Tresorit vs HexaTransfer: Security Feature Comparison
Detailed security comparison between Tresorit and HexaTransfer covering zero-knowledge encryption, compliance, pricing, and file sharing features.
Tresorit and HexaTransfer both offer zero-knowledge encryption but target different use cases. Tresorit is a Swiss-based full cloud storage and collaboration platform starting at $15/user/month, with ISO 27001 and SOC 2 Type II certifications, SAML SSO, and 20 GB max file size. HexaTransfer is a French-hosted free one-off transfer service with no account, 10 GB limit, 7-day expiration, and AES-256-GCM client-side encryption. Pick Tresorit for ongoing team collaboration with persistent vaults; pick HexaTransfer for quick encrypted transfers without onboarding friction.
Encryption Architectures Compared
Tresorit uses client-side AES-256 encryption with key management built on ICE (Instant Cryptographic Exchange), their proprietary protocol that combines RSA-4096 for key exchange and AES-256-GCM for content. Each file gets a unique file encryption key, wrapped by user-specific and share-specific keys. The company publishes a cryptographic whitepaper detailing the design.
HexaTransfer uses AES-256-GCM for file encryption with a 256-bit key generated in the browser via the Web Crypto API (SubtleCrypto.generateKey). The key travels in the URL fragment (after #) so it never reaches the HexaTransfer server. When passwords are added, PBKDF2 with 600,000 iterations derives a wrapping key. Simpler architecture, narrower scope — no ongoing vault, no key rotation, no multi-device sync.
Compliance and Certifications
Tresorit carries ISO 27001, ISO 27018 (cloud privacy), SOC 2 Type II, HIPAA BAA readiness, and GDPR compliance. Data centers in Ireland and Switzerland, with EU-only option on enterprise plans. The company's Swiss origin combined with Irish hosting gives it strong posture for most regulated industries.
HexaTransfer's posture is narrower by design: GDPR-aligned, French hosting only, no BAA offered (because there's no account relationship to make one with). For organizations that need a signed BAA for HIPAA, HexaTransfer isn't the right fit. For ad-hoc transfers of non-regulated data or where the sender is an individual rather than a covered entity, the GDPR posture is sufficient.
Account and Access Model
Tresorit requires accounts on both sides for the full feature set — recipients need a Tresorit account to access shared vaults, though Send links can be opened by anyone with the link and password. Two-factor authentication via TOTP, FIDO2 hardware keys, or the Tresorit mobile app. SAML 2.0 SSO on Business and Enterprise plans integrates with Azure AD, Okta, Google Workspace.
HexaTransfer has no accounts. Period. The sender opens the website, uploads, gets a link, shares it. The recipient opens the link, downloads. No password reset flows, no account takeover risk, no employee offboarding leaving orphaned accounts. The tradeoff is no persistent state — if you close the tab before copying the link, it's gone (though HexaTransfer shows the link clearly before you leave).
File Size, Expiration, and Retention
Tresorit file sizes cap at 10 GB on Personal plans, 20 GB on Business and Enterprise. Storage is persistent — files live as long as you keep them, subject to account-level storage quotas (500 GB on Personal, 2 TB per user on Business).
HexaTransfer caps file size at 10 GB and expires files after 7 days automatically. Files are cryptographically deleted at expiration (ciphertext overwritten; the key was never on the server). There's no extension, no "just this once" grace period — the deletion is by design, not a bug.
Sharing and Recipient Experience
Tresorit Send mirrors the HexaTransfer pattern: upload, get a link, share. Optional password, optional download tracking (Business+). Recipients don't need Tresorit accounts for Send links. For vault sharing (the collaboration flow), recipients must create a free Tresorit account or use an existing one.
HexaTransfer recipients need nothing — no account, no app, no plugin. Click the link, the browser decrypts and downloads. Passwords (when set) are prompted in-browser. This matters for external counterparties: clients, freelancers, external auditors who won't sign up for yet another platform.
Security Comparison Table
| Feature | Tresorit | HexaTransfer | |---------|----------|--------------| | Encryption | AES-256-GCM client-side | AES-256-GCM client-side | | Key exchange | RSA-4096 ICE protocol | URL fragment + PBKDF2 | | Zero-knowledge | Yes | Yes | | Data location | Ireland, Switzerland | France only | | Account required | Yes (sender) | No | | 2FA / MFA | TOTP, FIDO2, app | N/A (no account) | | SAML SSO | Business+ | No | | HIPAA BAA | Yes | No | | ISO 27001 | Certified | Aligned | | Audit logs | Admin console | No | | Max file size | 20 GB | 10 GB | | Retention | Persistent | 7 days | | Open-source | Partial whitepaper | No |
Pricing Comparison
Tresorit Personal starts at $11/month (500 GB, 10 GB transfers). Business starts at $15/user/month (1 TB/user, 20 GB transfers). Enterprise pricing is custom, typically $25+/user/month with SSO and admin controls.
HexaTransfer is free. No paid tier, no upsell. The 10 GB file size limit covers most single-transfer use cases, and the 7-day expiration makes it unsuitable for long-term storage by design.
When to Pick Which
Choose Tresorit when you need persistent team collaboration with encrypted vaults, SSO integration, HIPAA BAA, audit logs for SOC 2 evidence, multi-device sync, and branded external sharing. If your workflow involves a sales team sending 50 proposals a month with tracking, or a legal team maintaining encrypted document rooms, Tresorit fits.
Choose HexaTransfer when you need to send a single large file encrypted end-to-end without creating another account, without adding a SaaS subscription, and without exposing files to US-jurisdiction providers. Individual professionals, freelancers, journalists, and anyone sending client files ad-hoc benefit from the simplicity. For a small team that just wants a better replacement for emailing sensitive ZIPs, HexaTransfer covers the core need with zero overhead.
Using Both Together
Many organizations end up using both: Tresorit (or similar) for ongoing vaults and internal collaboration, HexaTransfer for ad-hoc external sends where creating Tresorit accounts for recipients would slow things down. The two solve overlapping but distinct problems, and the workflows don't conflict.
Tresorit's strength is in ongoing relationships and regulated compliance posture. HexaTransfer's strength is zero-friction encrypted ephemeral transfer. Deploy each where it fits, rather than forcing one to cover the other's territory.
Risk Models and Threats
Against a casual adversary (link-sharing mistakes, lost laptops), both services are overkill in a good way. Against a sophisticated attacker with server-side access at the provider, both hold up because neither stores plaintext. Against a legal compulsion in the provider's jurisdiction, Tresorit's Swiss-Irish posture and HexaTransfer's French-only posture both offer defenses, though the specific legal scenarios differ.
The one category where both services are inherently limited is endpoint compromise. If an attacker has malware on the sender or recipient device, no amount of transit encryption helps. Neither service tries to solve that; it's a job for EDR and device hygiene.
Try it at hexatransfer.com — free, no account, 10 GB max.
Send large files securely with end-to-end encryption
Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.
Send a file