Hexiosec Transfer
Hexiosec Transfer is a secure file transfer solution with true end-to-end encryption, designed for organisations that need control and confidentiality when sharing sensitive data. It supports secure file transfer, forms, email and spaces, ensuring only intended recipients can ever access data.
Features
- Secure file transfer
- Secure forms
- Secure email
- Secure spaces
- True end-to-end encryption
- Built, maintained and hosted in the UK
- Outlook add-in
Benefits
- Send files securely
- Request form data securely
- Send emails securely
- Collaborate with others securely
- No one else can access your data, not even us
- Maintain control of your data sovereignty
- Send files as easily as attachments from Outlook
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 8 3 2 3 7 9 6 4 2 0 9 0 3 5
Contact
HEXIOSEC LIMITED
Rob Wright
Telephone: 01242474970
Email: frameworks@hexiosec.com
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Content Sharing and Collaboration Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- N/A
- System requirements
- Available via your browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Usually within 4 hours during office hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support is provided during office hours via email and phone. This is triaged by a Product Support Specialist, who will either resolve the query themselves or engage one of our engineering team as required.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Every new organisation will be provided with a video call and demonstration of Hexiosec Transfer so they can easily set up and start using the service. We help users start using our service by providing comprehensive online user documentation through our support portal and documentation site. This includes detailed guides on setup, secure file sharing, and API integration. We also offer responsive online support via email and in-app help during UK business hours, with typical response times within 4 hours.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- No user data is held, with the exception of any data transfers, which will remain accessible for up to 28 days (as specified by the user, the same as during the contract).
- End-of-contract process
- At the end of the contract any data transfers will remain accessible for up to 28 days as specified by the user (the same as during the contract).
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- N/A
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
Hexiosec Transfer provides a REST API for secure file operations and user management. Users can set up the service by authenticating via OpenID Connect (e.g., Microsoft Entra ID or Google Workspace) and generating an API key from an authenticated session. API calls require either a valid session cookie or API key header.
Through the API, users can manage their own profiles, transfer files, and perform tenant-scoped tasks based on assigned roles and groups. Changes such as resource updates or configuration adjustments are allowed only if the user has the necessary permissions. All interactions are logged for audit and compliance.
Limitations include strict role-based access control, meaning low-privilege users have limited capabilities (often read-only). API keys cannot be created without prior authentication and appropriate privileges. Requests must meet validation rules; invalid calls return errors. MFA may be enforced by the tenant’s identity provider.
Documentation is available in HTML and PDF formats, with additional internal resources. There are no limitations to the API, however client integrations will have to implement the encrypt/decrypt interface as is required for end-to-end encryption. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Organisations can apply their own branding to the Hexiosec Transfer service to give confidence to recipients. Authorised users within the organisation can configure branding customisations, and Hexiosec will assist with these customisations. Optional security features can be enforced on a user or group level, via a discussion with our support team.
Scaling
- Independence of resources
- Hexiosec Transfer uses scalable cloud services so there are no practical limitations through demand. The service is monitored during office hours to ensure this is the case.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Users can see when their files were downloaded and by what IP address or what email address if selected. Users can see how many times their files have been downloaded. Administrators can see how many file transfers have been made and how many GB have been transferred.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- No user data is held by the service, with the exception of any data transfers (the purpose of the service). Users can access that data according to the policies they set up when creating the transfer. No other type of data export is applicable.
- Data export formats
- Other
- Other data export formats
- Original format they imported the data in.
- Data import formats
- Other
- Other data import formats
- Any file format can be sent via the service.
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We aim to provide continuous access to Hexiosec Transfer using high-availability infrastructure, but we do not guarantee a specific uptime level unless a separate SLA is agreed. Maintenance, updates, or unforeseen events may cause interruptions. Standard terms include email-based support during UK business hours, with no guaranteed response times unless covered by an SLA.
- Approach to resilience
- Available on request.
- Outage reporting
- Email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Hexiosec Transfer has been written as a secure file transfer capability by cyber security engineers with experience in developing crypt-key for the highest level of government security. For more information about Hexiosec Transfer, including how we restrict access in management interfaces and support channels, please ask for further information.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Hexiosec operates a single, coherent set of policies and processes aligned with ISO 27001 and NCSC Cyber Assessment Framework. Governance ensures security risk ownership at appropriate levels with documented roles and responsibilities. All employees, contractors, and third-party users must read and understand the Information Security Policy. Policies map to ISO 27001 controls and CAF objectives, supporting compliance and resilience. Risk management includes structured assessments, asset visibility through Hexiosec ASM, supply chain assurance, and defined incident response processes. Governance is reinforced by continuous improvement through regular reviews, audits, and updates, embedding security awareness and accountability across the organisation.
- Information security policies and processes
- Hexiosec follows a single, coherent set of policies and processes aligned with ISO 27001 and NCSC Cyber Assessment Framework objectives. Our Information Security Policy applies to all employees, contractors, and third-party users who interact with Hexiosec information. Policies map directly to ISO 27001 controls, ensuring compliance and resilience. Security risk ownership is embedded at appropriate levels with documented roles and responsibilities. Governance includes structured risk assessments, asset visibility through Hexiosec ASM, supply chain assurance, and defined incident response processes. Policies are enforced through continuous improvement, regular reviews, audits, and updates. All staff must read and understand the Information Security Policy, embedding security awareness and accountability across the organisation.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Hexiosec follows documented configuration and change management processes aligned with ISO 27001. All components are tracked through their lifecycle using formal records and audit trails to ensure accuracy and accountability. Changes are managed through structured reviews and approval workflows, with each change assessed for potential impact before implementation. This includes validation against established policies and documented controls to confirm compliance and minimise risk. Regular audits and continuous improvement cycles ensure that configuration baselines remain current and that all changes are properly recorded, authorised, and communicated across the organisation.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Hexiosec is an expert in vulnerability management. We maintain a vulnerability management plan that captures, triages, and prioritises issues based on severity and impact. Knowledge of public vulnerabilities is kept up to date through automated dependency advisories and external scanning of public-facing sites. Renovate is used for automated updates, ensuring timely remediation. Threat intelligence sources include CISA’s Known Exploited Vulnerability list and Exploit Prediction Scoring System (EPSS) data, adding real-world context to risk assessments. Combining severity, known exploits, and likelihood of active exploitation ensures critical vulnerabilities are addressed promptly while lower-severity items are managed effectively within development sprints.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Hexiosec’s incident management policy defines how vulnerabilities are escalated and communicated to relevant internal security stakeholders. Clear escalation to internal security teams ensures vulnerabilities are assessed quickly and addressed effectively, reducing the risk of delayed response. The policy also covers communication with affected customers in the event of a vulnerability or incident. Customers are notified promptly with appropriate guidance, helping them take protective action, reducing impact, and maintaining trust in Hexiosec’s services. This structured approach ensures timely reporting to internal teams and affected customers, supporting rapid containment and remediation.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Hexiosec has pre-defined processes for common security events as part of its incident management policy. The policy defines how vulnerabilities and incidents are escalated and communicated to relevant internal security stakeholders, ensuring rapid assessment and effective response. Users can report incidents through established communication channels defined in the policy, which include direct escalation to internal security teams. When an incident occurs, affected customers are informed promptly with appropriate guidance to help them take protective action and reduce impact. Incident reports are provided in line with the policy, ensuring clear communication and maintaining trust in Hexiosec’s services.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- You can book a live demo to see the platform in action or create a free account to try out the key functionality. Our team will walk you through the key features and help you get set up quickly.
- Link to free trial
- https://transfer.hexiosec.com/signin?register=true
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 9%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ba00785d-7c2f-403c-9759-0f8d8067aa6a
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Volunteering opportunities for staff
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-