same code.
  4. 04Encrypted connectionWebRTC encrypts the file while it travels.
  5. 05File verificationIncomplete or changed files are not completed.
01

The room code does not grant access

The six-digit room code only helps a device find the room. A receiving device must still request access, both devices must show the same security code, and the sender must approve the request.

Compare the complete security code on both screens. Reject any device you do not recognize. File names and file data are not shared before approval.

02

Connection setup is encrypted

The browsers create separate encryption keys for messages sent in each direction. AllFileGo uses established cryptographic standards, and it rejects old, repeated, or incorrectly ordered encrypted messages.

The service still handles temporary room information, public pairing data, encrypted setup messages, and connection metadata. Security also depends on the AllFileGo website, both browsers, both operating systems, and installed browser extensions.

03

The file connection is encrypted

WebRTC encrypts DataChannel traffic while it travels between the devices. AllFileGo also limits message types, sizes, queues, rooms, and request rates to reduce abuse and unexpected input.

Encryption prevents someone who only watches the network from reading the file. It does not hide that a connection exists or make either device anonymous.

04

The receiver checks the completed file

The receiver checks the file size and SHA-256 fingerprint against the sender's file before marking the transfer complete. This detects missing or changed data and prevents a partial file from appearing as complete.

This check does not scan for malware or prove that the sender is trustworthy. Do not open an unexpected file simply because the transfer completed successfully.

05

What AllFileGo cannot protect

An approved receiver can save, copy, or forward the file, and AllFileGo cannot take back a completed download. Direct transfer also cannot protect a compromised device, malicious file, unsafe browser extension, or compromised website.