How to send large files to clients securely
A practical method for handing over big client files: what to lock down, how long the link should live, and why the download page matters more than you think.
There is a specific moment in every project that nobody designs: the handover. The work is finished, the invoice is going out, and the last thing the client actually experiences is a link.
Most of us have spent about zero minutes thinking about that link, and it does more work than the case study will.
Here is the method I would use, in the order the decisions matter.
1. Decide whether it needs to be a file at all
Start here, because it removes the problem entirely for a large share of what gets sent.
If the client will read it — a proposal, a report, a deck, a brochure, a set of guidelines — it does not need to be a file. A link opens instantly on a phone, cannot bounce off a mail server, can be updated without a resend, and tells you when it was read. Files are a format for keeping things. Links are a format for showing them, and most handovers are showing.
If the client will use it — masters, source files, a photo library, an editable deliverable — it is a file, and the rest of this applies.
Being straight about which one you are doing saves an extraordinary amount of faff. There is no reason a 90 MB PDF proposal should ever be a download.
2. Shrink it before you shop for a bigger pipe
Before you go looking for a service that handles 20 GB, spend two minutes on why it is 20 GB.
In my experience the answer is usually one of: an uncompressed master where a review copy was wanted, 45-megapixel photography dropped straight into a layout, three near-identical exports of the same file, or a folder that has silently accumulated everything from the project since March.
Send what they need. Keep the rest available on request. A 3 GB delivery is easier for both of you than a 20 GB one and there is rarely any information lost.
3. Pick the mechanism by what the file is worth
| The file is | Send it | Because |
|---|---|---|
| Not sensitive, one-off | Any free transfer service | Nothing to protect; do not overthink it |
| Client work with commercial detail | A controlled link — password, expiry, receipt | You need to be able to withdraw it |
| Something they will collaborate on | A shared folder | Handover is not the job; access is |
| Enormous, and time-critical | An accelerated transfer service | You are paying for throughput, correctly |
Most agency handovers are row two, and most agencies do them with row one.
4. Lock down four things, not one
“Secure” turns into a mush of encryption talk very quickly. Four concrete controls do nearly all the useful work.
A password, sent separately. The link is a bearer key — anyone holding it can download, including everyone the email gets forwarded to. A password fixes that in one step, and it only works if it arrives by a different route. Text it. Say it on the call. Emailing it directly under the link is theatre.
An expiry you chose. One to two weeks fits how client work actually happens. Files that sit indefinitely become a slow leak; files that expire in three days become a support ticket the week your contact is in Portugal.
A recall button. You will send the wrong version at some point. Everyone does. The question is whether you fix it with a click or with an apology.
A record of who collected it. Not a view count. A name and a time. This ends the single most pointless message in client services — “did you get it?” — and it tells you the handover landed before you raise the invoice.
Notice that only one of those four is about security. The other three are about keeping control after you press send — which is the part most tools charge for and most people never check.
5. Now the part that is not about security at all
Everything above is table stakes. This is the bit that separates a delivery from a handover.
The download page is a moment in your client’s experience of you, and by default you are giving it away.
Picture it from their side. An email arrives from a service, not from you. They click through to a page carrying a logo that belongs to neither of you, with an advert on it if you are on a free plan. They download, and the page forgets they exist. Three days later the file quietly deletes itself and nobody is told.
Now the other version. The email comes from your domain. The page carries their brand — their logo, their colours, because it is their project. The link has your name in it. They collect it, and you get a note in your inbox saying who did and when.
Same file, same five minutes. One of those looks like the project ended. The other looks like it was delivered.
I am not claiming a branded download page wins accounts. I am claiming it is the last visible thing in a project you were paid well for, it costs nothing to claim, and giving it to a third party is a strange place to be modest.
6. Write the email like a handover
Whatever tool you use, this bit is free.
- Say what is in it, by name. “Final masters, both aspect ratios, plus the stills” beats “here you go”.
- Say what to do with it, if that is not obvious.
- Say how long the link lives, so the expiry is never a surprise.
- Say where the password came from — “password is in the text I just sent” — because nobody enjoys hunting for it.
- Say what happens next. The invoice, the next milestone, the sign-off you need.
Four lines. It converts a file drop into a completed piece of work, which is what they are paying for.
What we built
We put this into Transfers because we kept watching agencies do beautiful work and then hand it over through a consumer tool with someone else’s logo on it.
Sends of 10 GB on Agency and 25 GB on Agency Pro. An expiry from one to fourteen days, chosen per send. A password when you want one, download caps, instant revoke if you sent the wrong cut, and an email gate so the receipt names the person who collected it. The download page inherits the branding you already set for that client’s documents, so their work arrives in their livery — or in your agency’s, if it is your own pitch going out.
It is coming soon, included with the Agency plans rather than billed as a second subscription, alongside the documents, the white-label reader and the analytics.
I’m Richard, and I build Living Page — document and file delivery for agencies and freelancers. See how Transfers works, or compare the plans.
Frequently asked questions
- What is the most secure way to send a large file to a client?
- A link you control, with a password the client receives through a different channel, an expiry you set, and a record of who downloaded it. That combination beats an encrypted attachment, because it survives the thing attachments cannot survive: needing to withdraw or replace the file after you have sent it.
- How do I send a 20 GB file to a client?
- Not by email — every mail server will refuse it long before 20 GB. Use a transfer service with a ceiling above that, or a cloud drive with a shared link. If it is video, send a review copy rather than the master; a great many 20 GB transfers are an uncompressed export that nobody asked for and no client can play.
- Should I password-protect files I send to clients?
- For anything with commercial detail, unreleased work or personal data in it, yes — and send the password by a different route than the link. Text it, or say it on the call. Emailing the password in the same thread as the file is the most common way this protection gets quietly cancelled out.
- How long should a client download link last?
- Long enough to survive a holiday and short enough to not be lying around next year. One to two weeks suits most client work. Three days is too short in practice, because it expires while your contact is away and you end up re-uploading the whole thing to solve a diary problem.
- Is it unprofessional to send client work through WeTransfer?
- It is not unprofessional, it is just anonymous. The delivery arrives carrying a third party's branding rather than yours, which costs you the last visible moment of the project. Whether that matters depends on your rates and your competition, but it is a free impression to claim and most agencies leave it on the table.
Read next
- The Best WeTransfer Alternatives in 2026WeTransfer's free tier shrank and Portals was switched off. The alternatives worth moving to — and where WeTransfer is still the right answer.
- How Agencies Share Documents With Clients ProfessionallyA practical system for sending client work: what to send as a link, what to send as a file, and how to make it look like your agency rather than a tool.
- The FTP Alternative for Agencies in 2026FTP still moves files fine. What it does not do is anything a client-facing business needs — expiry, receipts, revoking access, or looking professional.