The stack behind GetFileShare,
named plainly.
Our Security page covers the cryptography. This page covers the concrete services and providers GetFileShare actually runs on.
Application Layers
Next.js + React
The site you're reading is a Next.js/React app, served over TLS and split into direct-transfer, cloud-upload, and content pages.
NestJS on Node.js
A TypeScript backend built on NestJS handles the API, WebSocket signaling, and encrypted-chunk relay for direct transfers.
Socket.io + WebRTC
Direct E2E transfers negotiate a WebRTC data channel over Socket.io signaling, with our own coturn STUN/TURN server for NAT traversal. Connections that cannot find a direct route are relayed by it, as is the socket relay used for small transfers — in both cases carrying ciphertext rather than readable files.
Cloud & Hosting
Network Security
Cloudflare
DNS and network-level security sit in front of the origin server via Cloudflare — TLS termination, DDoS mitigation, and traffic filtering happen at the edge before a request ever reaches our infrastructure.
Object Storage
Cloudflare R2
Uploaded and shared files are stored in Cloudflare R2, an S3-compatible object store, accessed through the standard AWS S3 SDK and kept separate from the metadata database.
Database
MongoDB Atlas
Share records, expiry timers, and account metadata live in MongoDB Atlas, a managed database service reached over an authenticated, encrypted connection — never the file contents themselves.
Cloud & Hosting
Hetzner · Ubuntu
Application servers run on Hetzner Cloud infrastructure on Ubuntu Linux, with web and API traffic reaching them through Cloudflare rather than directly. The one exception is the STUN/TURN server: NAT traversal needs UDP and TCP ports a web proxy does not carry, so that host answers on the open internet by design.
What this setup does and does not mean
Every provider above is a well-established, independently operated service — we don't run our own database or object storage cluster. That gives us their infrastructure-level security and durability guarantees for the pieces they control.
It doesn't mean GetFileShare itself has been independently audited. We're a new service and run on a single application deployment rather than a multi-region, high-availability setup — see our About page for that context.
For how data is actually protected in transit and at rest — TLS, encryption, access rules — see the Security page; for how long data is kept and who can request it, see our Privacy Policy.