Skip to main content
VaultFerry
← Home

Share files straight from the cloud storage you already own

VaultFerry connects to your own S3, Google Cloud Storage, or Azure Blob bucket and turns any file into a secure, expiring link — with password protection on the Pro and Business plans. The bytes travel directly from your bucket to whoever you send it to — they never pass through our servers.

By Lorenzo Piovesan · Updated

How it works

  1. Connect your bucket

    Add a storage connection with read access to your AWS S3, Google Cloud Storage, or Azure Blob container. Your credentials are encrypted with AES-256-GCM and decrypted in memory only, at the moment a link is minted.

  2. Pick a file and make a link

    Browse your bucket through one unified file view and turn any object into a share link. Set an expiry, add a password on the Pro and Business plans, and — on Business — cap how many times it can be downloaded.

  3. Your client downloads directly

    When they click, VaultFerry mints a fresh short-lived signed URL from your credentials and hands it straight to the browser. The file streams directly from your bucket to your client — we never see it.

Why share from your own storage

  • One bill: bytes move directly between your bucket and your client, so you pay your cloud provider once and never a per-gigabyte transfer surcharge on top.
  • One copy: your file is never duplicated into someone else's infrastructure, so there's no second place for it to leak from.
  • Your region, your rules: because the storage is yours, you decide where data physically lives — useful for residency and compliance commitments.
  • Your brand: on the Business plan, the public download page carries your logo and accent color instead of ours.

Frequently asked questions

Which cloud storage providers can I connect?
AWS S3, Google Cloud Storage, and Azure Blob Storage. S3-compatible providers that follow the S3 API generally work too, by pointing the connection at their endpoint.
Does my file ever pass through VaultFerry's servers?
No. We generate a short-lived signed URL from your credentials, and the browser fetches the file directly from your bucket. The bytes never touch our infrastructure, and we never store a second copy.
How are my cloud credentials protected?
They're encrypted at rest with AES-256-GCM and decrypted in memory only, at the instant a link is minted. They're never logged and never returned to the browser.
Can I password-protect and expire a link?
Every link on every plan has an expiry, and on the Pro and Business plans a link can also carry a bcrypt-hashed password. Download URLs are short-lived — at most five minutes after they're issued — and revoking a link stops any new URL from being minted for it.
Do I have to move my files into VaultFerry first?
No. That's the whole point — your files stay exactly where they are, in the bucket you already own. VaultFerry only adds the secure sharing layer on top.

Built for your work

See how VaultFerry fits law firms and professional services, creative agencies, and freelancers and solo consultants.

Get started free