Email is the default way most people send a document, and it is the wrong tool for anything private. Not because it is broken — because it was designed to deliver copies, and a copy is exactly what you don’t want when the document is sensitive.
An email attachment is stored unencrypted on every mail server it passes through, stays in inboxes and backups indefinitely, can be forwarded to anyone, and gives you no way to know who opened it. None of that is a setting you can turn off. It is how email works.
Armadoc sends a link instead of a copy. Your file is encrypted in your browser before it is uploaded, so the encrypted blob on my storage is unreadable without a key I never hold. The key is sealed so that only your recipient’s device can open it, and it is released only after they verify with a one-time code. When the expiry you chose passes, the file is permanently deleted. Your recipient needs no account and no app.
| Email attachment | Armadoc | |
|---|---|---|
| Who can read it | Your provider, your recipient’s provider, and every server in between | Only your recipient — it is encrypted before it leaves your browser |
| How long it lasts | Indefinitely, in every inbox, archive and backup it reached | Until the expiry you set, then permanently deleted |
| Who can open it | Anyone the message reaches, including anyone it is forwarded to | One recipient, after a one-time code sent to their email or phone |
| Taking it back | Not possible once it has been delivered | Built in — you choose the expiry before you send |
| Knowing it arrived | A read receipt your recipient can silently decline | A notification when the file is actually opened |
| What the recipient does | Nothing — which is the problem | Enters a code. No account, no app, no password to invent |
When you attach a file and hit send, your mail server hands it to your recipient’s mail server, often through others along the way. The connections between those servers are usually encrypted. The file sitting on them is not — it rests in ordinary storage, in an account your provider controls, on infrastructure neither you nor your recipient has ever seen.
That copy then multiplies quietly. It lands in a sent folder, an inbox, a mobile client’s local cache, a corporate archive, an automatic backup. Every one of those is a copy that outlives the moment you needed to share it, and none of them answers to you.
It helps, and it is better than nothing. But the weak link is the password itself: you still have to get it to your recipient somehow, and in practice it travels in the same email, or a text message sent a minute later — sitting right next to the file it unlocks.
It is also only as strong as the password you chose, which is usually a date or a surname. And it leaves the other three problems entirely untouched: you still cannot verify who opened the file, it still never expires, and it is still never deleted.
Partly, and the distinction matters. Mail between major providers is normally encrypted in transit, and stored encrypted at rest on their disks. That is real protection, and it defeats an eavesdropper on the wire.
But your provider holds those keys, not you. Encryption at rest protects the data from someone who steals the hard drive; it does not protect it from the system that is designed to read it, or from anyone who reaches an inbox the message landed in. End-to-end encryption means something stricter: the key never exists on the server at all.
No. Recall features exist, but they only work inside a single organization’s mail system, and only if the message hasn’t been read yet. Across providers — which is most of the time — there is no mechanism at all. Once it is delivered, it is delivered.
Expiry has to be part of how the file was sent in the first place. With Armadoc you choose it before sending: up to 10 days on the free plan, anywhere from 1 to 30 days on Pro. When it passes, the encrypted file is deleted from storage for good.
Most of what you send doesn’t need any of this. A meeting agenda, a photo of a receipt, a draft nobody would care about — attach it and move on. Adding ceremony to an ordinary file helps nobody, and I’d rather say so than pretend every message is a security incident.
The moment it is worth changing tools is when the document would matter if it ended up somewhere you didn’t choose: a passport scan, a tax return, a signed contract, medical paperwork, anything with a bank account number on it. That is the handful of sends Armadoc is built for — which is also why the free plan is five a month rather than unlimited.
Encrypted in your browser, opened only by the person you chose, gone when it expires. Your recipient doesn’t need an account.
Send a fileFive free sends every month. No card to start. · See how it works