All posts

How to send large files securely: a practical guide

Sending a large file safely comes down to four questions: who can open the link, how long it lives, what the other person may do with the file, and where it sits in the meantime. Here is how to answer each one in Nemi, which settings fit which situation, and what the person on the other end actually sees.

Guides · · 8 min read

Email was never built to carry big files, and the usual workaround, a link to a file in somebody's cloud folder, solves the size problem by creating a different one: a link that anybody can open, forever, with no record of who did. Sending a large file securely is not one feature. It is four small decisions, and every one of them takes a few seconds.

  • Who can open it. Anyone with the link, anyone signed in, or only the people you name, with or without a password on top.
  • How long it lives. An expiry date, a download limit, or both.
  • What they may do with it. Download it, or only look at it, and whether they have to approve it.
  • Where it sits meanwhile. Which country, encrypted how, and checked for what.

Which settings fit which situation?

The right answer depends on what you are sending and to whom. A contract for one client and a press kit for fifty journalists want opposite settings, and the safest link is not the one with every lock switched on, it is the one that fits. Pick a situation below to see what we would choose and why, then change anything and watch what the recipient gets.

Build a link for your situation

What are you sending?

One reader you can name, a document that should not travel. A password sent by another route keeps a forwarded email from opening it, a short expiry and a small download count stop it lingering, and Approval lets the client answer on the page instead of in a reply you have to find later. If your client has a Nemi account, Approved is stronger still: only their account gets in.

Who can open it

No account needed. The link is the key.

Expires

Under More

Your plan

Services agreement.pdf (2 MB) fits in one upload on Creator.

What they see

  1. Screen 1

    This link is protected

    One password box, and nothing about the files until it is right: not the names, not how many.

  2. Screen 2: your page

    Services agreement.pdf2 MBPreview, Download
    Your question, such as: is this ready to sign?ApproveRequest changes
    • The link stops working after 7 days.
    • After 3 downloads it stops serving anything, previews included.
The expiry choices each plan offers come from the same function the share panel uses, and the file size check reads the plan limits directly. The screens on the right use the wording on the real pages.

How do I send a large file with Nemi?

Every step below names the button as it appears on screen. The link exists the moment you create it. The expiry, the password and who can open it can be changed afterwards without the address changing; the rest is decided when you create the link.

  1. 1

    Upload the file

    Drag it onto the file browser, or press Upload Files. The upload goes straight from your browser to storage, and a file over 32 MB is sent in 16 MB pieces, so a dropped connection costs only the pieces in flight rather than the whole file.
  2. 2

    Select it and press Share

    The share panel opens with a name filled in. Type over it: that name is the heading your recipient reads, so write it for them rather than for your folder structure.
  3. 3

    Choose when it expires and who can open it

    Expiry is the row of choices at the top, from 24 hours to Never; the choices the workspace's plan does not include sit behind one Longer button with a padlock. Who can open it is three buttons: Anyone, Sign-in and Approved.
  4. 4

    Open More for the rest

    A password, a download limit of 1, 3, 5 or 10, and the switches for Once, Preview, Approval, Watermark and Trace. Once, Preview and Watermark are decided now, not later.
  5. 5

    Press Create link

    If you typed email addresses under the name, the button reads Create & send and Nemi emails the link for you. If you set a password, send it by a different route from the link: a text message, a call.

How large a file can I send?

The limit is on the upload, per file, and it comes from the plan of whoever owns the workspace. It ranges from 500 MB on Free to 200 GB in a single file on Business. Two other numbers matter for big deliveries: the longest a link may stay open, and how much you can upload in a calendar month. The monthly figure counts what you upload, and deleting a file afterwards does not give it back, because storing it has already cost money the moment it arrived.

Plan limits for sending large files
PlanLargest fileLongest linkUpload a month
Free500 MB7 days15 GB
Starter5 GB1 month300 GB
Creator15 GB1 year800 GB
Pro25 GBNever2 TB
Max100 GBNever3 TB
Business200 GBNever10 TB

Very large uploads survive a bad connection. If a transfer stops, drag the same file into the same folder again within 5 hours of starting it and it continues from the pieces storage already holds, even after closing the tab. We wrote about how that works, and why the browser is never trusted to remember which pieces arrived, in a separate post. If the file is a video that only has to be watched, making it smaller may be all you need, and a whole folder reaches the other side as one zip that streams.

Password, expiry or download limit: which do I need?

They are three different locks, checked independently, and it helps to know what each one does to the person on the other end.

A password gates entry. The visitor sees a page that says This link is protected with one box, and nothing about the files until they get it right: not the names, not the count. It sits on top of whichever access mode you chose, so Anyone plus a password is the classic arrangement of the link by email and the password by phone. We store the password hashed and cannot read it back, so if you forget it, set a new one.

An expiry ends the link on a date. For 30 days afterwards the recipient sees that it has expired with a button reading Ask the sender to resend, which lands in your notifications; after that there is nothing to press.

A download limit ends it on a count. Each single file download, folder zip, download of everything at once and save to a Nemi account counts as one; opening the page and previewing does not. Once the count is reached, the link stops serving anything, previews included, and says so. For a large file, be generous: every download that is started counts, so one that has to be started again after a dropped connection counts twice.

Previews, approvals and knowing what happened

Preview lets people look and never download. Documents, images, video, audio and many more formats open in the browser, so a draft can be watched, read and discussed without a copy leaving. It is the right setting for anything you want seen but not kept.

Approval turns the page into a question. A bar at the foot of the page asks what you wrote and offers Approve and Request changes, so sign off arrives in your notifications rather than in a reply you have to find. Do not confuse it with the Approved access mode, which is about who may open the link at all.

Trace records what happened after you sent it: opens and downloads, counted by our server, with the country and city they came from, the kind of device and the browser, and an estimate of reading time per page reported by the viewer's browser, plus a short code on every download so a copy that turns up somewhere can be traced to the download it came from. It is off unless you switch it on, per link, and only you see it. It also makes you the one recording somebody's visits, so tell the people you send it to; our terms require it. The details are in the help page on Trace.

Where are the files stored, and who can read them?

File storage runs in Amsterdam, and every request travels over TLS, from the upload in your browser to the download on the other side. Files are encrypted at rest with AES-256 by our storage provider. That protects a copy of the data; it does not make the files unreadable to Nemi, because our servers have to read a file to preview, convert or zip it. The one place that is closed to us is a Vault, which is encrypted in your browser with a key we never hold.

Uploads are scanned for malware in the background, on infrastructure we run ourselves, and nobody can download a file through a link until its scan has finished. Two kinds of file are not scanned: files in a Vault, which a scanner cannot read, and files above 500 MB. In a post about large files that second one is worth saying plainly: a scan is a safety net, not a reason to open something you did not expect.

Everything in this guide works from the same panel: see Sharing for the overview, Security for how files are protected, passwords, expiry and download limits for every message a recipient can see, and pricing for the plans.

Questions people ask

What is the most secure way to send a large file?

Use a link you control rather than an attachment or an open cloud folder: limit who can open it, add a password and send it by a different route, and give the link an expiry date or a download limit. In Nemi all of that is set in the share panel, and the file is stored in Amsterdam and encrypted at rest.

How do I send a file that is too large for email?

Upload it and send a link instead. In Nemi, upload the file, select it, press Share, choose who can open it and when it expires, and press Create link. If you type email addresses under the name, the button reads Create & send and Nemi emails the link for you.

How large a file can I send with Nemi?

Per file, it depends on the plan of whoever owns the workspace: 500 MB on Free, 5 GB on Starter, 15 GB on Creator, 25 GB on Pro, 100 GB on Max and 200 GB on Business. Each plan also has a monthly upload volume, and deleting a file afterwards does not give that back.

Should I password protect a shared file link?

For anything private, yes, and send the password by a different route from the link, such as a text message or a call. In Nemi the visitor sees only a box saying the link is protected, and nothing about the files, until the password is right. The password is stored hashed and we cannot read it back.

Can I see who downloaded my file?

With Trace switched on for a link, Nemi records its opens and downloads with the country and city, the kind of device and the browser, an estimated reading time per page, and a short code on every download. It names a person only when you typed their email address for that link. It is off unless you turn it on, only you see it, and our terms require you to tell the people you send it to.

Are files sent with Nemi encrypted?

Yes, in transit and at rest: every request travels over TLS, and files are encrypted with AES-256 by our storage provider in Amsterdam. That protects copies of the data but does not make files unreadable to Nemi, because our servers read a file to preview, convert or zip it. Only a Vault is encrypted in your browser with a key we never hold.

What happens when a share link expires?

The link stops working and the file stays in your workspace. For 30 days afterwards the recipient sees that it has expired, with a button to ask you to resend it, which lands in your notifications.

Where the numbers come from

  • Plan limits: largest file, link expiry, monthly upload volume: lib/pricing-plans.ts (PLANS)
  • Which expiry choices each plan offers: lib/share-link-options.ts (getShareExpiryOptions)
  • Large uploads sent in pieces: lib/storage/wasabi.ts (MULTIPART_THRESHOLD, MULTIPART_PART_SIZE)
  • How long an interrupted upload can be resumed: lib/resumable-uploads.ts (RESUME_RECORD_TTL_MS)
  • The share panel and its labels: components/action-views/ShareViewV2.tsx
  • What a recipient sees: /help/sharing/passwords-expiry-and-limits
  • Where files are stored and how they are protected: /security

Read next

Use the thing we write about.

Files, docs, sheets, photos, calendar and meetings in one account.