Secure file sharing for clinics & medical practices

Patient documents, sealed end-to-end

Health data is the most sensitive category of personal data there is. GCN.ONE encrypts medical documents in the browser before upload, so referral letters, lab results and imaging reports travel and rest as ciphertext we cannot read - and disappear automatically when the transfer window closes.

Send a file now - no signup form See pricing
Health data deserves better than email and consumer file senders

Special-category data under the GDPR demands stronger safeguards than a plain email attachment or an ad-funded consumer file service can offer. Yet that is how discharge letters and lab results routinely travel today - readable by every system in between.

The safest provider is one that couldn't read patient data even if compelled to. With client-side encryption, confidentiality stops being a promise in a privacy policy and becomes a property of the system.

How it works in a practice
1
Encrypt at the point of care
Documents are encrypted in the browser on your machine before upload. Keys never reach our servers - there is nothing readable on our side at any point.
2
Deliver to patients or colleagues
Patients and referring colleagues receive a secure link and decrypt locally - no account or software needed on their side. You're notified when documents are collected.
3
Let it expire
Transfers expire automatically and the encrypted data is permanently deleted - no archive, no backup, no forgotten copies of patient data accumulating with a third party.
Aligned with how health data must be handled
Structurally confidential
Zero-knowledge, end-to-end encryption: we cannot access patient documents - not for support, not under pressure. There is no master key to misuse.
Data minimisation, automated
Automatic expiry with permanent deletion builds storage limitation into the workflow instead of leaving it to periodic clean-ups.
Accountable by design
Delivery notifications and a tamper-evident, publicly anchored audit trail document that a transfer happened - without exposing what was inside.
European, and only European
The systems that hold your data run inside the EU, under EU jurisdiction. The single third-country leg is payment processing - covered by standard contractual clauses, and it never touches file content. No patient data leaves the EU for your DPO to assess.
Documented delivery, when it matters

When a practice must show that records were provided - to a patient exercising their right of access, or to a specialist ahead of a procedure - a signed delivery certificate records what was delivered, to whom, and when, verifiable independently at our public Verify page.

The underlying audit log is tamper-evident and publicly anchored: the record of the delivery cannot be silently rewritten afterwards, by us or anyone else.

Where this fits your GDPR obligations

GCN.ONE was built to GDPR standards from the ground up and runs entirely under EU jurisdiction. To be precise about the boundary: file contents, filenames and messages are encrypted client-side and unreadable to us; transfer metadata (sender, recipient, timestamps, sizes) is processed to operate the service. Your organisation remains the controller for its use of the service - we support that role with a DPA rather than claiming compliance on your behalf.

Request our Data Processing Agreement (DPA)

Frequently asked questions

The platform is built to GDPR standards on EU infrastructure, and its core design - client-side encryption, automatic deletion, minimal metadata - maps directly onto GDPR principles like integrity, confidentiality and storage limitation. Compliance of a processing activity is always assessed by the controller: we support that assessment with a DPA and full technical documentation.

Not the documents. File contents, filenames and messages are encrypted in your browser before upload and we hold no keys. What our servers necessarily process is transfer metadata: who sent to whom, when, and how large the encrypted payload was. We state this openly because a provider that claims to see nothing at all isn't being straight with you.

No. Patients open a secure link in their browser; decryption happens locally on their device. No account is required to receive documents.

They expire on schedule and the encrypted data is permanently deleted - no archive, no backup, no residual copy. If a patient misses the window, you simply send again.
See the workflow with a test document
Try a first encrypted transfer with a non-sensitive file - a temporary account, gone in 3 days.