Skip to content
HexaTransfer
Back to blog
Productivity & Collaboration

How Agencies Share Files with Clients Securely

Learn how agencies can securely exchange files with clients. Best practices for branding, access control, and professional file delivery.

Agencies share files with clients securely by encrypting payloads with AES-256-GCM before they leave the workstation, gating access with per-link passwords sent through a separate channel, keeping retention to the shortest window the engagement allows (typically 7-14 days), and running the exchange through a tool that logs downloads. The professional polish — branded delivery pages, custom domains, agency logo on the landing page — matters for optics but should never override the security baseline. This guide covers both sides: what makes a client handoff look professional, and what makes it actually safe.

What Clients See vs What They Need

A client receiving a 4 GB campaign delivery cares about three things, in order: does the link work, does the file open cleanly, and does the agency look competent in the handoff. Everything else — the header graphic, the custom subdomain, the elegant email template — is secondary.

The agency cares about a different set: was the file intercepted, did the right person receive it, is there a record for billing and dispute resolution, and did it go out under NDA constraints.

A good exchange tool serves both sides without making one compromise the other.

Branding the Delivery Page Without Weakening Security

Most agency-grade transfer tools let you customize the delivery page. WeTransfer Pro, Smash, Dropbox Transfer, and Portal by Copilot all support logos, colors, and custom messages. The temptation is to pile on: full brand palette, testimonials, CTAs for other services.

Resist. A cluttered delivery page distracts the client from the file they came for. Keep it to:

  • Agency logo at the top.
  • One-line project description ("Q3 Campaign — Final Masters").
  • The file list with sizes and download buttons.
  • A contact line ("Questions? reply to this email or call X").

Brand consistency builds trust. Noise undermines it.

Custom Domains and Why They Matter

A link at files.youragency.com/transfers/xyz reads very differently from one at wetransfer.com/downloads/xyz. Clients forward the branded version internally without hesitation; they balk at the generic one because it looks like a phishing risk.

Tools that support custom domains via CNAME: WeTransfer Pro, Smash Team, Portal, Hightail, and MASV. Set up DNS with a CNAME record pointing to the vendor's delivery host, install the TLS 1.3 cert (Let's Encrypt or the vendor's), and test. Budget a day for the first setup; subsequent domains are faster.

For one-off sends where custom domain isn't set up, HexaTransfer links on hexatransfer.com carry the clean, recognizable URL that clients trust more than an obscure service they've never heard of.

Per-Engagement Access Controls

Every client engagement has its own sensitivity profile. A public launch asset in the final week before embargo needs tighter control than a finished campaign already in the wild.

Baseline per engagement:

  • NDA-covered work: password-protected links, 48-72 hour expiry, 3-download cap, passwords sent via SMS or a call.
  • Pre-launch assets: password-protected, 7-day expiry, 5-download cap.
  • Post-launch / published work: optional password, 30-day expiry.
  • Large archival handoffs at engagement close: password, 30-day expiry, client confirms receipt in writing before link expires.

Document these in your statement of work so the client understands what to expect and can request exceptions up front.

Recipient Verification Before the Send

The most common agency file incident isn't interception — it's sending to the wrong person. A contact with a similar name. An old contact from before a client personnel change. An autocomplete suggestion that matched the wrong domain.

Slow down the send:

  • Type the recipient email manually for the first send to a new contact. Don't rely on autocomplete.
  • For anything under NDA, confirm the email in a separate channel before sending the link.
  • When sending to a new domain, verify the domain on the client's website (legal entity, not a lookalike).
  • For unusually large or sensitive sends, require a manager review step in your agency's workflow.

These add 5 minutes to a send. They save weeks of cleanup when something goes wrong.

The Two-Channel Password Pattern

End-to-end encryption means even the transfer service can't read the file. But if you send the password in the same email as the link, anyone who intercepts the email has both. Use two channels:

  • Link by email.
  • Password by SMS to a phone number verified during client onboarding.

Some agencies use an encrypted messaging app (Signal, WhatsApp) for the password; others call and read it over the phone. Whatever the channel, it has to be different from the channel carrying the link.

HexaTransfer encrypts content client-side with AES-256-GCM and derives keys from the URL fragment, so the server never sees plaintext — the two-channel pattern doubles that protection against phishing and email compromise.

Retention That Respects Client Contracts

Statements of work often include data handling clauses. Read them before configuring retention defaults.

Common clauses to watch for:

  • "Contractor shall delete all client materials within 30 days of engagement close." Set retention to match.
  • "Contractor shall retain records for audit purposes for 3 years." This applies to project records, not necessarily to transfer links — but check.
  • "GDPR Article 28 processing terms apply." Retention limits flow from the lawful basis you're operating under.
  • "HIPAA Business Associate Agreement in effect." 6-year log retention from the date of creation or last effective date.

Default short, extend only when required, and document what's held where.

Audit Trail the Client Can Request

Clients occasionally ask, "did my media company actually download that file?" A good exchange tool answers with a timestamp, IP, and user agent. Provide:

  • Download events with date, time, IP, user agent.
  • Link expiry status.
  • Password-attempt log if the tool captures it.
  • Creation and access log export as a .csv for the client's records.

Some agencies include a link to the audit log in the delivery email. Others provide it on request. Either way, having it available distinguishes professional delivery from casual file-drop.

When Clients Need to Send Files Back

Exchange is bidirectional. Source footage, reference photos, signed contracts — clients often need to send back to the agency. Options:

  • Request links (upload-only): agency generates a one-way upload link; the client drops files without needing an account. Uploads land in the agency's workspace.
  • Shared folder with client access: long-term engagements. Dropbox shared folder, Google Drive shared drive, or SharePoint with B2B federation.
  • Portal: tools like Content Snare, Filemail, or Copilot Portal provide a client portal with intake forms and structured upload. Heavier setup, stronger experience for long relationships.

For one-off intakes, request links cover most needs. For recurring relationships, a portal pays off.

Templates That Save Time

Build delivery templates in your transfer tool of choice:

  • Round 2 feedback package: standard subject line, password-protected, 72-hour expiry, "Review notes attached" body.
  • Final masters delivery: standard subject, password, 14-day expiry, checksum in body, contact line.
  • Invoice and contracts: no password needed (usually), 30-day expiry.
  • Intake request to client: upload link, 14-day expiry, instructions in body.

Templates reduce decision fatigue and ensure every send has the right controls on by default.

Pricing and Positioning

Agencies should bake file delivery tooling into overhead, not bill it back. Transparent line items like "file delivery fee" look petty. A $12-30/month subscription across the agency is rounding error compared to project budgets.

Use free tiers (HexaTransfer free for most sends) and keep a paid account for branded domain delivery when the engagement's polish calls for it.

The Agency Standard to Aim For

Clients leave one agency for another over small frictions as often as over big mistakes. A link that doesn't work, a password sent in a confusing way, a delivery that looks sloppy — those moments compound. The agencies that hold clients longest treat delivery as part of the deliverable, not an afterthought.

Try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file