An alternative to password-protected zips

Told that your zip files
can't be accepted?

FILE SHIPPER, large file transfer
More and more companies now refuse password-protected zip attachments. Most small businesses, though, have no IT department to hand the problem to. FILE SHIPPER needs no setup and no internal sign-off — you can use it for the very next file you send, and your recipient never creates an account.

No credit card · about a minute to sign up

That policy wasn't aimed at you.

The message usually arrives like this:

"Our security policy has changed, so we can no longer receive password-protected zip files."

It sounds abrupt, but it isn't your customer's own decision. It's the result of a shift that started with government bodies and spread through large enterprises — and it isn't going to reverse.

The difficulty is that the companies asked to adapt are mostly small ones with no IT department. There is nobody internal to ask, and files still have to go out tomorrow, and the day after.

This page sets out the options you can actually act on today.

Three reasons the practice was abandoned

Zipping a file with a password, emailing it, then emailing the password separately — a habit known in Japan as "PPAP" — came under review for three reasons.

Both halves travel the same road

The file and its password go through the same mail path. If you assume that path can be observed, both arrive together and the encryption stops meaning anything.

It defeats virus scanning

An encrypted zip can't be inspected by the security products on the receiving side. It has repeatedly been used as a way to walk malware past them.

A misdirected email cannot be recalled

Realising you used the wrong address doesn't bring the message back. Withholding the password is some comfort, but the file itself stays in the wrong hands.

So the practice costs real effort and doesn't protect the thing it was meant to protect. A customer refusing these attachments is being reasonable, not difficult.

What to do instead

The usual replacements each suit some situations better than others.

Alternatives to password-protected zip files, compared
OptionSuitsWatch out for
A cloud storage share linkInternal sharing, and long-running client relationshipsLinks are often left set to "anyone with the link". Shares accumulate and stop being managed by anyone.
A free file transfer servicePersonal, one-off exchangesThird-party ads appear on the download page. Worth checking whether that's a page you want a client to see.
A dedicated file sharing systemCompanies with an IT departmentSomeone has to deploy and run it. At a few people, that is often not realistic.
FILE SHIPPERSending and receiving files with customers generallyBuilt around per-recipient verification and automatic deletion. Nothing to deploy.

The easiest one to get wrong is the storage link. You can drop zip files entirely and still be worse off, if what replaced them is a link anyone who has it can open. What matters is that the sender decides who can receive the file.

Designed so the file reaches the named recipient, and nobody else.

A one-time code confirms who is downloading

Opening the link is not enough to reach the files. The recipient confirms their email address and passes one-time-code verification first. If the link is forwarded, it gets the new holder nowhere.

No password to send separately

Verification happens on our side, so there is no password to invent and no second email to send. The step of zipping things up disappears with it.

Your recipient signs up for nothing

Nobody has to be asked to register. They enter their email address and the one-time code they receive. The usual objection — that you'd be putting the client to trouble — never comes up.

Every file is malware-checked

Files are checked against known malware immediately on upload. Anything flagged is quarantined automatically, and share links already sent stop working at that moment. This runs on every plan, the free one included.

Files really do disappear on schedule

Once the retention period is up, the system deletes the files. The deletion time is shown on the recipient's screen too, so nobody is left wondering how long a copy sticks around.

You can stop a share after sending it

If you spot a mistake, the share can be stopped from your share history right away. Unlike an email, it can be taken back.

Personal information such as email addresses is encrypted with AES-256-GCM at rest, and the encryption keys are held in the key-management service of a Japanese provider (Sakura Internet), inside Japanese jurisdiction.

No internal sign-off, and nobody to escalate to.

  1. Create an account (about a minute)

    An email address is all it takes. No credit card.

  2. Pick the files and enter the recipients

    Upload exactly what you would have attached to the email.

  3. Email the link

    Your recipient verifies with a one-time code and downloads. There is no password to follow up with.

Tomorrow's first email can already work this way.

Wording you can send your customer as-is

A short note makes the change easier on the receiving end. Feel free to use this verbatim.

We have changed the way we send files.

Please follow the link below and enter the verification code sent to your email address. No account registration is required.

We will no longer be sending passwords separately.

Try it free first, then decide.

Free

¥0/ month

10GB per file · 10GB per month · 24-hour retention

One-time-code verification, automatic deletion and malware checking are all included on the free plan.

Ads are shown on the download page.

Start for free

If your only goal is to stop sending password-protected zips, the free plan already does it. Choose Business when you want the page your customer sees to look like your company.

Frequently asked questions

Does my customer have to register for anything?
No. The recipient enters their email address and the one-time code they receive, and that is the whole process.
We have no IT staff. Can we still use this?
Yes. There are no servers to configure and nothing to install — it all happens in the browser.
Can I set a password on a file?
Instead of a password, we confirm the recipient’s email address and verify them with a one-time code. That removes the need to invent a password and send it separately.
What if I notice a mistake after sending?
You can stop the share from your share history right away. After that, opening the link no longer allows a download.
How long are files kept?
You can choose 24 hours, 3 days or 1 week, and the system deletes the files automatically once that period is up (the free plan is fixed at 24 hours).
Our customer says they have "abolished PPAP". Is this the same thing?
Yes. PPAP is the name for the practice of sending a password-protected zip and then emailing the password separately. FILE SHIPPER does not use that practice, so it meets the requirement as-is.
Is the free plan less secure?
One-time-code verification, automatic deletion and malware checking work identically on every plan. The free plan shows ads on the download page and cannot use the branding features.

Change it with the very next file you send.

Creating an account takes about a minute, and needs no credit card.