Beyond PPAP — Secure File Sharing
PPAP — sending a password-protected ZIP via email followed by the password in a separate email — has been widely used in Japan. However, it carries significant security risks. SecureMint offers a safer, simpler alternative.
What is PPAP?
- P — Send a Password-protected ZIP file
- P — Send the Password in a separate email
- A — Encrypt (Angou in Japanese)
- P — Protocol
* This practice was widespread in Japanese business, but the Cabinet Office announced its discontinuation in 2020.
Problems with PPAP
Password sent over the same channel
Both the ZIP file and password travel through the same email channel. An attacker who intercepts one can intercept both, rendering the protection meaningless.
Weak ZIP encryption
Standard ZIP encryption (ZipCrypto) is vulnerable to known-plaintext attacks. Even AES-256 ZIP encryption can be brute-forced if the password is weak.
Bypasses virus scanning
Encrypted ZIP files bypass email gateway virus scanning. Malware like Emotet has exploited this vector to spread through corporate networks.
No audit trail
There is no way to track who downloaded the file or how many times it was accessed. Data leaks go undetected.
How SecureMint Solves This
End-to-End Encryption
AES-256-GCM encryption runs entirely in your browser. The decryption key is stored in the URL fragment (#), which is never sent to the server.
Separate key delivery
Encrypted files travel through the server; the decryption key is embedded in the URL. The file and key travel through separate channels, solving PPAP's fundamental flaw.
Auto-expiry & download limits
Set expiry times and download limits on every link. Expired files are automatically deleted.
Download logs (Pro)
Track who downloaded and when. Detect potential data leaks early.
Comparison
| Feature | PPAP | SecureMint |
|---|---|---|
| Encryption | ZipCrypto / AES-ZIP | AES-256-GCM |
| Key delivery | Same email channel | URL fragment (separate) |
| Virus scanning | Bypassed | Not affected |
| Expiry control | None | 1 hour to 30 days |
| Download limit | None | Customizable |
| Audit trail | None | Download logs (Pro) |
| Software needed | ZIP extractor | Browser only |
Replace PPAP in 3 Steps
Drag & drop your file
Drop your file on the Secure File Sharing page. It's encrypted with AES-256 right in your browser.
Copy the share link
A share link is generated after encryption. The decryption key is embedded in the URL and never sent to the server.
Send the link to your recipient
Send the link via email or chat. Recipients just click to download — no app installation needed.
Free to try, no registration required