Law firms send files constantly, and the sensitivity varies enormously. A scanned engagement letter is not a witness statement. A public filing is not a privileged memo. Using one tool for all of it is either overkill for the routine work or dangerously casual with the confidential work.

This is a practical guide to sorting that out. It is deliberately blunt about where free tools - including this one - stop being appropriate, because the alternative is a comfortable article that gets someone in trouble.

Nothing here is legal advice, and your bar association's guidance and your own professional indemnity requirements override anything below.

Key takeaways

  • Match the tool to the sensitivity of the document, not to firm habit
  • Privileged and client-confidential material needs end-to-end encryption and a signed data processing agreement
  • Free transfer tools are appropriate for routine, non-confidential exchange
  • Ask any vendor three questions: who can read it, where is it stored, and what do you sign

Sort Your Files Into Three Tiers

Almost every document a firm sends falls into one of these.

Tier 1 - Public or routine. Filed pleadings already on a public docket, marketing material, published judgments, an appointment confirmation. Confidentiality is not really at stake.

Tier 2 - Business confidential. Engagement letters, invoices, general correspondence. You would not want it public, but it is not privileged and disclosure would be embarrassing rather than damaging.

Tier 3 - Privileged or client-confidential. Advice, witness statements, discovery material, anything covered by legal professional privilege, anything with personal data about a client or third party.

The tiers need genuinely different tools, and the mistake firms make is using a Tier 3 tool for everything (slow, expensive, so people work around it) or a Tier 1 tool for everything (fast, cheap, eventually a problem).

What Tier 3 Actually Requires

For privileged material, the bar is higher than "it uses HTTPS." You are looking for:

End-to-end encryption, meaning the provider cannot read the file even if compelled to. If the vendor holds a key that can decrypt your document, then so does anyone with a warrant, and so does anyone who breaches them.

A data processing agreement you can actually sign, naming subprocessors and setting out breach notification. Without one you cannot demonstrate you controlled the data.

Known data residency. Where the file physically sits matters for cross-border privilege questions and for data protection compliance.

Access logging and retention control. Who downloaded it, when, and a defensible deletion policy.

Audit and certification. SOC 2 Type II or ISO 27001 as a baseline, because it means someone independent checked.

Tools that credibly meet this include Tresorit, Egnyte, NetDocuments, iManage Share, and Box or Microsoft 365 on the appropriate enterprise plans with a signed agreement. They cost money, and that is the trade.

Where Free Tools Fit - and Where They Do Not

This is the part worth being straight about.

ShareIt.onl is a Tier 1 and Tier 2 tool. It is good at what it does: files travel over HTTPS, links are random and never indexed, you can put a free password on a share, you can set it to delete after a single download, and every link expires on a timer you choose. Deletion is real - once a share expires, the files are gone from storage and cannot be recovered by you or by us. That is genuinely useful for routine exchange.

But it is not end-to-end encrypted, and we do not claim encryption at rest. Our team can access files when reviewing an abuse or copyright report. There is no data processing agreement on offer. For privileged material, those three facts are disqualifying, and no amount of password protection changes that.

So: sending a client a copy of their own filed document, an invoice, a form to complete? Fine, and faster than the secure portal nobody can log into. Sending draft advice or discovery material? Use the firm's proper system.

The same reasoning applies to WeTransfer, SwissTransfer, Smash, and pCloud Transfer. They are convenience tools. None of them is a privileged-document channel, whatever their marketing says about encryption.

The Three Questions to Ask Any Vendor

Before a tool touches Tier 3 material:

  1. Can you read my files? If the honest answer is yes, it is not end-to-end encrypted, regardless of what the homepage says. "Encrypted in transit and at rest" is not the same thing.
  2. Where are they stored, and who else touches them? Ask for the subprocessor list and the data centre locations.
  3. What will you sign? A DPA, and for US healthcare-adjacent work a BAA. If there is nothing to sign, there is nothing to rely on.

Vendors serving legal clients answer these in writing without hesitation. Consumer tools generally cannot.

Practical Habits That Matter More Than the Tool

Most confidentiality failures are process failures, not technology failures.

Check the recipient before sending, every time. Autocomplete sending privileged material to the wrong person is the most common incident in the profession. No encryption protects against a correct delivery to the wrong address.

Send the password by a different channel. A password in the same email as the link protects nothing. Text it, or say it on the phone.

Set the shortest workable expiry. A link that dies in 24 hours is exposed for 24 hours. One that lives forever is exposed forever. See why expiring links are safer.

Do not use transfer tools as storage. They delete files by design. Your matter file belongs in your document management system.

Write down which tier uses which tool, and tell everyone. An unwritten policy is not a policy, and juniors default to whatever is fastest.

A Workable Split

Tier Example Tool
Public / routine Filed pleading, invoice, form Free share link, short expiry, password if useful
Business confidential Engagement letter, correspondence Free link with password and one-time download, or firm email
Privileged / client-confidential Advice, statements, discovery Encrypted platform with a signed DPA

The point of the split is not to be precious. It is that a firm using a heavyweight portal for everything ends up with fee-earners emailing documents from personal accounts because the portal is painful - which is far worse than a sensible tiered policy.

The Short Version

Free transfer tools are fine for routine material and genuinely convenient. They are not appropriate for privileged documents, and any tool that will not tell you whether it can read your files has answered the question.

Sort your documents into three tiers, pick a tool for each, and write it down.

For routine exchange, send a file with a password and an expiry. For the background, read how to send sensitive documents securely and our security and retention page.