How to share files securely by link — and what “secure” really means
August 14, 2026 7 min read
"Send me a link" is the fastest way to share a file — and, by default, the least private one. A share link is built for convenience first: it's public, and anyone who gets the URL can open it, whether you sent it to them or not. That's fine for a portfolio and a problem for a contract. This is a plain-English guide to the controls that make a link safer, what each one actually protects against, and — just as important — the limits nobody likes to mention.
A plain link is convenience, not privacy
Let's be honest about the starting point. When you upload a file and get a link, that link is public. There's no gate. If it lands in the wrong chat, gets forwarded, or shows up in someone's browser history, whoever has it can open it. A URL is not a password — it's an address, and addresses get shared.
For a lot of things, that's exactly what you want: a resume, a public deck, a photo album for friends. The convenience is the point. The trouble starts when people assume a link is private just because it looks random. It isn't. If a file matters, you add controls on purpose — you don't get them for free.
The protective layers — and each one's real limit
Here are the controls worth knowing, each paired with the honest boundary of what it does. Notice the pattern: most of them raise the effort or narrow the window, but none of them make a file un-shareable.
- Password protection. The link only opens after someone types the secret. This stops the wrong opener — a forwarded link, a lucky guess, a stranger with the URL. It does notstop a determined person you gave the password to, and it's only as strong as the password and how you shared it (don't put both in the same email).
- View-only / disable download. The file renders in the browser but the download button is gone. This deters casual saving and keeps people from carelessly re-sending your file. It cannot stop screenshots, screen recording, or a phone camera pointed at the screen. Treat it as friction, not a lock.
- Expiry date. The link simply stops working after a date you pick. Great for time-boxed access — a quote valid this week, a doc for a meeting. The limit is obvious: anyone who opened or downloaded it before expiry already has it.
- View limit / one-time link.The link dies after it's opened N times (or just once). Useful for "this is for you and nobody else." But a "view" is a request, not a person — a preview loader, a bot, or a double-click can spend one, and a screenshot on the first open defeats the whole idea.
- Notify-on-view.You get a ping when the file is opened. This doesn't protect the file at all — it gives you awareness. You learn it was opened, roughly when, and can follow up (or get suspicious if a link opens from somewhere you didn't expect).
- Watermark.Stamping a name, email, or timestamp onto a PDF makes leaks traceable back to whoever received that copy. It's a deterrent and a forensic tool — people are less cavalier with a document that has their name on it — but it doesn't prevent the leak, it just tells you who to ask about it afterward.
The boundary you can't design around
Every control above shares one hard limit: once someone has opened or downloaded a file, you can't un-send it. Expiry, view limits, and disabled downloads all act at the front door. None of them reach into a copy that's already on someone's device or screen. Revoking a link stops the next person, not the last one.
It's also worth being precise about a word people throw around: a share link is notend-to-end encryption. The layers here are access controls — they decide who gets in — not cryptographic guarantees that only a specific recipient can ever read the bytes. For most business files, access control is exactly the right tool and plenty. For genuinely sensitive data, it isn't enough.
When a link isn't the right tool at all
For truly sensitive material — legal discovery, medical records, credentials, financial secrets, anything with a compliance obligation — don't reach for a share link at all. Use a purpose-built, end-to-end encrypted tool designed for that data, with real access logs and a chain of custody. A convenient link is the wrong instrument for a serious secret, no matter how many controls you bolt onto it. Knowing that boundary is part of sharing responsibly.
How to do it with Link in Seconds
Link in Seconds turns a PDF, image, video, ZIP, or HTML file into a clean public link (linkinseconds.com/p/…) with a QR code and view analytics — no account needed on the other end, and links never expire by default. Drop several files in and they bundle into one album link (linkinseconds.com/b/…). Then you layer on exactly the controls the file deserves:
- Free, on every link: a clean public URL, a QR code, and view tracking so you know it was opened.
- Pro, when the file needs it: password protection, an expiry date, a custom link, view-only (download disabled), a view limit / self-destruct, notify-on-view, and PDF watermarking — each enforced on the server, not just hidden in the UI.
So a portfolio stays a one-click public link, while a contract goes out as a password + expiry + view-limited link that pings you the moment it's opened. See how the download-off flow works on the view-only file sharing page, or walk through the lock step by step in how to password-protect a file you share. The free plan already gives you the public link, QR, and view tracking — start there and add the Pro controls when a file actually calls for them.
Turn any file into a link in seconds
Upload a PDF, image, video, or ZIP and get a clean, trackable link with a QR code — free.
Try Link in Seconds →