Send your attachments and sensitive files
completely securely

Canal256 is a B2B file-sharing platform designed for SMEs, freelancers, and regulated professions,
for whom data confidentiality is not an option, but a legal obligation.

In a context of constant cyber-insecurity, the GDPR requires companies to guarantee the confidentiality of their clients' data under penalty of heavy fines. In the event of a leak, it is up to you to prove that you had implemented the necessary tools. Today, some insurance companies refuse to compensate businesses for "gross negligence" if they use consumer-grade tools.

1. The email attachment trap

Email is the #1 tool for professionals, but it accounts for 90% of cyberattacks. Sending an attachment is like sending a postcard: anyone along the way can read it. Furthermore, a sent document "sleeps" indefinitely in vulnerable inboxes.

The Canal256 solution: We replace the attachment with a secure, ephemeral, and encrypted link. Once the document is retrieved, no trace can be exploited by a hacker.

2. The illusion of American giants (WeTransfer, Dropbox, Google Drive)

These mass platforms store billions of data points, making them prime targets for hackers (especially via highly realistic AI-generated phishing emails). Moreover, being subject to the US CLOUD Act, American authorities can legally access your documents, instantly breaching the professional secrecy you owe to your clients.

Canal256 is not just another mainstream platform. It is a dedicated, sovereign vault under your total control.

  • End-to-End Encryption: Your files are encrypted from the moment they leave your computer until they are received.
  • Zero-Knowledge Technology: We provide the technology, but we do not have the keys. Even we are technically incapable of reading or knowing the contents of your documents.
  • 100% Sovereign Hosting: Your data is stored in Europe on servers protected from the US CLOUD Act, fully compliant with the GDPR.

1. Login (Entering the vault room)
The analogy: Imagine that your password is not a simple key you hand to the teller, but a complex blueprint to forge a unique key that only you possess. The tech: When users enter their password, it is never sent as-is to the server. The web browser uses an ultra-secure hashing algorithm called Argon2 (the strongest standard currently resistant to supercomputer attacks). This algorithm takes the password and "kneads" it thousands of times to derive a unique cryptographic footprint. The server verifies this footprint without ever knowing the original password.

2. Key generation (Forging the locks)
The analogy: Before sending a document, a custom armored box and a tamper-proof lock must be prepared. The tech: Once logged in, the browser locally generates a set of cryptographic keys. The platform uses a combination of asymmetric cryptography (a public key to close the padlock, a private key to open it) and symmetric cryptography (a unique key randomly generated on the fly to lock the file itself).

3. Client-side encryption (Sealing the box)
The analogy: This is the principle of "Zero-Knowledge". You place your document in a safe, lock it yourself in your own office, and hand the sealed safe to the courier. The courier (BLWorks servers) never has access to the contents. The tech: This is the most critical step. The moment the user selects their file, everything happens in their own web browser. The file is locally encrypted using the AES-256 algorithm (Advanced Encryption Standard), the same standard used by governments, militaries, and banks. The original document is transformed into a garbled string of indecipherable characters. Only this scrambled, locked file is then sent over the Internet to the storage servers.

4. Dispatch to the recipient (Dual-channel delivery)
The analogy: You send the locked safe via a standard courier, but you entrust the opening code to a completely different, independent messenger. If a thief intercepts the safe, they don't have the code. If they intercept the code, they don't have the safe. The tech: This is known as Out-of-Band authentication.

  • Channel 1 (Email): The recipient receives a standard email containing a unique, ephemeral, and random link. This link allows them to download the locked file (which remains incomprehensible).
  • Channel 2 (SMS): The system generates a one-time PIN code and sends it to the recipient's mobile phone via the cellular network. The key required to unlock the AES file is protected by this PIN.

5. Reception and opening (Final decryption)
The analogy: The recipient places the safe on their table, receives the code on their phone, and opens the door themselves to retrieve the intact document. The tech: The recipient clicks on the link and lands on a secure web page. The platform asks for the PIN code received via SMS. Once the code is entered, the cryptographic key is released. The recipient's web browser then uses this key to perform the reverse operation: it decrypts the AES-256 algorithm locally, on the recipient's computer. The file becomes readable again, and the download begins. Once the operation is complete, according to the defined rules (e.g., valid for a single download or for 24 hours), the safe, link, and keys are permanently destroyed, leaving no exploitable trace on the servers.

Behind Canal256, there is no opaque multinational or faceless automated servers. There is BLWorks: a human-sized, agile, and passionate team, founded by Jeanne Fichoux and Baudouin Lamourère.
Based in Seville (Spain) since 2006, we design custom web and cybersecurity solutions. Our philosophy is built on strong values:

  • Historical Trust: With over 25 years of technical expertise, our greatest pride is the loyalty of our clients, the majority of whom have trusted us for over 15 years.
  • A Spirit of Craftsmanship: We develop our own tools with immense attention to detail, rigorous ethics, and constant proactivity to stay ahead of security threats.
  • Unmatched Service Level: We believe premium security requires premium support. We offer total responsiveness, rare flexibility, and direct human availability to assist you every day.

Maximum Security vs Common Practices

Feature Classic Email US Giants (Dropbox, WeTransfer...) Canal256
End-to-End Encryption No ⚠️ Rarely (or they hold the keys) Yes
Zero-Knowledge Philosophy No No (Analyzed by their AIs) Yes
CLOUD Act Immunity (USA) No No Yes (100% European)
Zero trace post-download No (Remains on servers) ⚠️ Variable Yes (Ephemeral link)
GDPR Compliance & Insurance High Risk ⚠️ Legal grey area Fully compliant