Security
Your files, nobody else’s business.
Always encrypted, with a key for every file, on servers in Germany. And for the files even we shouldn’t be able to open, a vault and end-to-end encrypted transfers.
The journey of a file
From your laptop to their inbox, sealed the whole way.
- Leaves your deviceOver an encrypted connection, straight to our servers.
- Gets its own keySealed with AES-256-GCM and a key made for this file alone.
- Stored in GermanyWritten to disk at Hetzner. Never to a public bucket.
- CheckedScanned for viruses as soon as it finishes uploading.
- Delivered by usEvery download passes through Yungle, so links really expire.
Every file gets its own key.
Files are encrypted as they upload, before anything is written to disk, with AES-256-GCM and a key that belongs to that one file. Those keys are themselves locked with a master key that lives outside the database and is escrowed offline.
- A unique key for every file, never shared between them
- Encrypted on the way in, not in a nightly batch
- Keys kept apart from the files they unlock
Hosted in Germany, by a European company.
Yungle runs at Hetzner in Germany, in ISO 27001-certified data centres. Nightly backups go to storage in EU jurisdiction at a second provider, and a restore is rehearsed automatically every week rather than assumed to work.
- Your files are served from Germany
- No public storage bucket: every download goes through Yungle
- So an expired or revoked link really stops working
Every upload is checked.
Each file is scanned for viruses as soon as it finishes uploading — including files strangers send you through a request link. A file that fails the scan has its key destroyed on the spot, which blocks every download of it at once.
When encryption alone isn’t enough.
Some files should be unreadable even to us. The vault is locked with a passphrase that never leaves your browser, and a transfer can be sent end-to-end encrypted, with the key carried in the link itself and never sent to our servers.
- A vault only your passphrase opens
- Optional end-to-end encrypted transfers, free
- Password-protected links and expiry dates you choose
What we’d rather tell you now
- By default we hold the keys. That is what makes previews and virus scanning possible — use the vault or an end-to-end encrypted transfer for anything we must not be able to open.
- Yungle runs on one server, with no failover and no service level agreement. We would rather say so than publish an uptime figure.
- Yungle holds no security certification of its own. The data centres it runs in are ISO 27001 certified.
- Files in the vault and in end-to-end encrypted transfers cannot be scanned for viruses, because we cannot read them.
Questions, answered.
Ask us something elseIs Yungle end-to-end encrypted?
Not by default, and we are careful to say so. Every file is always encrypted, with its own key, but those keys are held by Yungle — which is what allows previews and virus scanning. The vault and optional end-to-end encrypted transfers use keys that never reach us.
Where are my files stored?
On servers at Hetzner in Germany. Nightly backups are kept in EU-jurisdiction storage at a second provider. The full list of companies that process data for us is in the privacy policy.
Can anyone at Yungle look at my files?
Nobody browses uploads. Because the service holds the keys for ordinary files, it is technically able to decrypt them — that is how a preview is made. If that is not acceptable for a file, put it in the vault or send it end-to-end encrypted.
Do you sign a data processing agreement?
Yes. The data processing agreement is published and applies to every account, so there is nothing to request or negotiate before you start.
How do I report a security problem?
Write to hello@yungle.co. It reaches the person who runs the service directly, and reports are answered, not queued.
Send your first file in ten seconds.
10 GB, free, right now — no account, no card, no ads. Pay us only when you want your work to stay put.
- Cancel anytime
- iDEAL, card or SEPA
- Export or delete everything, yourself