Skip to main content

SGraph Send

Zero-knowledge encrypted file sharing. The server never sees your files.

send.sgraph.ai | Currently in private beta


How It Works

A complete walkthrough of the upload-to-download flow. The server never sees your plaintext, your file name, or your decryption key at any point.

Step 1: Select a file

Drop a file into the upload zone or click to browse. No account required.

Upload page with drop zone and test files section

Step 2: Encrypt and upload

Your file is shown with its size. Click "Encrypt & Upload" -- encryption happens entirely in your browser using AES-256-GCM before anything leaves your device.

File selected, showing test-data.json ready for encryption

Step 3: Share the link and key separately

After upload, you get two things: a download link and a decryption key, each with its own copy button. The security tip reminds you to share these through different channels. The transparency panel proves what was stored (encrypted file, size) and what was NOT stored (file name, decryption key, raw IP).

File sent with download link, decryption key, and transparency panel

Step 4: Recipient opens the download link

The recipient sees the encrypted file metadata and a field to paste the decryption key. The server never sees the key -- it is shared out-of-band between sender and recipient.

Download page showing encrypted file and decryption key input

Step 5: File decrypted locally

The file is decrypted in the recipient's browser. The transparency panel confirms: file content was encrypted (the server could not read it), the decryption key was NOT stored (only you have it), and the file name was never sent to the server.

Download confirmation with transparency panel showing zero-knowledge proof

Step 6: Original file, intact

The downloaded file is identical to the original. The server only ever had encrypted bytes -- it could not read, modify, or inspect the contents at any point.

Original test-data.json opened in text editor, content intact

Why This Exists

Most file sharing services require you to trust the provider with your unencrypted data. SGraph Send takes a different approach: the server is architecturally unable to read what you share.

  • No accounts required
  • No tracking, no cookies, no local storage
  • The server stores only encrypted bytes it cannot decrypt
  • IP addresses are hashed with a daily rotating salt — stored as one-way hashes, never in the clear

Architecture

Component Detail
Two Lambda functions User-facing (transfers, health, static UI) and Admin (tokens, stats)
Endpoints Lambda Function URLs — direct HTTPS, no API Gateway
Storage S3 via Memory-FS abstraction (pluggable: memory, disk, S3)
Encryption Web Crypto API, AES-256-GCM, client-side only
Frontend IFD Web Components — vanilla JS, zero framework dependencies
Backend FastAPI + Mangum via osbot-fast-api
Type system Type_Safe from osbot-utils (no Pydantic)

Three UIs serve different audiences: the user workflow, power user tools, and an admin console.


The Agentic Team

This project is built and maintained by a 15-role AI agentic team coordinated through Claude Code, with a human stakeholder (Dinis Cruz) providing direction through written briefs.

Roles: Architect, Dev, QA, DevOps, AppSec, GRC, DPO, Advocate, Sherpa, Ambassador, Journalist, Historian, Cartographer, Librarian, and Conductor.

Each role produces structured review documents, tracks decisions, and operates within defined boundaries. The team's work is fully visible in the repo:


Key Documents

Document Path
Project brief library/docs/_to_process/project - Secure Send Service brief.md
Phase roadmap library/roadmap/phases/v0.1.1__phase-overview.md
Agent guidance .claude/CLAUDE.md
Development guides library/guides/
Issue tracking .issues/

Project Structure

sgraph_ai_app_send/              # Application code
  lambda__admin/                 # Admin Lambda (FastAPI + Mangum)
  lambda__user/                  # User Lambda (FastAPI + Mangum)

sgraph_ai_app_send__ui__admin/   # Admin UI (static assets)
sgraph_ai_app_send__ui__user/    # User UI (static assets)

tests/unit/                      # Tests (no mocks, real in-memory stack)

.issues/                         # File-based issue tracking
library/                         # Specs, guides, roadmap, dependencies
team/                            # Agentic team roles, reviews, briefs

Development

Requires Python 3.12.

# Install dependencies
poetry install

# Run tests
poetry run pytest tests/unit/ -v

All tests use real implementations with an in-memory storage backend. No mocks, no patches. The full stack starts in under 3 seconds.


Stack

Layer Technology
Runtime Python 3.12 / arm64
Web framework FastAPI via osbot-fast-api / osbot-fast-api-serverless
Lambda adapter Mangum
Storage Memory-FS (pluggable: memory, disk, S3)
AWS operations osbot-aws
Type system Type_Safe (osbot-utils)
Frontend Vanilla JS + Web Components (IFD)
Encryption Web Crypto API (AES-256-GCM)
Testing pytest, in-memory stack, no mocks
CI/CD GitHub Actions (test, tag, deploy)

Status

v0.2.21 — S3 persistent storage live. End-to-end encryption working. CI/CD pipeline deploying automatically. 56 tests passing. Private beta phase.


License

Apache 2.0

Metadata

Release files for sgraph-ai-app-send 0.33.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sgraph-ai-app-send 0.33.0
File Size Uploaded
sgraph_ai_app_send-0.33.0.tar.gz 4.9 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for sgraph-ai-app-send 0.33.0
File Interpreter ABI Platform
sgraph_ai_app_send-0.33.0-py3-none-any.whl Python 3 none any Details

Total release size: 10.5 MB

Release files / sgraph_ai_app_send-0.33.0.tar.gz

Download URL sgraph_ai_app_send-0.33.0.tar.gz
Size 4.9 MB
Tags Source
SHA-256 checksum
How to use checksums
2d9e83a31bd844e10ca067f2fec9390c90c37722690e151b4975a038d31c7898
BLAKE2b-256 checksum
How to use checksums
05dec23d3e618ec07cfff9b4c05715e51d962b67e062fff35f37dbfbfb3c1a6f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.2.0 CPython/3.12.13

Release files / sgraph_ai_app_send-0.33.0-py3-none-any.whl

Download URL sgraph_ai_app_send-0.33.0-py3-none-any.whl
Size 5.6 MB
Tags Python 3
SHA-256 checksum
How to use checksums
056fe8ab2e0f6fe7436fe0d3598d4da6dfc9b4acfca4f4bf22148d5eecaffde6
BLAKE2b-256 checksum
How to use checksums
4f0dd88f5b44e1784bbaefff64133db36591a50bdae237414675757bdccadbcc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.2.0 CPython/3.12.13

Release history Release notifications | RSS feed

This release

0.33.0 This release

2 release files

0.31.0

2 release files

0.30.0

2 release files

0.29.0

2 release files

0.28.0

2 release files

0.25.0

2 release files

0.24.0

2 release files

0.23.0

2 release files

0.22.0

2 release files

0.21.0

2 release files

0.20.0

2 release files

0.19.0

2 release files

0.18.0

2 release files

0.17.0

2 release files

0.16.0

2 release files

0.15.0

2 release files

0.14.0

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page