# Boita: full site content > Large file transfer for anyone who moves a lot of data and has hit the bottleneck: a fast path that uses your whole line over any distance, resumes where it stopped and verifies every byte, with links, portals and automation around it. Flat plans, no per-GB fees. Built in India for labs, hospitals, engineers, studios, data teams and anyone with terabytes to move. Boita is a large-file transfer and storage workspace built in India by Aariko Systems (Pune). It moves hundreds of gigabytes to tens of terabytes per job with an accelerated transfer engine over UDP that holds the line rate regardless of distance, runs big jobs as parallel sessions (45 Mbps per session; 10 on Pro, 50 on Studio, 100 or more on Enterprise), resumes after any interruption and records a checksum for every file. Who it is for: Boita is not for any specific industry. It is for everyone who moves a lot of data and is facing a bottleneck — life sciences and genomics, healthcare imaging, engineering/CAD/BIM, architecture and construction, drone/satellite/geospatial, ML and data teams, backup/DR and NAS, research labs, legal and e-discovery, game development, VFX and post-production, broadcast and OTT, advertising and film, print and packaging, photography, audio. The problem is the same everywhere: large data over ordinary internet is slow, stalls, restarts from zero, and FTP or consumer tools cap out. Positioning: the ease of a consumer file-sharing link (recipients need no account and nothing to install) with the mechanics of an enterprise transfer suite (UDP acceleration, parallel sessions, resume, checksums, watch folders, a headless agent and CLI, upload portals, review and approval, automations, an API with SDKs), on flat plans with no per-GB transfer fees, no download charges and no per-seat pricing model. Status: sign-up is open at https://app.boita.io/signup (Free, no card); a guided pilot is available on request via /waitlist or /contact. Features are marked live (in the product today) or coming (committed roadmap, or built and waiting on an outside approval). Prices: Free ₹0 (10 GB), Pro ₹499/month (1 TB), Studio ₹7,999/month (10 TB), Enterprise custom; shown in USD, EUR, GBP, AED, SGD or AUD outside India. Currencies: plans are billed in INR in India (GST invoices) and shown in USD, EUR, GBP, AED, SGD, AUD elsewhere; the pricing page detects the visitor region and offers a manual switch. Machine-readable: this file, https://boita.io/llms-full.txt, https://boita.io/sitemap.xml, the OpenAPI 3.1 description at https://boita.io/openapi.json (also served live at https://api.boita.io/v1/openapi.json), the machine-readable changelog at https://boita.io/changelog.json, and JSON-LD (Organization, SoftwareApplication with offers, WebPage, BreadcrumbList, FAQPage, HowTo, Article, DefinedTermSet) on every page. ## How it works URL: https://boita.io/#how 1. **Point Boita at the data.** Drop files in the browser or the desktop app, point a watch folder at a folder that fills up, run the CLI from a script, or send a portal link so someone else can send to you. 2. **The fast path moves it.** The transfer runs as parallel sessions over UDP-based acceleration that holds your line rate whatever the distance. Drop the network and it resumes where it stopped. 3. **It lands, verified, and everyone knows.** Every file arrives with a checksum recorded on the server. Recipients open a page with nothing to install, you see who downloaded what, and rules, webhooks and chat notifications tell the rest of your systems. Mechanisms (each is a true statement about the product; no invented statistics): - **Uses the whole line.** UDP-based acceleration with its own rate control. Throughput climbs once and holds, instead of collapsing at every lost packet the way TCP does — whatever the distance. - **Parallel sessions.** A single big job runs as several sessions at once — 45 Mbps each, 10 on Pro, 50 on Studio, 100 or more on Enterprise — so one transfer can use the whole connection. - **Resumes, never restarts.** Transfers checkpoint as they run. A dropped link, a closed laptop or a reboot picks up where it stopped; completed files are never re-sent. - **Verifies every byte.** A checksum is recorded for every file at transfer time and shown on the receipt, so a delivery is checked rather than assumed. Transfer paths: the fast path (UDP-based acceleration, parallel sessions, resume) is first choice; if a network blocks UDP, Boita falls back to an HTTPS path automatically (slower, still resumable and encrypted, and the app shows which path is in use); recipients and portal uploaders use a browser path with nothing to install, and the page offers the free app for full speed on very large sends. Plan speed arithmetic: throughput = min(45 Mbps × sessions, your line rate). Free 2 sessions at 10 Mbps = 20 Mbps; Pro 10 × 45 = 450 Mbps; Studio 50 × 45 = 2.25 Gbps; Enterprise 100+ × 45 = 4.5 Gbps and above. Time = size / throughput (decimal units): 100 GB on Pro ≈ 30 min; 1 TB on Pro ≈ 4.9 h; 1 TB on Studio over a 1 Gbps line ≈ 2.2 h (line-limited); 10 TB on Enterprise over a 10 Gbps line ≈ 5 h (plan-limited). ## Product pillars ### Send URL: https://boita.io/send Pick files or folders, set the rules, send. Recipients get a page that works without an account and nothing to install, and you see exactly who opened and downloaded what. - [Live] **Expiry, password and download limits on every link.** Every link has an expiry. Add a password, cap the number of downloads, and get an email when someone downloads. - [Live] **Send by email from Boita.** Address recipients directly with a message; they receive the link and the file list from us. - [Live] **Recipient page, no account, nothing to install.** File list, sizes and a cover from the first preview on a clean page. Recipients download in the browser with nothing to install (the standard HTTPS path), or at full speed with resume through the free Boita app. They can pick only the files they need. - [Live] **Sender dashboard.** Views and downloads per file and per recipient, so you know a delivery landed. - [Live] **Expiry reminders, extend and resend.** A reminder before a link expires; extend it or resend with one click. - [Live] **Instant revocation.** Download tokens are minted per download and expire in minutes, so revoking a link stops new and resumed transfers immediately. - [Live] **Delivery receipts.** Each invited recipient gets their own link, so the receipt shows who viewed, who downloaded, when, from which client, with the integrity check on every completed download. Exportable as a PDF for your client (Studio and above). - [Live] **Sender-side encrypted delivery.** Upload with a passphrase and the files are encrypted on your machine before they leave it; they sit encrypted in the workspace and decrypt on the recipient's computer as they arrive. Boita never holds the passphrase — without it, a download is just an envelope. - [Live] **Recipient verification.** Ask recipients to confirm their email with a one-time code before anything about the files is shown. The receipt then names who downloaded, not just that someone did. Pro and above. - [Live] **Comments on share pages.** Recipients leave a note on a file or on the whole delivery, right on the share page. You get an email and a push, reply from Shares or the phone, and mark it resolved — no review-tool licence. - [Live] **Embargoed and view-only deliveries.** Set an opening time and the page shows a countdown until then — nothing is served early. View-only links let recipients look at previews and the player without a download button. - [Live] **Got it, Thanks, Something is wrong.** One button for the recipient to acknowledge a delivery; the answer lands on the receipt and in your activity feed, so you stop asking "did you get it?". - [Live] **Defaults, templates and an address book.** Set the expiry, password and notification rules once as the workspace default or as named templates. Recipients and groups live in an address book, so a weekly delivery is two clicks. Bulk extend, re-notify or revoke from the list. - [Live] **Delivery note as PDF.** A one-page note with the file list, sizes, checksums and the message, for the recipient or your own records. Delivery pages also unfurl as a proper card when the link is pasted into WhatsApp, Slack or iMessage. - [Live] **Recipients on WhatsApp.** Add a recipient by WhatsApp number and send them their personal link with the message already written. Their WhatsApp replies show up as comments on the delivery. - [Live] **Deliveries to me.** Recipients type their email once at app.boita.io/me and see every live delivery addressed to them, from any sender on Boita, with the personal link and how long each has left. - [Live] **Emails from your own domain.** Delivery notices arrive from delivery@mail.yourcompany.com, signed for your domain so they land in the inbox; replies go to whoever sent the delivery. Studio and above. - [Live] **Watermarked deliveries.** Tick Watermark on a link and every preview, video and image the recipient sees or downloads carries their name and yours. Studio and above; an invisible per-recipient mark on video is on Enterprise. - [Live] **Send files back.** Recipients can send files back from any delivery page, straight into a Replies folder in your workspace. ### Drive URL: https://boita.io/drive Browse, organise and search your workspace from the web. Every file carries its size, uploader and checksum; numbered sets show as one row; moves of hundreds of files are verified before anything is deleted; storage usage is always one glance away. - [Live] **Folders, rename, move, search.** Everyday file management across the whole workspace, with name search that walks every folder. - [Live] **Trash with a recovery window.** Deleted files and folders sit in the trash before the retention worker purges them for good. - [Live] **File details with checksums.** Size, type, modified date, uploader and the server-side checksum recorded at transfer time. - [Live] **Storage usage per workspace.** A usage bar on every page, email alerts as you approach your quota, and no surprise overage. - [Live] **Members, roles and invitations.** Owner, admin and member roles; invite by email; seats counted per plan. - [Live] **Previews you can switch off.** Thumbnails for images and PDFs and a still from every video, rendered on our servers after upload and shown in Files and on share pages without downloading the original. Previews can be turned off per link or per folder for material that must never be rendered (patient data, unreleased work). - [Live] **Folder permissions and groups.** View, download, upload or manage rights per folder, per member or group. A member restricted to one client folder sees nothing else. Studio and above. - [Live] **Your own buckets, two-way.** Connect S3-compatible, Google Cloud Storage and Azure Blob buckets: import a folder, deliver into a bucket, or keep a workspace folder and a bucket in continuous sync — unchanged objects are never copied twice and deletes stay opt-in. The transfer runs on our servers, not through your laptop. Two of the common personal cloud drives connect the same way today; the other two follow. - [Live] **Activity feed and daily digest.** Every upload, link, portal upload and member change in one filterable feed, and one morning email with the last 24 hours across your workspaces. - [Live] **Numbered file sets as one row.** tile_0001 to tile_2400, frame_0001 to frame_0240, scan_001 to scan_512: a numbered set is one row with the range, count, size and a gap warning — in Files, on the phone and on share pages. Expand it when you need a single file; download or share the whole set in one go. - [Live] **Version history.** When an upload replaces a file, the previous copy is kept for the retention window; restore or delete any version from Files. Admins set trash and version retention. - [Live] **Move, copy and rename at scale.** Hundreds of files at once, sequence-aware, previewed first and verified before anything is deleted. Up to 500 GB per job on Pro and above (250 GB on Free). Favourites, pinned folders, recents and copyable deep links. - [Live] **Media and file details.** Codec, resolution, frame rate, duration and audio layout on every video and audio file; size, type, uploader and checksum on everything. Delivery specs per folder or portal flag off-spec files on arrival. - [Live] **Archive tier with a manifest.** Move finished folders to cold storage with a manifest and restore on demand; nothing is removed that was not copied and verified first. Studio and above; Enterprise adds retention rules per folder. - [Coming] **Verifiable archive on decentralised storage (on request).** An optional cold tier with proof-of-storage on decentralised storage, restorable on demand. India-residency workspaces get a domestic archive instead. Never used for the transfer path. ### Portals URL: https://boita.io/portals Request links let outsiders send files straight into a folder in your workspace, with a form so the right details arrive with the files. Each upload lands in its own inbox folder and both sides get an email when it completes. - [Live] **Request links into any folder.** Create a portal link, send it to a supplier, a lab, a client or a field team; their upload arrives in your workspace with the sender name attached. - [Live] **Browser upload, nothing to install.** Uploaders add files or whole folders from the browser over the standard HTTPS path; the page offers the free Boita app for full speed and resume on very large sends. - [Live] **Forms, file rules and a size cap.** Required fields and dropdowns (job number, sample id, project code), allowed file types, naming rules and a size cap, so the first upload is the right one. Off-spec files are flagged on arrival by delivery specs. - [Live] **Deadlines, invited uploaders and reminders.** Give a request a deadline and invite named uploaders; they get a reminder 48 hours before and an overdue nudge after. Add the deadline to your calendar with one click. - [Live] **Per-upload inbox folders.** Every upload is isolated in its own dated folder with an upload-only token scoped to exactly that folder, for a few minutes, in one direction. - [Live] **Review each upload.** Approve or reject each upload from the web or the phone; rejected uploads go to trash, not into your folders. Both the owner and the uploader get a completion email. - [Live] **Checksums recorded on arrival.** The server records a checksum for every file as part of the transfer, so what arrived is what was sent. - [Live] **Branded portals on your own domain.** Your name, logo, colour and a line of your own on every upload page, share page and email; uploads.yourcompany.com with the certificate issued for you. Studio and above. - [Live] **Portals you can embed.** Drop an upload portal or a delivery page into your own site or intranet with an embed snippet. Studio and above. - [Live] **Rules that fire on arrival.** Turn a landed upload into a delivery link, tag it, email someone or post to a chat channel the moment it completes. Studio and above. ### Desktop, agent & CLI URL: https://boita.io/desktop The Boita app for macOS, Windows and Linux ships with the accelerated transfer engine built in: parallel sessions sized to your plan, resume after any interruption, and watch folders that upload files as soon as they are written. The headless agent and the boita CLI do the same on servers, NAS boxes and render nodes. - [Live] **Multi-session transfers that use your whole connection.** Uploads and downloads of any size run as parallel sessions, the number set by your plan, over UDP-based acceleration that does not slow down with distance. - [Live] **Resume after network drops, sleep or restart.** Quit the app mid-transfer and reopen it; completed files are never re-sent. - [Live] **Upload watch folders.** Point a local folder at a workspace folder. New and changed files upload automatically; a file is only sent once it has stopped changing, so a file still being written never ships. - [Live] **Download watch folders.** Point the app at a workspace folder and a local folder: anything a client uploads, or a colleague drops in, lands on your NAS or server within a minute, sub-folders intact. Nothing is ever deleted locally. - [Live] **Allowed hours and bandwidth windows.** A watch folder can send only between chosen hours, and the workspace can cap transfers during office hours ("200 Mbps, Mon–Fri 9–18") — enforced by the transfer server, not just the app. Include/exclude patterns are next. - [Live] **Drop window and live tray.** A compact always-on-top window (⌘⇧B / Ctrl+Shift+B): drop files or folders, get a link. The menu-bar or tray icon shows aggregate progress, lists active transfers with rate and ETA, and offers pause and resume for everything. - [Live] **Finder and Explorer integration.** Right-click "Send with Boita" on any file or folder (a Quick Action on macOS, a per-user context-menu entry on Windows); boita://send links let scripts and other apps open the drop window pre-filled. - [Live] **Watch-folder presets for edit suites.** Deliver-from-Resolve and Deliver-from-Avid presets: the right file types, a longer stability wait for renders that grow, index files that never leave, and a share link made for each finished delivery. - [Live] **Headless Linux agent and the boita CLI.** boita-agent for render farms, lab instruments, NAS boxes and servers: watch folders up and down from the shell, run by systemd, controlled from the web app. The boita CLI uploads, downloads, lists, shares, waits for a receipt and tests your line from scripts. - [Live] **Signed builds with automatic updates.** Universal macOS build (notarised), a Windows installer and an MSI for IT deployment (unsigned for now — an EV certificate is on order), AppImage and .deb for Linux. Updates fetch in the background and install on quit. - [Live] **Scheduled sync, Docker, Helm and NAS packages.** The agent mirrors folders on a schedule (two-way, conflict copies, a delete guard, bandwidth windows), runs as a container or a Helm release, installs on Synology and QNAP, and the Agents page shows every server, container and NAS with a "Sync now" button. ### Admin & security URL: https://boita.io/security Workspaces with roles and seats, two-factor authentication and passkeys, an audit trail, policies, single sign-on, and a written security programme for the organisations that will hand us unreleased or regulated work. - [Live] **Two-factor authentication.** Time-based codes with single-use recovery codes. - [Live] **Passkeys.** Sign in with Face ID, Touch ID, Windows Hello or a security key; a passkey counts as two-factor. - [Live] **Audit log.** Logins, shares created and opened, downloads, deletions and admin actions, recorded per workspace; export it, or stream it to your SIEM on Enterprise. - [Live] **Per-workspace isolation.** Each workspace has its own storage root and its own encryption key on the transfer server; nothing is shared between tenants. - [Live] **Folder permissions and groups.** View, download, upload or manage rights per folder, per member or group. A member restricted to one client folder sees nothing else. Studio and above. - [Live] **Workspace policies and legal hold.** Cap link expiry below the plan, require a password on every link, pick SHA-256 or SHA-512 for checksums, and place a legal hold that stops anything from being deleted for good until it is lifted. - [Live] **Single sign-on and SCIM.** OIDC with Okta, Microsoft Entra ID, Google Workspace, Keycloak and others; members and groups provisioned and removed from your directory over SCIM. Enterprise. - [Live] **Sessions, admin scopes, IP and device policies.** See and sign out any device, give each admin only the areas they need, and restrict access to approved networks and enrolled computers. Enterprise. - [Live] **Scan on arrival, DLP hooks, hold exports.** Every arriving file scanned for malware with automatic quarantine; your own DLP service asked before a link is created; legal-hold export packages for counsel. Enterprise. - [Live] **Auto-delivery to your own servers.** Pair a workspace folder with your own bucket or your own transfer server: every file that lands is pushed there within minutes, sub-folders kept, retried on failure, with a delivery log and a webhook per file. Enterprise. - [Live] **Boita as an SFTP endpoint.** A tool that only speaks SFTP gets a per-workspace login (password or SSH key) and its files land straight in the workspace, every session audited, no server of your own to run. Pro and above. - [Live] **Support by plan.** Tickets on every plan with a promised first reply; live chat on Studio; scheduled calls and a named contact on Enterprise. A person answers every ticket. ### Review URL: https://boita.io/review Recipients play, zoom, page and draw over a delivery without downloading it. Give each person a role, collect per-file approvals with reminders, and export every note to a CSV or straight into the edit suite. Plans: Comments and threads are on every plan. The player, drawings, version compare, presentation mode, roles, approvals and exports come with Studio and Enterprise. How it works: 1. **Send a link with roles.** Name each recipient a viewer, a reviewer or an approver. Everyone else who opens the plain link keeps the ordinary share-page rules. 2. **They review in the browser.** Video and audio play from a proxy rendered on our servers; images zoom and pan; PDFs page. A note starts at the current frame, with a pen, arrow or box if words are not enough. 3. **Decisions land on the receipt.** Approve or Request changes per file and per version. Approvers with files still pending are reminded twice; every decision names who made it and lands on the receipt and in your activity feed. Features: - [Live] **Frame-accurate player.** J/K/L shuttle, single-frame stepping, HH:MM:SS:FF timecode read at the file’s real frame rate, and a waveform under the scrubber with a marker for every timecoded note. - [Live] **Notes with drawings.** Press C to start a note at the current frame; draw with a pen, an arrow or a box in five colours. Notes carry the timecode or the page and show up in the thread. - [Live] **Image and PDF mark-up.** A zoom-and-pan viewer for stills and a page-by-page viewer for PDFs (up to 50 pages rendered), with the same note and drawing tools. - [Live] **Version compare.** When an upload replaces a file, compare the two side by side or with a wipe. Decisions are per version, so a replaced file is pending again. - [Live] **Presentation mode.** Full screen, arrow keys between items, R toggles the reviewer panel, Esc leaves. Built for a room, not a tab. - [Live] **Roles, approvals and reminders.** Viewer, reviewer and approver per recipient. Approve or request changes with a note; approvers are nudged 48 hours after the link is created and 24 hours before it expires. - [Live] **Threads, @mentions and timecodes.** Replies one level deep, timecodes typed as 00:12.400 or 00:00:12:10, and @mentions of teammates that recipients never see. - [Live] **Export to CSV or edit-suite markers.** Comments as CSV with timecodes in milliseconds, or a marker file the edit suite imports with colours for resolved, sender and recipient notes. - [Live] **Review on the phone.** Reviewers approve, request changes and comment from the Boita app for iPhone and Android; the sender gets a push for each decision. - [Live] **Acknowledgements.** Got it, Thanks or Something is wrong: one tap for the recipient, one line on the receipt for you. - [Live] **Review analytics.** Approvals turnaround, open and download times and reviewer activity on the Insights page. - [Live] **Watermarked review.** On a watermarked link the player, the stills and the PDF pages are rendered from the recipient’s own marked copy. The numbers: - **Proxy for the player.** Rendered on our servers for every video and audio file on every plan (720p H.264, AAC); images at 2048 px; PDFs up to 50 pages. Sources over 12 GB are reviewed by download instead. - **Note length.** Up to 2,000 characters, one reply level, unlimited notes per file. - **Reminders.** 48 hours after the link is created and 24 hours before it expires, once each. - **Who can decide.** Only people opening their personal link or a verified email, so the receipt always says who. - **Exports.** CSV (id, time, author, file, timecode, body, resolved, parent) and a tab-separated marker file for edit suites. FAQ: **Q: Does the recipient need an account to review?** A: No. They open their personal link from the invitation (or verify their email with a code) and everything they do is attributed to them on the receipt. Nothing to install. **Q: Is the original ever served to the browser?** A: No. The player, the image viewer and the PDF viewer all work from proxies rendered on our servers. Downloads are separate and can be switched off with a view-only link. **Q: Is review only for video?** A: No. Stills, layered artwork exported as images, PDFs (proofs, drawings, reports) and audio get the same notes, drawings and approvals. Anything else is approved from its row without a viewer. **Q: What if the file is replaced after approval?** A: Decisions are per version. A replaced file goes back to Pending review, the previous decision stays on the previous version, and version compare shows both. Related: Share links and receipts (https://boita.io/send); Docs: review and approval (https://boita.io/docs/review-approval); Docs: watermarks (https://boita.io/docs/watermarks); Use case: print and packaging (https://boita.io/use-cases/print-packaging) ### Automations URL: https://boita.io/automations Write a rule once — when this happens, if these conditions hold, do these things — and Boita runs it every time: a delivery link to the client, a message to the channel, a tag for the report. No scripts, no cron, and a dry-run before you switch it on. Plans: Rules come with Studio and Enterprise. The email-in address is on Pro and above. Calendar links, Slack and Teams notifications and REST hooks follow their own plan lines below. How it works: 1. **Pick a trigger.** Files land in the workspace, a delivery is downloaded, a portal upload completes or is reviewed, or a time of day on chosen weekdays. 2. **Narrow it with conditions.** A folder prefix, file extensions, a size range, a specific portal, a weekly window. A rule with no conditions fires on every matching event. 3. **Add up to ten actions.** Email, a chat message, a share link with expiry and recipients, a tag. Test it against the last matching event and see exactly what each action would do before anything is sent. Features: - [Live] **Five triggers.** Files land (an upload, an import or a filed email), a delivery is downloaded, a portal upload completes, a portal upload is approved or rejected, or a daily schedule in the workspace time zone. - [Live] **Conditions that read like the job.** Folder prefix, up to 50 extensions, minimum and maximum size, one portal, days and hours. "Renders/ and .mov over 2 GB on weekdays" is one rule. - [Live] **Create a delivery link.** Turn the landed files into a share link with expiry (capped by your plan and policy), up to 50 recipients, email verification and a message — the moment the last file finishes. - [Live] **Email and chat.** Email up to 10 people with a templated subject and body, or post to a channel. Templates know the file, the folder, the sender, the byte count, the link and the decision. - [Live] **Slack and Microsoft Teams apps.** Deliveries, comments, approvals, portal uploads and quarantines post to your channel; delivery links unfurl; /boita send makes a link from chat. Studio and above. - [Live] **Dry-run and a runs log.** Test evaluates a rule against the most recent matching event and shows what would happen. Every real run is logged with its outcome; failed actions retry on a ladder up to 12 hours; runs are kept 30 days. - [Live] **Email-in address.** ingest-@in.boita.io files the attachments of any mail under Inbox//, thanks the sender, and raises an event rules can act on. Rotate the address whenever you like. Pro and above. - [Live] **Calendar links.** An embargoed delivery and a portal deadline both offer an .ics with a reminder, so the moment sits in the calendar of everyone who needs to be there. - [Live] **Zapier, Make and n8n.** The same events reach any workflow platform through REST hooks on the API (Pro and above). Generated integrations for the three platforms are built; the public listings follow their reviews. - [Live] **Also deliver to.** Send an upload to several destinations at once — a client’s cloud drive, your own bucket, a second workspace folder — by naming delivery rules on the send. - [Coming] **Request approval as an action.** A rule that opens a review with approvers when files land. Reserved; skipped today with a note in the run log. The numbers: - **Rules per workspace.** 50, each with up to 10 actions and 50 extensions in a condition. - **Email action.** Up to 10 recipients; the share-link action up to 50. - **Retries.** 1 min, 5 min, 30 min, 2 h, 12 h; then the run is marked failed and stays in the log for 30 days. - **Email-in.** Up to 20 attachments per mail, 25 MB each, 100 MB per mail, 120 mails an hour per address (defaults). - **Who can edit.** Admins create and change rules; every member can read and dry-run them. FAQ: **Q: Can a rule send the wrong thing to a client?** A: It can only do what you wrote, and you can see that before it runs: Test shows each action against the last real event with nothing sent. A share-link action also respects workspace policy — if links must have a password, the rule fails cleanly instead of sending an open link. **Q: Do I need a developer for this?** A: No. Rules are built in the app from dropdowns and templates. If you do have developers, the same events are available as signed webhooks, a polling event stream and REST hooks for workflow platforms. **Q: What happens to rules if we change plan?** A: Rules are kept. On a plan without automations they stop firing until the plan includes them again; nothing is deleted. **Q: Where does email-in mail go?** A: Only the attachments are kept, under Inbox// in your workspace. The sender gets a confirmation or a reason it could not be filed. The panel says so if inbound mail is not switched on for your deployment yet. Related: Upload portals (https://boita.io/portals); Integrations (https://boita.io/integrations); API and webhooks (https://boita.io/developers); Docs: automations and email-in (https://boita.io/docs/automations-email-in) ### Projects & search URL: https://boita.io/projects A project groups a client job’s share links, upload portals, deliveries and transfers with its crew, dates and status. Search walks the whole workspace by name, tag, codec, resolution, size, date or the fields you define, and the searches you run every week are one click. Plans: Projects, search, tags, custom fields, favourites, deep links, folder notes and requests are on every plan. Free keeps three saved searches; Pro and above have no limit. Move and copy jobs run up to 500 GB per job on Pro and above (250 GB on Free). How it works: 1. **Open a project for the job.** Name, client, status (Active, On hold, Delivered, Archived), start and due dates, notes and the crew with a lead. Anything you create from the project page is grouped under it. 2. **Files index themselves.** Every upload is indexed the moment it lands, with codec, resolution, frame rate and audio layout from the probe; a reconcile walk every 30 seconds picks up anything that arrived by a watch folder or an import. 3. **Find it, act on it.** Filter by extension, tag, size, date, codec, resolution, custom field or folder; select hundreds of results; move, copy, rename or share them in one verified job. Features: - [Live] **Projects with crew, dates and status.** Bytes sent and received, transfers, downloads and open links per project, on the web and the phone. Deleting a project removes the grouping only; nothing else changes. - [Live] **Search by what the file is.** Words from the name, tags, container, codec, resolution (1080p, 4k, 8k), frame rate or audio layout, with filters for size, date, folder and custom fields. Results respect folder permissions. - [Live] **Tags and custom fields.** Up to 30 tags per file; up to 20 workspace-defined fields (text, dropdown or date) such as sample id, project code, revision or sensitivity, filled per file and searchable as key:value. - [Live] **Saved searches.** Save a search for the whole workspace: "approved this week", "over 50 GB and older than 30 days", "revision:B". Three on Free, unlimited from Pro. - [Live] **Move, copy and rename at scale.** Hundreds of files per job, sequence-aware, previewed first and verified on the destination before anything is removed from the source. - [Live] **Numbered sets as one row.** Tiles, frames, scans or slices numbered 0001 to 2400 are one row with the range, the count, the size and a gap warning; expand for a single file. - [Live] **Favourites, pins, recents, deep links.** Star a file, pin a folder, see what you touched last, and copy a link that opens the same folder or file for a teammate. - [Live] **Folder notes and internal requests.** Pin a note to a folder ("final deliverables here, nothing else"), and ask a teammate for files in a folder with a request that tracks whether they landed. - [Live] **Workspace templates.** Start a new workspace from a template of folders, defaults and rules for a kind of team, then change anything. - [Live] **Version history.** When an upload replaces a file the previous copy is kept for the retention window; restore or delete any version from Files. - [Live] **All your workspaces on one page.** Every workspace you belong to, with usage and role, in one list. The numbers: - **Tags.** 30 per file, 40 characters each, lower-cased. - **Custom fields.** 20 per workspace; dropdowns up to 50 options. - **Saved searches.** 3 on Free; unlimited on Pro, Studio and Enterprise. - **Search results.** Pages of up to 200; the index is refreshed on every upload and reconciled every 30 seconds. - **Move / copy jobs.** 500 GB per job on Pro and above, 250 GB on Free; verified before the source is removed. FAQ: **Q: Is a project a folder?** A: A project sits on a folder and groups everything created from the project page: links, portals, auto-delivery rules and transfers into that folder. The files stay ordinary files; removing the project changes nothing about them. **Q: Can I search inside file contents?** A: No. Search covers names, paths, tags, custom fields and the technical details probed from media files (codec, resolution, frame rate, audio layout, duration). It does not read documents. **Q: What does "verified before anything is deleted" mean for a move?** A: A move copies to the destination, checks the copy against the recorded checksum, and only then removes the source. If anything fails, the source is untouched and the job says which files. Related: Drive: storage and versions (https://boita.io/drive); Insights (https://boita.io/insights); Docs: projects and search (https://boita.io/docs/projects-search); Use case: engineering, CAD and BIM (https://boita.io/use-cases/engineering-cad-bim) ### Enterprise URL: https://boita.io/enterprise Enterprise workspaces add identity from your directory, the admin split your auditors expect, an event stream into your SIEM, network and device restrictions, scanning and DLP on the way in and out, legal holds and retention rules, and the option of a transfer node in your own cloud account. Plans: Everything on this page is included in the Enterprise plan; a few items (SSO, legal hold, auto-delivery) are also called out on the pricing page. Studio workspaces get watermarks, archive tiers, review and automations; Enterprise adds the controls below. How it works: 1. **Connect identity.** OpenID Connect with PKCE to Okta, Microsoft Entra ID, Google Workspace, Keycloak or any OIDC provider, routed by email domain and optionally enforced. SCIM provisions members and groups from the directory and removes them the same way. 2. **Split the admin role.** Billing, members, security and content are separate scopes. Sessions and devices are visible and revocable; every admin action is in the audit log and in your SIEM within seconds. 3. **Set the perimeter.** An IP allow-list with a grace window that cannot lock you out, a device policy that limits transfers to enrolled computers, scanning and quarantine on arrival, a DLP check before any link goes out, and a legal hold that stops permanent deletion. Features: - [Live] **Single sign-on.** One OIDC provider per workspace, routed by email domain. Enforce it so password sign-in is refused for those domains; new people are created on first sign-in with a default role; your provider owns the second factor. - [Live] **SCIM provisioning.** Members and groups from Okta or Entra, created, updated and deactivated from the directory. Directory-managed accounts cannot be re-addressed outside the organisation. - [Live] **Sessions and devices.** Every sign-in with device, a hashed address hint, two-factor state and expiry; revoke one or sign out every other device. API keys cannot touch sessions. - [Live] **Admin scopes.** Billing, members, security and content as separate grants. The owner always has all four; without the feature every admin has all four. - [Live] **Audit export and SIEM stream.** CSV or JSON Lines of the audit log and workspace events (100,000 rows per export), and a signed HTTPS stream of events to one endpoint per workspace, resumable after a pause. - [Live] **IP allow-list and device policy.** Up to 200 addresses or ranges (IPv4 and IPv6), a 15-minute owner grace window after every change, and a test button. Require the desktop app for member transfers or restrict them to approved computers. - [Live] **Scan on arrival and quarantine.** Every arriving file is scanned for malware; hits are quarantined automatically and posted to your channel. Whether sharing is blocked while a scan is queued is a workspace decision. - [Live] **DLP hooks.** Before a link is created, Boita asks your DLP service and honours the answer. Your classifier, your rules. - [Live] **Legal hold and hold exports.** A hold stops anything in scope from being purged, whatever the retention setting, with the reason recorded. Export a hold as a package for counsel. - [Live] **Forensic watermark.** An invisible per-recipient mark on video deliveries and a "who leaked this?" tool that reads it back from a clip. - [Live] **Archive tiers and retention rules.** Move finished folders to cold storage with a manifest and restore on demand; retention rules per folder decide what is kept for how long. - [Live] **Auto-delivery and a dedicated lane.** Push anything that lands to your own S3-compatible bucket or transfer server, and run on a dedicated bandwidth lane on the transfer node with 100 or more parallel sessions. - [Live] **Self-managed transfer nodes.** Stand up a transfer node in your own AWS account with our Terraform module; the workspace, links and receipts stay with Boita. Regional nodes elsewhere on request. - [Live] **Security questionnaire pack.** A data processing agreement, sub-processor list and DPDP statement are published; the TPN control-by-control gap list and the 2026-09-21 security review are available on request. Counsel review of the legal pack and an independent penetration test are in progress. The numbers: - **SSO.** One OIDC provider per workspace; any number of email domains; enforced or optional. - **Sessions.** 30 days from sign-in; revocable individually or all at once. - **Exports.** 100,000 rows per audit or event export, with a marker when truncated. - **SIEM.** Signed batches (the webhook signature scheme); 50 consecutive failures pause the stream and email the owner. - **IP allow-list.** 200 entries; the list is refused if it would lock out the person saving it. - **Parallel sessions.** 100 or more at 45 Mbps each (4.5 Gbps and above) on a dedicated lane. FAQ: **Q: Can we keep files in our own cloud account?** A: Two ways. Auto-delivery pushes everything that lands to your own S3-compatible bucket or transfer server within minutes. A self-managed transfer node in your AWS account (Terraform module) keeps the storage under your account while Boita runs the workspace, links and receipts. **Q: Where do you stand on SOC 2, ISO 27001 and TPN?** A: SOC 2 Type II is in progress on a compliance platform; ISO/IEC 27001 is targeted within 12 to 18 months of launch; the TPN self-assessment against the MPA content-security guidelines is written control by control and available on request with its gap list. Nothing is claimed as certified until it is. **Q: Does the security team get an incident feed?** A: The SIEM stream carries every workspace event; status.boita.io announces incidents and maintenance; every incident gets a written post-mortem. The Trust page lists recovery objectives and the backup schedule. **Q: Is there a data processing agreement?** A: Yes, published at /legal/dpa with the sub-processor list and the DPDP statement. Counsel review of the pack is in progress; custom terms are handled per contract. Related: Security programme (https://boita.io/security); Trust and transparency (https://boita.io/trust); Data processing agreement (https://boita.io/legal/dpa); Docs: security and governance (https://boita.io/docs/security-governance) ### Integrations URL: https://boita.io/integrations Deliveries post to the channel. Landed files go on to the cloud drive the client uses. The edit suite sends renders on its own. A pipeline drives it from the CLI, the SDKs or a workflow platform. What is not built yet is marked as coming. Plans: Slack and Teams apps come with Studio and Enterprise. REST hooks for workflow platforms, the CLI, SDKs and API keys are on Pro and above. Cloud-drive destinations, the edit-suite presets and the panel are on every plan that has the underlying feature. How it works: 1. **Connect once.** Add the Slack or Teams app to a channel, paste a webhook, connect a cloud drive, or create an API key under Developers. Secrets are shown once and stored encrypted. 2. **Pick what should flow.** Which events reach the channel, which folder goes to which drive, which watch folder uses which preset, which rule fires on which trigger. 3. **Forget it is there.** Every delivery, comment, approval, portal upload and quarantine shows up where the team already looks; every failure is retried and logged. Features: - [Live] **Slack.** Deliveries, comments, approvals, portal uploads and quarantines to your channel; delivery links unfurl; /boita send makes a link from chat. Studio and above. - [Live] **Microsoft Teams.** The same notifications to a Teams channel through an incoming webhook today; the full Teams app with unfurls and commands follows its directory registration. - [Live] **Zapier, Make and n8n.** REST hooks on the API expose every event to the three platforms with generated integrations; works today with an API key, public listings follow their reviews. Pro and above. - [Live] **Cloud-drive destinations.** Deliver a share or any files straight into the cloud drive the client already uses — the four common ones — as a send option or an automation action; the personal drives connect as each app review clears. - [Live] **Object storage.** Import from any S3-compatible bucket; auto-deliver to your own S3-compatible bucket or transfer server (Enterprise). Buckets on the other major clouds work through their S3-compatible endpoints today; native connectors are coming. - [Live] **Premiere Pro panel.** Deliver renders, jump to reviewers’ timecoded notes and import from the workspace without leaving the edit; the marketplace listing follows the developer-account step. - [Live] **Resolve and Avid watch-folder presets.** Point a preset at the render or export folder: the right file types, a longer stability wait for renders that grow, index files that never leave, and a share link per finished delivery. - [Live] **Finder and Explorer.** Right-click "Send with Boita" on any file or folder; boita://send links open the drop window from scripts and other apps. - [Live] **CLI, SDKs and OpenAPI.** The boita CLI for scripts and render pipelines; TypeScript and Python SDKs generated from the OpenAPI description; scoped API keys and signed webhooks. Pro and above. - [Live] **WhatsApp.** Recipients by WhatsApp number, replies as comments; reminders, receipts and sign-in codes over WhatsApp switch on when the message templates are approved. - [Coming] **Docker, Helm and NAS packages for the agent.** Run the headless agent as a container or as a package on the common NAS platforms. - [Coming] **SFTP endpoint.** An SFTP front door for systems that can only speak SFTP, landing in the workspace like any other upload. Until then, portals, the CLI and the agent replace the FTP server. - [Coming] **Native GCS and Azure Blob connectors.** Import from and auto-deliver to the two other major clouds without an S3-compatible endpoint. - [Coming] **Media asset management connectors.** Connectors for the common MAM and archive systems, starting with the ones that offer self-serve trials. Good to know: - **Chat apps.** One Slack workspace or Teams tenant per Boita workspace; events chosen per channel. - **Webhooks.** Signed with HMAC-SHA256, 10-second timeout, retried after 1 min, 5 min, 30 min, 2 h and 12 h. - **API keys.** Scoped read or read + write, optional expiry, 600 requests a minute per key. - **Presets.** Deliver from Resolve, Deliver from Avid; more on request. The Linux agent applies the same presets headlessly. FAQ: **Q: Do I need Slack for automations to work?** A: No. Rules can email, tag and create links without any chat app. Slack and Teams add a channel as a destination and let people make a link from chat. **Q: Can the client receive files in their own cloud drive?** A: Yes. Choose the drive as the destination when you send, or make it an automation action for a folder; the delivery lands there and the receipt still records it. **Q: We only have an FTP workflow. What replaces it?** A: Portals for people, the CLI and the agent for machines, and links for outbound. An SFTP endpoint for legacy systems is on the roadmap; until then the agent on the same server usually covers it. Related: Automations (https://boita.io/automations); API, SDKs and webhooks (https://boita.io/developers); Desktop, agent and CLI (https://boita.io/desktop); Replace your FTP server (https://boita.io/solutions/replace-ftp-server) ### Mobile URL: https://boita.io/mobile Everything you would check between meetings is on the phone: who downloaded, what landed, what needs approving, how a transfer is doing. Pick files on your Mac or PC from the phone and the desktop app sends them on the fast path. Plans: The app is free with every plan and signs in with your Boita account (two-factor and passkeys work). Plan features follow the workspace: review, automations and archives appear on Studio and above, insights on Pro and above. How it works: 1. **Sign in, pick a workspace.** Five tabs: Home, Files, Share links, Portals and More. Share links, portals and invitations open in the app when tapped; the Scan button reads their QR codes. 2. **Send from the phone or from your computer.** Documents, photos and videos upload from the phone as originals over HTTPS. Send from my computer picks files on any Mac or PC where the desktop app is signed in as you; they go over the fast path from that machine. 3. **Act on what happens.** Push notifications for downloads, comments, reactions, approvals and portal uploads. Approve or reject a portal upload, approve a file, reply to a comment, re-notify a recipient, all from the phone. Features: - [Live] **Files and search.** Browse with breadcrumbs, search with saved searches, favourites and recents; numbered sets as one row; details, rename, move to trash, download to the phone. - [Live] **Share links with receipts.** Expiry presets, download limits, passwords, a title and message; every link’s receipt with who viewed and downloaded. - [Live] **Portals.** Create portals, see uploads as they land, approve or reject each one. - [Live] **Review on the phone.** Approve, request changes and comment on deliveries as a reviewer or approver. Studio and above. - [Live] **Send from my computer.** Pick files on a Mac or PC running the desktop app and have it send them on the fast path; turn a computer folder into a watch folder from the phone. - [Live] **WhatsApp send.** Send a recipient their personal link on WhatsApp with the message already written; their replies show up as comments. - [Live] **Deliveries to me.** Recipients see every live delivery addressed to them, from any sender, without an account. - [Live] **Transfers and your connection.** All, running and failed transfers with the speed badge; a speed test and a plain explanation of which path your files take. - [Live] **Automations, archives, health.** Read and dry-run rules, move folders to the archive tier and restore, and a health check of everything the workspace depends on. - [Live] **Members, sessions, security.** Members and seats, sessions and devices, two-factor and passkeys, integrations. - [Live] **Insights.** The delivery funnel, time to open, busiest clients and senders, compactly. Pro and above. - [Live] **Low bandwidth.** A low-bandwidth switch on delivery pages for 2G and 3G: previews, covers and animations off so the page and the download still work. - [Coming] **Accelerated transfers on the phone.** The fast path inside the mobile app itself, for multi-GB sends without a computer. Arrives with a later store build. - [Coming] **Camera-roll backup, widgets, share sheet.** Automatic camera-roll backup, home-screen widgets and Live Activities, a share-sheet extension, tablet layouts and background uploads with the next native build. Good to know: - **Uploads from the phone.** Originals with EXIF kept, up to 50 per pick, over the standard-speed HTTPS path. - **Fast path.** Through Send from my computer today; the desktop app is the fast path for multi-GB deliveries. - **Updates.** The app updates itself over the air between store releases. - **Recipients.** Do not need the app: delivery pages open in any mobile browser, with a low-bandwidth switch. FAQ: **Q: Can I upload a 50 GB file from my phone?** A: You can, over HTTPS at standard speed, and it resumes if the app is interrupted. For multi-GB deliveries the fast path is Send from my computer: pick the file on your Mac or PC from the phone and the desktop app sends it. **Q: Do recipients need the app?** A: No. Delivery and portal pages open in any mobile browser. The app adds push notifications, QR scanning and a home screen for people who work in Boita every day. **Q: Does the app work with SSO and passkeys?** A: Yes. Sign in with your identity provider on Enterprise, or with a passkey or an authenticator code on any plan. Related: Desktop, agent and CLI (https://boita.io/desktop); Docs: mobile app (https://boita.io/docs/mobile); India first: WhatsApp, UPI, low bandwidth (https://boita.io/india); Review and approval (https://boita.io/review) ### Insights URL: https://boita.io/insights Insights turns receipts, transfers and portals into answers: the delivery funnel, median time to first open, recipients by domain, storage growth, transfer speed over time and how much of your plan you are leaving unused. Then it writes the client report for you. Plans: Insights, client reports and bandwidth analytics come with Pro and above. Speed receipts, the health page and the one-question feedback prompt are on every plan. How it works: 1. **Every transfer leaves a receipt.** How big, how long, how fast, and how much faster than a typical upload over that route — on receipts, share pages, the dashboard, emails, the desktop app and the phone. 2. **Insights add it up.** Sent, opened and downloaded per day; time to first open and download; recipients by domain; busiest senders; portal conversion; storage growth; speed over time. 30 or 90 days, cached for ten minutes. 3. **The report writes itself.** A branded per-client delivery report as PDF, on demand for any recipient domain or address-book group, or emailed monthly on the day you choose. Features: - [Live] **Delivery funnel.** Deliveries sent, opened and downloaded, the rates between them, and a per-day series for 30 or 90 days. - [Live] **Time to open.** Median time from send to first open and to first download, so you know which clients read on Monday and which on Friday. - [Live] **Clients and senders.** Recipients by domain (people and deliveries), and who on your team sends most. - [Live] **Speed receipts.** Every finished transfer says how big, how long and how much faster than a typical upload — a stated model of TCP over that route, not a marketing number. - [Live] **Bandwidth analytics.** Daily volume, peak rates, busiest hours (IST), by client and by person, and the plan headroom you are not using. - [Live] **Client reports (PDF).** A branded report per client with every delivery, its files, sizes, checksums, who opened it and when; on demand or monthly by email. - [Live] **Review analytics.** Approvals turnaround and reviewer activity on the same page. - [Live] **Portal conversion.** Invited uploaders against completed uploads, per portal. - [Live] **Health page.** Plain-English checks of everything the workspace depends on, with remedies and a link to the status page. Every plan. - [Live] **Your connection.** A speed test in the desktop app and the phone, and which path your files take (fast path or HTTPS) and why. - [Live] **Feedback.** One question after a download and after your tenth link; recipients answer anonymously. The numbers: - **Windows.** 30 or 90 days, cached ten minutes per workspace. - **Client report.** Any recipient domain or address-book group; monthly send on a day from 1 to 28; one email per group with deliveries in the previous month. - **Speed receipt model.** The "typical upload" is TCP with loss-based congestion control over the route (the Mathis model), granted four parallel streams and capped at the line rate; the assumption is printed on the receipt. - **Per-session cap.** 45 Mbps per session; 10 sessions on Pro (450 Mbps), 50 on Studio (2.25 Gbps), 100 or more on Enterprise. A receipt never claims more than the plan and the line allow. FAQ: **Q: How is "faster than a typical upload" calculated?** A: From the route. A textbook model of TCP throughput given the round-trip time and loss on the path, granted four parallel streams to be fair to multipart uploaders and capped at your line rate. The assumption is printed on the receipt and the same model runs the calculator on the home page. **Q: Can the client see the report?** A: It is a PDF you send them, branded with your name and logo on Studio and above. It lists every delivery in the period, its files and checksums, and who opened and downloaded what, with the platform named only in the footer. **Q: Is any of this shared with other customers?** A: No. Insights are computed per workspace from your own receipts and transfers, and cached per workspace. Related: Share links and receipts (https://boita.io/send); Speed calculator (https://boita.io/#calculator); Trust: status, backups, recovery (https://boita.io/trust); Docs: insights and client reports (https://boita.io/docs/projects-search) ### India first URL: https://boita.io/india Clients reply on WhatsApp, finance wants a GST invoice with the GSTIN on it, the site office is on a 3G dongle, and the data must stay in the country. Boita was built here, so those are defaults, not add-ons. Plans: WhatsApp recipients, INR pricing, low-bandwidth mode and Mumbai residency are on every plan. Parts that depend on outside approvals — message templates and the payment provider’s verification — are marked coming. How it works: 1. **Deliver where the reply will come from.** Add a recipient by WhatsApp number next to the email addresses. They get their own personal link, and when they reply on WhatsApp the note lands as a comment on the delivery with an acknowledgement in the same chat. 2. **Pay the way finance expects.** Plans in INR with GST invoices in the company format and your GSTIN on them, credit notes for refunds, UPI Autopay or a card, or pay once for a month. 3. **Work on the connection you have.** A low-bandwidth mode on delivery, portal and Files pages for 2G and 3G; an HTTPS fallback where UDP is blocked. Features: - [Live] **Recipients on WhatsApp.** Numbers with the country code, up to 200 per link, each with a personal link; a Send on WhatsApp button with the message ready; public pages never show a full number. - [Live] **Replies as comments.** A recipient’s WhatsApp reply is matched to the delivery and lands in its comment thread, marked (WhatsApp); the sender is notified. - [Coming] **Reminders, receipts and sign-in codes on WhatsApp.** Template messages sent by Boita — invitations on create, reminders, download receipts and one-time codes — switch on as soon as the channel’s templates are approved. - [Live] **Pricing in INR.** Free ₹0, Pro ₹499 a month, Studio ₹7,999 a month, Enterprise custom; GST added on top; no per-GB fees. - [Live] **GST tax invoices and credit notes.** Numbered per financial year (#INV-AS-BOITA/YY-YY/000001), CGST + SGST or IGST as your state requires, a GSTIN field checked for format and state, credit notes for refunds. - [Coming] **UPI Autopay and cards.** A UPI mandate that renews monthly and is revocable from your UPI app, a card subscription, or one payment for a month. Built; switches on when the payment provider completes verification of the Boita account. - [Live] **Low-bandwidth mode.** Suggested automatically on 2G/3G or Data Saver: previews, covers and animations off so the page and the download still work. Remembered per browser. - [Live] **Data in Mumbai.** Files, the transfer server, the application and the database run in AWS Mumbai; backups in Mumbai and Singapore. The Trust page lists every location. - [Live] **DPDP Act alignment.** A published DPDP statement for recipients and uploaders, a grievance officer, consent and deletion flows, 180-day access logs for CERT-In directions; counsel review of the legal pack in progress. - [Live] **Support in IST.** Tickets on every plan, live chat on Studio 9:00–21:00 IST every day, calls and a named contact on Enterprise. WhatsApp for sales and support. - [Live] **Rest of the world.** The same plans in USD, EUR, GBP, AED, SGD or AUD with tax invoices; regional transfer nodes elsewhere on request for Enterprise. The numbers: - **WhatsApp recipients.** Up to 200 numbers per link; numbers normalised on entry; shown as +91…210 on public pages. - **GST.** 18 % on INR plans; exports zero-rated in other currencies; the SAC is printed on the invoice. - **Dunning.** Three autopay attempts with an email each; 14 days to fix the payment method before the workspace drops to Free with files kept. - **Low-bandwidth mode.** Per browser; suggested on 2G/3G or Data Saver, never forced. FAQ: **Q: Can my clients reply on WhatsApp without an account?** A: Yes. They tap the link in the WhatsApp message, and any reply in that chat is matched to the delivery and shown to you as a comment. They never need a Boita account. **Q: Will the invoice carry my GSTIN?** A: Yes. Add your GSTIN and billing address under Plan & billing; it is checked for format and state, and every invoice and credit note carries it with CGST + SGST or IGST as applicable. **Q: Is data stored outside India?** A: Files and the database are in Mumbai. Encrypted backup copies are also kept in Singapore for disaster recovery; the sub-processor list on the Trust page says exactly what leaves the country (transactional email, crash reports without file contents). Related: Pricing in INR (https://boita.io/pricing); Docs: WhatsApp deliveries (https://boita.io/docs/whatsapp); DPDP statement (https://boita.io/docs/dpdp); Trust: where data lives (https://boita.io/trust) ## Plans URL: https://boita.io/pricing Prices (monthly, flat): Free ₹0 / $0 with 10 GB; Pro ₹499 / $7 / €6.50 / £5.50 with 1 TB; Studio ₹7,999 / $99 / €92 / £79 with 10 TB; Enterprise custom. Plans are flat monthly amounts sized by storage, share retention, seats and speed: a per-session rate times parallel sessions (Free 2 × 10 Mbps = 20 Mbps; Pro 10 × 45 Mbps = 450 Mbps; Studio 50 × 45 Mbps = 2.25 Gbps; Enterprise 100+ sessions, 4.5 Gbps and above). The customer’s own line is the other limit; the rate can be lowered from the app, never raised above the plan. No per-GB transfer fees; downloads and re-downloads free; storage overage, if it ever applies, is shown before it happens. GST tax invoices in India; UPI Autopay and cards switch on once the payment provider completes verification. Cancellation and refunds: monthly plans cancel any time effective end of period; annual plans pro rata on request within 14 days; overage not refundable. | Plan | Audience | Storage | Share retention | Seats | Parallelism | Priority | Support | Includes | |---|---|---|---|---|---|---|---|---| | Free | Try it, or send the odd file | 10 GB | 3 days | 1 seat | 2 sessions | Low | Tickets · 48 h | Web app; Share links with expiry; Sender dashboard | | Pro | Freelancers, labs and small teams | 1 TB | 14 days | 3 seats | 10 sessions | Fair share | Tickets · 24 h | Everything in Free; Desktop app for macOS and Windows; Password-protected shares; Upload portals; 2 watch folders; API keys, webhooks, SDKs; Email-in and insights | | Studio | Studios, agencies, engineering and data teams | 10 TB | 30 days | 15 seats | 50 sessions | High | Chat · 4 h | Everything in Pro; Unlimited watch folders; Branded portals and share pages; Delivery receipts (PDF); Review and approval; Automations, Slack and Teams; Watermarks and archive tier | | Enterprise | Regulated, multi-site and large organisations | Custom | Custom | Custom | 100+ sessions | Dedicated lane | Calls · 2 h | Everything in Studio; SSO and SCIM; Auto-delivery to your servers; Sessions, SIEM, IP and device policies; Scan on arrival, DLP, hold exports; Dedicated bandwidth lane | Full plan matrix (every plan-gated feature and the plan it starts on): | Feature | Free | Pro | Studio | Enterprise | |---|---|---|---|---| | Storage and speed: Storage | 10 GB | 1 TB | 10 TB | Custom | | Storage and speed: Speed ceiling (per session × sessions) | 20 Mbps | 450 Mbps | 2.25 Gbps | 4.5 Gbps+ | | Storage and speed: Per-session rate | 10 Mbps | 45 Mbps | 45 Mbps | 45 Mbps | | Storage and speed: Parallel sessions | 2 | 10 | 50 | 100+ | | Storage and speed: Priority on the shared node | Low | Fair share | High | Dedicated lane | | Storage and speed: Priority lanes (Deadline / Background) | yes | yes | yes | yes | | Storage and speed: Seats | 1 | 3 | 15 | Custom | | Storage and speed: Trash retention | 7 days | 30 days | 30 days | 30 days | | Storage and speed: Move / copy jobs, per job | 250 GB | 500 GB | 500 GB | 500 GB | | Sending and receiving: Share links with expiry and download limits | yes | yes | yes | yes | | Sending and receiving: Share retention (default · maximum) | 3 · 7 days | 14 · 30 days | 30 · 90 days | 30 · 365 days | | Sending and receiving: Password-protected shares | — | yes | yes | yes | | Sending and receiving: Recipient verification by email code | — | yes | yes | yes | | Sending and receiving: Sender-side encrypted delivery (passphrase) | yes | yes | yes | yes | | Sending and receiving: Embargoes, view-only, acknowledgements, templates, address book | yes | yes | yes | yes | | Sending and receiving: Delivery receipts (who viewed, who downloaded, checksums) | yes | yes | yes | yes | | Sending and receiving: Receipt and verification report as PDF and CSV | — | — | yes | yes | | Sending and receiving: Recipients on WhatsApp | yes | yes | yes | yes | | Sending and receiving: Upload portals (forms, rules, deadlines, review) | — | yes | yes | yes | | Sending and receiving: Branded pages, portals and emails; your own domain | — | — | yes | yes | | Sending and receiving: Embed delivery pages and portals on your site | — | — | yes | yes | | Sending and receiving: Watermarked previews and downloads | — | — | yes | yes | | Sending and receiving: Invisible per-recipient mark on video | — | — | — | yes | | Sending and receiving: Desktop app for macOS, Windows and Linux | — | yes | yes | yes | | Sending and receiving: Send from my computer (phone picks, desktop sends) | — | yes | yes | yes | | Sending and receiving: Watch folders | — | 2 | Unlimited | Unlimited | | Sending and receiving: Headless Linux agent and boita CLI | — | yes | yes | yes | | Sending and receiving: Import from S3-compatible buckets and cloud drives | yes | yes | yes | yes | | Sending and receiving: Auto-delivery to your own bucket or server | — | — | — | yes | | Sending and receiving: Archive tier with manifest and restore | — | — | yes | yes | | Sending and receiving: Retention rules per folder | — | — | — | yes | | Review, projects and automation: Comments on delivery pages | yes | yes | yes | yes | | Review, projects and automation: Review roles, approvals, reminders, comment exports | — | — | yes | yes | | Review, projects and automation: Frame-accurate player, drawings, version compare, presentation mode | — | — | yes | yes | | Review, projects and automation: Projects, tags, custom fields and search | yes | yes | yes | yes | | Review, projects and automation: Saved searches | 3 | Unlimited | Unlimited | Unlimited | | Review, projects and automation: Automations (rules on arrival) | — | — | yes | yes | | Review, projects and automation: Email-in address | — | yes | yes | yes | | Review, projects and automation: Insights and monthly client reports (PDF) | — | yes | yes | yes | | Review, projects and automation: Slack and Microsoft Teams apps | — | — | yes | yes | | Review, projects and automation: Zapier, Make and n8n (REST hooks) | — | yes | yes | yes | | Review, projects and automation: Cloud-drive destinations for deliveries | yes | yes | yes | yes | | Team and control: Members and roles | yes | yes | yes | yes | | Team and control: Folder permissions and groups | — | — | yes | yes | | Team and control: Two-factor authentication and passkeys | yes | yes | yes | yes | | Team and control: Audit log | yes | yes | yes | yes | | Team and control: Workspace policies (expiry cap, password required, checksum type, legal hold) | yes | yes | yes | yes | | Team and control: Single sign-on (OIDC) and SCIM provisioning | — | — | — | yes | | Team and control: Sessions, admin scopes, audit export and SIEM streaming | — | — | — | yes | | Team and control: IP allow-lists and device policies | — | — | — | yes | | Team and control: Malware scan on arrival with quarantine | — | — | — | yes | | Team and control: DLP hooks before links go out | — | — | — | yes | | Team and control: Legal-hold export packages | — | — | — | yes | | Team and control: Dedicated bandwidth lane on the transfer node | — | — | — | yes | | Team and control: Self-managed transfer nodes in your AWS account (Terraform) | — | — | — | yes | | Developers: Scoped API keys | — | yes | yes | yes | | Developers: Webhooks (signed, retried) and the webhook console | — | yes | yes | yes | | Developers: Event stream | — | yes | yes | yes | | Developers: OpenAPI description, TypeScript and Python SDKs | yes | yes | yes | yes | | Developers: Sandbox workspaces | — | yes | yes | yes | | Support: Tickets and email | yes | yes | yes | yes | | Support: First reply within | 48 h | 24 h | 4 h | 2 h | | Support: Live chat | — | — | yes | yes | | Support: Scheduled calls and a named contact | — | — | — | yes | | Support: Coverage | Mon–Fri | Mon–Sat | Every day | 24×7 for outages | Pricing-model comparison by category (no vendor named): per-GB transfer services meter every GB sent and often count re-downloads against credit; per-seat enterprise transfer suites charge per user with per-transfer caps on lower tiers; Boita is flat with neither. ## Who uses it (situations) - **A 400 GB sequencing run to a collaborator** (FASTQ · BAM · microscopy stacks): From the instrument PC to a lab on another continent, with a checksum on every file so the reanalysis starts from the same bytes. See https://boita.io/use-cases/life-sciences-genomics - **Nightly off-site copies from a NAS** (File server · NAS · archives): A headless agent on the box, a watch folder that sends only after hours, a second site filled by a download watch folder. See https://boita.io/use-cases/backup-dr-nas - **Render outputs to a client, as they finish** (EXR · DPX · ProRes · caches): Frames leave the farm the moment they stop changing; the client opens a page with the sequence as one row and a receipt when they download. See https://boita.io/use-cases/vfx-post-production - **Imaging studies between sites** (DICOM · whole-slide · NIfTI): DICOM series and whole-slide images to a reading centre or a trial sponsor, with verified recipients, an audit log and previews switched off. See https://boita.io/use-cases/medical-imaging - **Tonight’s build to QA and the publisher** (Builds · packages · symbols): A watch folder on the build machine, one link per platform build, and a dashboard that shows who pulled it. See https://boita.io/use-cases/game-development-builds - **Satellite and drone imagery to customers** (GeoTIFF · COG · LAS · SAR): Thousands of tiles per acquisition, checksummed, delivered to a link or straight into the customer’s own bucket. See https://boita.io/use-cases/satellite-earth-observation - **CAD assemblies and BIM models to partners** (Assemblies · IFC · point clouds · CFD): Whole folder trees with references intact, versions kept when a file is replaced, portals for suppliers to send parts in. See https://boita.io/use-cases/engineering-cad-bim - **Training sets to the cloud and back** (Datasets · shards · checkpoints): Millions of small files or a few huge shards, from the CLI in a pipeline, into your own S3-compatible bucket. See https://boita.io/use-cases/ml-datasets - **An episode to a broadcaster before the cut-off** (IMF · MXF · mezzanine): Mezzanine packages that hold line rate over distance, with a receipt that proves what landed and when. See https://boita.io/use-cases/broadcast-ott-delivery - **Print-ready artwork to the press** (PDF/X · layered artwork · dielines): A portal with the job number and file rules so it arrives right the first time, and approval on the delivery page. See https://boita.io/use-cases/print-packaging - **A survey week out of a site office** (LAS · orthomosaics · photogrammetry): Terabytes of captures pushed out overnight from a laptop on a mediocre link, resuming every time it drops. See https://boita.io/use-cases/drone-survey-gis - **Evidence sets to counsel** (E01 · PST · document sets): Forensic images and document sets with a checksum, a verified recipient and an audit trail for the matter file. See https://boita.io/use-cases/legal-ediscovery ## Security (summary) URL: https://boita.io/security Live: transfers encrypted in transit by the engine (AES-256) and HTTPS-only web surfaces; per-workspace storage roots with automated cross-tenant isolation tests; per-operation transfer tokens scoped to paths and direction, expiring in minutes; two-factor authentication and passkeys (mandatory for staff); per-workspace audit log with export and SIEM streaming (Enterprise); sender-encrypted delivery with a passphrase; single sign-on and SCIM (Enterprise); sessions and admin scopes, IP allow-lists and device policies, malware scan on arrival with quarantine, DLP hooks, legal hold and hold exports, forensic watermark (Enterprise); data in AWS Mumbai with encrypted backups in Mumbai and Singapore; status page and uptime SLA with automatic credits; a dated second-reviewer security review (2026-09-21). In progress: encryption at rest on the two original volumes (migration announced on the status page); ticketed, approved, time-limited break-glass access; counsel review of the legal pack; SOC 2 Type II. Planned: independent penetration test; customer-held keys; ISO 27001; TPN assessment (self-assessment and gap list available on request). ## Archive tiers Shipped (Studio and above): move finished folders to cold storage with a manifest and restore on demand; Enterprise adds retention rules per folder. Coming, on request: a verifiable archive tier with proof-of-storage on decentralised storage (a domestic object-storage archive for India-residency workspaces). The archive is only ever a destination for cold data; transfers never run through it. ## FAQ URL: https://boita.io/faq **Q: Is Boita only for media and post-production?** A: No. Boita is for anyone who moves a lot of data and has hit the bottleneck: labs sending sequencing runs, hospitals moving imaging studies, engineering teams exchanging CAD and BIM models, satellite and drone operators, ML teams moving datasets, IT teams doing off-site copies, game studios shipping builds, print houses receiving artwork — and yes, studios delivering renders and episodes. The engine, the links, the portals and the automation are the same; only the examples change. **Q: How is Boita faster than a normal upload?** A: Ordinary uploads run over TCP, which slows down every time a packet is lost and never recovers the distance to a far-away server. Boita moves data with an accelerated transfer engine over UDP with its own rate control, so a transfer climbs to your line rate and stays there whether the other end is across town or across an ocean. Big jobs also run as several parallel sessions: 45 Mbps per session, 10 sessions on Pro (450 Mbps), 50 on Studio (2.25 Gbps), 100 or more on Enterprise. **Q: Do I need to install anything?** A: Not to start. The web app uploads and downloads in the browser, and recipients and portal uploaders need nothing installed either. For full speed, resume and watch folders, install the free desktop app (macOS, Windows, Linux) or the headless agent on a server; both carry the transfer engine, so there is no second client to keep updated. **Q: What happens if my connection drops mid-transfer?** A: The transfer checkpoints as it runs. When the network is back, or you reopen the app, it resumes from where it stopped; completed files are never re-sent. **Q: What happens on a slow connection?** A: Boita uses whatever line you have; the plan sets the ceiling, not the floor. If your network blocks UDP, transfers fall back to an HTTPS path automatically and the app says which path you are on. On a 2G or 3G connection the delivery, portal and Files pages offer a low-bandwidth mode that switches off previews, covers and animations so the page and the link still work. **Q: Do recipients need an account or a licence?** A: No. Recipients open a share page, see the files and download in the browser with nothing to install. The page offers the free Boita app for full speed and resume on very large deliveries. **Q: Do you charge for downloads?** A: No. Plans are flat monthly amounts, billed in your local currency (INR in India). We do not charge per GB downloaded, and re-downloads are free. If storage overage ever applies it is shown before it happens, never after. **Q: Where is my data stored?** A: In India: files, the transfer server, the application and the database run in AWS Mumbai, with encrypted backups in Mumbai and Singapore. The Trust page lists every location and sub-processor. Regional nodes elsewhere are available on request for Enterprise; a self-managed node in your own AWS account is also possible with our Terraform module. **Q: Is there a mobile app?** A: Yes — Boita for iPhone and Android: your dashboard, files and search, share links with receipts, upload portals, review and approval, transfers, automations, members and security. "Send from my computer" lets you pick files on your Mac or PC from the phone and have the desktop app send them on the fast path. Uploads straight from the phone go over HTTPS at standard speed. **Q: What does Boita cost?** A: Free is ₹0 with 10 GB. Pro is ₹499 a month with 1 TB, Studio ₹7,999 a month with 10 TB, Enterprise is custom. Visitors outside India see the same plans in USD, EUR, GBP, AED, SGD or AUD. No per-GB fees, no download charges, GST invoices in India. Sign up free at app.boita.io; teams moving terabytes a month can ask for a guided pilot. **Q: Do you charge per GB or per download?** A: No. Every plan is a flat monthly amount in your currency. Downloads and re-downloads are free, and there are no per-GB transfer fees. If storage overage ever applies it is shown before it happens. **Q: What does fair use mean?** A: Plans are built for real production workloads, not for reselling bandwidth. Lower plans carry a monthly transfer allowance; if you are consistently far above it we will talk to you about the right plan before anything is limited. **Q: What do the speed figures on the plan cards mean?** A: Each plan sets a ceiling per transfer: a rate per session times the number of parallel sessions. Free runs 2 sessions at up to 10 Mbps each (20 Mbps), Pro 10 sessions at up to 45 Mbps each (450 Mbps), Studio 50 sessions (2.25 Gbps), Enterprise 100 or more (4.5 Gbps and above). Your own line is the other limit: a plan never makes a 100 Mbps connection faster than 100 Mbps, but unlike ordinary uploads it lets you use all of it regardless of distance. You can lower the rate from the app during a transfer; you cannot raise it above the plan. **Q: Do my clients need a plan?** A: No. Recipients download from a share page and clients upload through a portal without an account or a plan of their own. **Q: Can I cancel any time?** A: Yes. Cancel from your workspace settings; your plan runs to the end of the billing period and your files follow the published retention policy after that. **Q: Which currency will I be billed in, and do you issue GST invoices?** A: In India, subscriptions are billed in INR with GST invoices and a GSTIN field. Elsewhere, we issue tax invoices in your local currency: USD, EUR, GBP, AED, SGD or AUD, chosen from your region and changeable on the pricing page. **Q: Do you issue GST invoices, and can I pay by UPI?** A: Every INR charge comes with a GST tax invoice in the company format, with your GSTIN on it, and refunds come with a credit note. UPI Autopay, cards and one-off monthly payments are built and switch on as soon as our payment provider completes its verification of the Boita account; until then, invoices are raised by our team. **Q: Can I get a refund?** A: Monthly plans can be cancelled at any time and run to the end of the period. Annual plans can be refunded pro rata on request within 14 days of purchase. Usage-based overage, where it applies, is not refundable. The full policy is at /legal/refunds. **Q: Who makes Boita?** A: Boita is built and operated by Aariko Systems, a small team in Pune, India. The company grew out of the founder's earlier 3D rendering business, where deliveries of 10 to 20 TB per job were normal and the transfer was the bottleneck. **Q: Is Boita a consumer file-sharing tool or an enterprise transfer suite?** A: Neither, on purpose. It has the ease of a consumer sharing link (recipients need no account and nothing to install) and the mechanics of an enterprise transfer suite (UDP acceleration, parallel sessions, resume, checksums, watch folders, an agent and a CLI), on flat plans without per-seat or per-GB pricing. **Q: What is the verifiable archive tier?** A: An optional cold tier, available on request when it ships: aged deliveries can be moved out of hot storage to an archive with proof-of-storage, on decentralised storage or on a domestic object store for India-residency workspaces, and restored on demand with the restore time shown. It is only ever an archive; transfers never touch it. The archive tier that ships today (Studio and above) moves folders to cold storage with a manifest and restores on demand. **Q: Can I run Boita on my own servers?** A: Partly. Enterprise workspaces can auto-deliver anything landing in a folder to their own transfer server or S3-compatible object storage, and can stand up a self-managed transfer node in their own AWS account with our Terraform module. The web app, accounts and receipts stay with us. **Q: Does Boita work on Linux?** A: Yes. The desktop app ships as an AppImage and a .deb, and the headless boita-agent with the boita CLI runs on servers, NAS boxes, lab instruments and render nodes under systemd. The web app works in any modern browser. **Q: Can I connect Boita to my pipeline?** A: Yes. Pro and above get scoped API keys for the same REST surface the apps use (files, share links, portals, transfers, receipts), signed webhooks, an OpenAPI description with TypeScript and Python SDKs, and REST hooks for Zapier, Make and n8n. See boita.io/developers. **Q: Which languages does the app speak?** A: English, everywhere: the app, the delivery and portal pages, the emails and this site. Other languages are not offered for now. **Q: How do I reach a person?** A: Write to hello@boita.io for anything commercial, open a ticket from Support inside the app (or support@boita.io) once you are a customer, and security@boita.io for vulnerability reports. Every plan has a promised first-reply time; Studio adds live chat, Enterprise adds scheduled calls and a named contact. A person replies. # Use cases URL: https://boita.io/use-cases ## Large-file transfer for VFX and post-production studios URL: https://boita.io/use-cases/vfx-post-production A shot is not one file; it is a folder of thousands of frames that keep arriving as the farm renders. Boita was built for that shape of work: watch folders that ship frames as they finish, transfers that use the whole connection, and delivery you can prove. ### The problem with ordinary uploads Consumer file-sharing tools and browser uploads run over TCP. Every lost packet halves the rate, and the further the far end is, the longer it takes to recover. A 2 TB delivery from Pune to a client in Los Angeles can take days that way, and a dropped connection at hour nine often means starting again. Studios have worked around this with couriers, hard drives and late nights. The Founder ran a 3D rendering business where deliveries of 10 to 20 TB per job were normal, and a transfer tool that held line rate over distance was the difference between hitting a deadline and missing it. ### What Boita does differently Boita moves data with an accelerated transfer engine over UDP with its own rate control. A transfer climbs to your line rate once and holds it whether the other end is across town or across an ocean. Big jobs run as several parallel sessions, the number set by your plan, so a single delivery can fill a fat office pipe. Transfers checkpoint as they run. A dropped link, a closed laptop or a reboot picks up where it stopped, and completed files are never re-sent. The server records a checksum for every file at transfer time and shows it in the file details, so a delivery is checked rather than assumed. ### Frames leave the farm as they finish Point a watch folder in the desktop app at your render output and a folder in your workspace. New and changed files upload on their own, and a file is only sent once it has stopped changing, so a half-written frame never ships. State is kept locally, so reopening the app does not re-upload the whole sequence. Two watch folders come with Pro; Studio has no limit. When the render finishes, the last frames are already on the server. Send the client a share link with an expiry, an optional password and a download limit; they open a clean page, see the file list and download without creating an account. ### Receiving plates and camera originals Half of a post house’s traffic is inbound. An upload portal is a request link that lets a DIT, a client or a vendor upload straight into a folder you choose. Each upload lands in its own dated inbox folder on an upload-only token scoped to exactly that folder, and both sides get an email when it completes. Clients never see the rest of your workspace. ### Built for sequences Drive understands image sequences: shot_010.####.exr is one row with the frame range, count, size and a gap warning, in Files, on the phone and on share pages, with codec, resolution and frame rate in the details panel. Previews render for images, PDFs and video, and delivery receipts carry per-file checksums with a CSV verification report, as a PDF on Studio and above. A 2 TB shot delivery on Studio, over a 1 Gbps line, takes about four and a half hours, line-limited; on a 2.5 Gbps line about two hours, plan-limited at 2.25 Gbps. The calculator on the home page models your own line and distance. - UDP-based acceleration at your line rate, parallel sessions sized to your plan - Resume after any interruption; completed files never re-sent - Watch folders with a stability wait, restart-safe, batched sends - Share links with expiry, password and download limits; no recipient account - Upload portals with per-upload inbox folders - Checksums recorded on arrival; receipts with a verification report ### FAQ **Q: Can a single transfer use our whole office connection?** A: Yes, within your plan. A big job runs as several parallel sessions; Pro allows more than Free, Studio allows many, and Enterprise is custom. The far end and your own link are the real ceilings. **Q: Do our clients need Boita to receive a delivery?** A: No. Recipients open a share page and download: through the free Boita app for full speed and resume, or in the browser with nothing to install on the slower HTTPS path. **Q: What if a frame is still being written when the watch folder sees it?** A: It waits. A file is uploaded only after it has stopped changing for a set number of seconds, so partial frames never ship. **Q: Is there per-GB pricing for a 10 TB delivery?** A: No. Plans are flat monthly amounts sized by storage, retention and seats. There are no per-GB transfer fees and no charge for downloads or re-downloads. Related: Desktop app and watch folders (https://boita.io/desktop); Upload portals (https://boita.io/portals); Watch-folder automation (https://boita.io/solutions/watch-folder-automation); Broadcast and OTT delivery (https://boita.io/use-cases/broadcast-ott-delivery) ## Episode and mezzanine delivery for broadcasters and OTT platforms URL: https://boita.io/use-cases/broadcast-ott-delivery A delivery window is a hard edge. Boita gets mezzanine masters and episode packages to the platform at the speed of your connection, resumes if anything drops, and records a checksum for every file so both sides know what arrived. ### Deadlines do not care about distance A broadcaster in one city, a post house in another and a platform ingest point on a third continent: the same package has to arrive at all of them, intact, before a cut-off. Ordinary TCP uploads slow down with distance and stumble at every lost packet, so the last few percent of a large master can take longer than the first ninety. Boita’s accelerated transfer engine uses UDP with its own rate control. It fills your connection and holds that rate over any distance, and it runs large packages as parallel sessions so one delivery can use everything your plan allows. ### Proof of delivery, not a hope Every file carries the checksum the server recorded when it arrived. The sender dashboard shows views and downloads per file and per recipient, so you know a delivery landed and who collected it. Delivery receipts list files, sizes, checksums, timestamp and who downloaded, with a CSV verification report, and as a PDF on Studio and above. Every share link has an expiry, and you can add a password and a download limit. Download tokens are minted per download and expire in minutes, so revoking a link stops new and resumed transfers immediately. Recipient verification by one-time email code names who downloaded, and a deadline priority lane makes other transfers give way to the one that is due. A 400 GB mezzanine package on Pro, over a 1 Gbps line, is on the server in about two hours, plan-limited at 450 Mbps; a 1 TB episode drop on Studio over the same line takes about two and a quarter hours, line-limited. The calculator on the home page models your own line and distance. ### Standing deliveries without scripts A watch folder in the desktop app turns a delivery folder into a standing instruction: whatever lands here goes there. It survives restarts, only sends files once they have stopped changing, and never re-sends what is already on the server. For platforms that receive from many suppliers, an upload portal gives each supplier a request link that drops their package into its own inbox folder with an email to both sides, and delivery specs flag off-spec files on arrival. Enterprise workspaces auto-deliver anything landing in a folder to their own transfer server or S3-compatible bucket, and any workspace on Pro and above drives Boita from a pipeline through scoped API keys and signed webhooks. ### Security that a compliance team can read Transfer sessions are encrypted end to end by the engine, web and share pages are HTTPS only, and each workspace has its own storage root and encryption key. Two-factor authentication and a per-workspace audit log of logins, shares, downloads and admin actions are on every plan. Single sign-on, SCIM, audit export to a SIEM and malware scanning on arrival are on Enterprise; workspace policies cap link expiry and require passwords today, with enforced MFA and allowed recipient domains coming. - Line-rate transfers over distance, parallel sessions per plan - Checksums on every file; receipts with a verification report, PDF on Studio and above - Expiry, password, download limits, recipient verification and instant revocation - Watch folders and upload portals for standing supplier deliveries - Audit log, two-factor authentication; SSO on Enterprise ### FAQ **Q: Can we prove a package was delivered on time?** A: Yes. The delivery receipt records who downloaded which file and when, with per-file checksums and a CSV verification report; on Studio and above it exports as a PDF for the platform. **Q: Does a large MXF or IMF package have a size limit?** A: Links are not capped by file size; your storage quota is the limit. Studio includes 10 TB and Enterprise is custom. **Q: Our network blocks UDP. Does Boita still work?** A: Yes. Boita falls back to an HTTPS path automatically. It is slower but still resumable and encrypted, and the app tells you which path you are on so IT knows what to open. **Q: Can suppliers deliver to us without an account?** A: Yes. Send each supplier an upload portal link. Their upload lands in its own inbox folder in your workspace and both sides get a completion email. Related: Share links and receipts (https://boita.io/send); Security posture (https://boita.io/security); Client upload portal (https://boita.io/solutions/client-upload-portal); VFX and post-production (https://boita.io/use-cases/vfx-post-production) ## Moving drone, LiDAR and photogrammetry data from the field URL: https://boita.io/use-cases/drone-survey-gis A survey week produces terabytes on a laptop in a site office with a mediocre connection. Boita is built to push that data out overnight, survive the link dropping, and let the processing team start before the drive would have reached them. ### The courier is the bottleneck Drone, LiDAR and photogrammetry projects produce point clouds, raw captures and orthomosaic tiles by the hundred gigabytes per day. Posting a drive works until it is lost, delayed or arrives corrupt, and browser uploads over a site connection tend to fail halfway through and start again. Boita’s accelerated transfer engine runs over UDP with its own rate control, so it holds your line rate regardless of the distance to the server. Transfers checkpoint as they run and resume from where they stopped after a network drop, sleep or reboot. Completed files are never re-sent. ### Point a watch folder at the capture drive Install the desktop app on the field laptop and point a watch folder at the folder where captures are offloaded. New files upload as they appear, once they have stopped changing, and the queue keeps running from the menu bar or tray with the window closed. State is kept locally, so a restart does not re-upload the week. Allowed hours per watch folder and a workspace bandwidth window, enforced by the transfer server, let the site connection be used only after hours. Include and exclude patterns are coming. A 400 GB week of captures on Pro, over a 100 Mbps site line, takes about nine hours, line-limited, which is an overnight window. Back at the office on a 1 Gbps line the same 400 GB takes about two hours, plan-limited at 450 Mbps. The calculator on the home page models your own line and distance. ### Share results with clients who have no account Processed orthomosaics and models go out as share links with an expiry, an optional password and a download limit. Clients open a page, see the files and sizes, and download; no account or plan of their own. Receiving raw data from a subcontractor works the same way in reverse through an upload portal that drops each delivery into its own inbox folder. ### Intact, and you can check Every file shows the checksum the server recorded when it arrived, so a corrupt tile is caught at ingest rather than in the deliverable. Numbered tile sets show as one row with a gap warning. Storage usage is shown on every page with an email before you reach your quota, and there are no per-GB transfer fees, so a heavy capture month does not produce a surprise bill. Projects that must be kept but rarely opened can move to the archive tier with a manifest and restore on demand (Studio and above). - Resumable, line-rate transfers from field connections - Watch folders on the offload laptop; allowed hours and bandwidth windows - Share links and upload portals with no accounts for the other side - Checksums on every file; storage usage always visible - Flat plans, no per-GB fees ### FAQ **Q: What happens when the site connection drops overnight?** A: The transfer waits and resumes from its checkpoint when the link is back. Nothing already uploaded is sent again. **Q: Can we limit how much of the site connection Boita uses?** A: Yes. A watch folder can send only between chosen hours, and the workspace can cap transfers during office hours; the transfer server enforces the cap. You can also lower the rate from the app during a transfer. **Q: Do LAS, LAZ or GeoTIFF files need special handling?** A: No. Boita moves any file type as is. Images and PDFs get previews; point-cloud viewers are not planned. **Q: Is there a Linux client for a field server?** A: Yes. The desktop app ships as AppImage or .deb, and the headless boita-agent runs watch folders on a server under systemd, with the boita CLI for scripts. Related: Desktop app and watch folders (https://boita.io/desktop); Watch-folder automation (https://boita.io/solutions/watch-folder-automation); Archives and backups (https://boita.io/use-cases/archives-backups); Plans (https://boita.io/pricing) ## Sharing DICOM studies and whole-slide images between sites URL: https://boita.io/use-cases/medical-imaging A CT series is hundreds of megabytes, an MRI study is gigabytes, a whole-slide image is 1 to 5 GB on its own, and every one of them is patient data. Boita moves them intact at the speed of your connection and puts the controls a compliance team asks about on every link: who opened it, and whether Boita could see it at all. ### Big studies, and every one of them sensitive Tele-radiology and second opinions move DICOM studies between sites: CT and MRI series of hundreds of megabytes to tens of gigabytes, and whole-slide pathology images of 1 to 5 GB each. Clinical trial imaging goes from sites to a CRO on a schedule, and research cohorts run to terabytes. Ordinary uploads over TCP are slow over distance and fail on large studies, and consumer sharing tools give a compliance officer nothing to sign off. ### Moved intact, and you can show it Boita moves data with an accelerated transfer engine over UDP with its own rate control, at your line rate whatever the distance, in parallel sessions sized to your plan, with resume after any interruption. The server records a checksum for every file on arrival, so a truncated series is caught before anyone reads it, and the delivery receipt lists each file with its checksum, who downloaded it and when, with a CSV verification report (PDF on Studio and above). Boita is not a PACS and does not interpret DICOM. It does not read or modify headers, anonymise, or render a study; it moves the files exactly as they left and keeps a record of the movement. Consent, de-identification and the legal basis for sharing remain yours. ### Controls on every link Every share link has an expiry, an optional password and a download limit, and can be revoked at any time; download tokens expire in minutes, so revocation stops resumed downloads too. Recipient verification asks the clinician to confirm their email with a one-time code before anything about the files is shown, so the receipt names who downloaded. Sender-side encrypted delivery with a passphrase encrypts files on your machine before they leave it and decrypts them on the recipient’s; Boita never holds the passphrase and cannot see the contents. If you want no image of a study rendered on our servers, previews can be switched off per link. A referring site sends a study in through an upload portal with a form for the study identifier; each upload lands in its own dated inbox folder on a token that can write there and nowhere else. ### A worked example A 20 GB MRI study reaches a reading centre from a hospital on Pro, over a 1 Gbps line, in about six minutes, plan-limited at 450 Mbps. A 200 GB batch of trial imaging to a CRO on the same plan and line takes about an hour. The calculator on the home page models your own line and distance. - DICOM, NIfTI and whole-slide files moved as they are; checksum on every file - Recipient verification by email code; password links; expiry and revocation - Sender-side encryption so Boita never sees contents; previews off per link - Audit log on every plan; SIEM export, IP allow-lists, device policies, retention rules and legal hold on Enterprise - Data in India (Mumbai); DPDP statement published ### Where the data lives, and who can reach it Files and the transfer server run in AWS Mumbai; each workspace has its own storage root and encryption key, and the trust page lists every sub-processor. A per-workspace audit log records logins, shares, downloads, deletions and admin actions, on every plan. Enterprise adds audit export to your SIEM, IP allow-lists and device policies so staff reach the workspace only from approved networks and computers, retention rules per folder, SSO and SCIM, and a legal hold that stops anything being deleted until it is lifted. A DPDP statement and a data processing summary are published. ### FAQ **Q: Is Boita HIPAA or DPDP compliant?** A: Boita publishes a DPDP statement and a data processing summary and stores data in India. It does not claim HIPAA or ISO certification; an independent penetration test and SOC 2 are planned. **Q: Can we make sure only a named clinician opens a link?** A: Yes. Turn on recipient verification: the recipient confirms their email with a one-time code before the file list is shown, and the receipt names them. Add a password and a download limit as well. **Q: Can Boita staff see our images?** A: Support works from metadata, and with sender-side encryption nobody at Boita can read the files. Break-glass access to unencrypted contents will require a ticket, a second approver and a time limit, and appear in your audit log; this process is being built. Related: Security posture (https://boita.io/security); Trust and transparency (https://boita.io/trust); DPDP statement (https://boita.io/docs/dpdp); Life sciences and genomics (https://boita.io/use-cases/life-sciences-genomics) ## Transferring research datasets to collaborators URL: https://boita.io/use-cases/research-data Sequencer output, microscope stacks and simulation dumps do not fit the tools a university gives you, and per-GB services turn a data-sharing habit into a budget line. Boita gives labs a flat plan, fast resumable transfers, and links anyone can open. ### Collaboration means moving data A FASTQ run from one sequencing core, an HDF5 stack from an instrument, a terabyte of simulation output for a co-author on another continent. Each is a transfer that the usual campus tools make slow and that per-GB transfer services make expensive. Boita’s accelerated engine runs over UDP with its own rate control, so a transfer holds your line rate over any distance and finishes in hours rather than days. Large jobs run as parallel sessions sized to your plan, transfers checkpoint and resume after any interruption, and completed files are never re-sent. ### Links for people outside your workspace Send a share link to a collaborator; they open a page, see the file list and sizes and download without creating an account. Every link has an expiry; add a password or a download limit if the data is under embargo, and see on the sender dashboard who downloaded what. Send by email straight from Boita with a message. To receive data from a partner lab, create an upload portal for a folder. Their upload lands in its own dated inbox folder with their name attached, and both sides get an email when it completes. ### Integrity you can cite Every file shows the checksum the server recorded when it arrived. Compare it with the one you computed on the instrument and you know the copy is bit-for-bit identical. Delivery receipts list files, sizes, checksums, timestamp and who downloaded, with a CSV verification report, and as a PDF on Studio and above. A 1 TB simulation output leaves a lab on Pro, over a 1 Gbps campus line, in about five hours, plan-limited at 450 Mbps; on Studio over the same line it is line-limited and takes about two and a quarter hours. What a co-author abroad sees on the way down depends on distance and loss on their side; the calculator on the home page models it. ### Budget-shaped pricing Plans are flat monthly amounts sized by storage, share retention and seats. Free gives a 10 GB workspace with three-day share retention; Pro gives 1 TB, 14 days and three seats; Studio gives 10 TB, 30 days and fifteen seats. Downloads and re-downloads are free on every plan, there are no per-GB transfer fees, and storage usage is shown on every page with an email before you reach your quota. Datasets that must be kept for a funder but rarely opened can move to the archive tier with a manifest and restore on demand (Studio and above). - Line-rate, resumable transfers of FASTQ, HDF5 and simulation output - Share links and upload portals with no accounts for collaborators - Checksums on every file; receipts with a verification report - Flat plans, no per-GB fees, downloads always free - Archive tier with manifest and restore (Studio and above) ### FAQ **Q: Does a collaborator need to install anything?** A: No. The share page offers the free Boita app for the fast path with resume, and a browser download with nothing to install on the slower HTTPS path. **Q: Is there a command-line or API for a pipeline?** A: Yes. Scoped API keys and signed webhooks (Pro and above), an OpenAPI description with TypeScript and Python SDKs, and the boita CLI that ships with the headless Linux agent. **Q: How long do shared files stay available?** A: Share retention is per plan: 3 days on Free, 14 on Pro, 30 on Studio, custom on Enterprise. You get a reminder before a link expires and can extend it with one click. **Q: Can we keep data in India?** A: Yes. Files and the transfer server run in AWS Mumbai; the trust page lists where everything lives and every sub-processor. Related: Share links (https://boita.io/send); Upload portals (https://boita.io/portals); Alternative to per-GB transfer (https://boita.io/solutions/alternative-to-per-gb-transfer); Medical imaging (https://boita.io/use-cases/medical-imaging) ## Off-site archives and project close-out backups URL: https://boita.io/use-cases/archives-backups An archive that arrives corrupt is not an archive. Boita moves close-out copies and CCTV retention sets at the speed of your connection, records a checksum for every file, and offers an archive tier with a manifest and restore on demand for data you must keep but rarely open. ### Copies that need to arrive intact, not fast-ish A finished production, a quarter of CCTV footage or a closed engineering project is a large, mostly static set of files that has to exist somewhere other than the office. Ordinary uploads of that size fail midway and silently deliver truncated files. Boita’s accelerated transfer engine holds your line rate over UDP, runs the job as parallel sessions, resumes after any interruption and never re-sends what is already on the server. The server records a checksum for every file as part of the transfer and shows it in the file details. Compare it with your local copy and the archive is verified, not assumed. A 5 TB project close-out on Studio, over a 1 Gbps office line, takes about eleven hours, line-limited: an overnight window. A 1 TB CCTV quarter on Pro over the same line takes about five hours, plan-limited at 450 Mbps. The calculator on the home page models your own line and distance. ### Standing off-site copy with a watch folder Point a watch folder at the archive share on your NAS and a folder in your workspace, from the desktop app or the headless Linux agent. New and changed files upload on their own once they have stopped changing, the queue runs in the background, and state is kept locally so a restart does not re-scan the whole tree. Allowed hours per folder and a workspace bandwidth window, enforced by the transfer server, keep the copy to overnight. Watch folders never mirror deletions: a Boita-side deletion is not applied to your NAS and a local deletion is not applied to Boita. ### Trash, versions and quotas you can see Deleted files and folders sit in the trash for a recovery window before the retention worker purges them, so a mis-click does not lose a close-out. When an upload replaces a file, the previous copy is kept as a version for the retention window. Storage usage is on every page with an email before you reach your quota. Plans include 10 GB to 10 TB of storage, custom above that, with no per-GB transfer fees on the way in or out. ### An archive tier with a manifest Aged deliveries and archive sets can be moved out of hot storage to the archive tier with a manifest, and restored on demand with the restore time shown (Studio and above); Enterprise adds retention rules per folder and legal hold. The archive tier is only ever a destination for cold data; transfers never run through it. A variant on decentralised storage with proof-of-storage is coming, on request; India-residency workspaces keep a domestic object-storage archive. - Line-rate, resumable transfers; nothing re-sent - Checksum on every file, visible in the details panel - Watch folders from a NAS share; allowed hours and bandwidth windows - Trash with a recovery window; versions when a file is replaced - Archive tier with manifest and restore (Studio and above) ### FAQ **Q: Is Boita a backup product?** A: Boita is a transfer and storage workspace. It is a good destination for off-site copies and close-out archives, with checksums, versions and a trash window, but it does not do snapshots, deduplication or bare-metal restore. **Q: How do I know the archive copy is identical?** A: Every file shows the checksum the server recorded when it arrived. Compare it with the checksum of your local copy, or use the CSV verification report on a delivery receipt. **Q: What is proof-of-storage?** A: A cryptographic proof, produced by a decentralised storage provider, that the data is still being held as agreed. Boita will record it on archived items when that archive backend ships. **Q: Can archived data stay in India?** A: Yes. The archive tier is domestic object storage; a decentralised backend is optional and coming. Related: Drive and storage (https://boita.io/drive); Desktop app and watch folders (https://boita.io/desktop); Backup, DR and NAS (https://boita.io/use-cases/backup-dr-nas); Drone, survey and GIS (https://boita.io/use-cases/drone-survey-gis) ## File transfer for advertising agencies and film production URL: https://boita.io/use-cases/advertising-film-production A campaign is many deliverables to many places: a graded master to the agency, versions to each broadcaster, a DCP to the lab, rushes back to the edit. Boita moves each at the speed of your connection, resumes if the link drops, and shows a checksum for every file so the last-minute version is the right one. ### Versions, deadlines and too many recipients A single commercial ends up as a family of files: a 4K master, cut-downs for each length, broadcaster-specific versions, social crops, a DCP for cinema, and the rushes and project files that made them. Each goes to a different party, often in a different city, and most of them are due at once. Consumer file-sharing links stall over distance because they run over TCP, and a browser upload that fails at the last percent of a 200 GB master costs an evening. Production houses have answered this with couriers and drives, which work until a drive is lost, a lab receives a corrupt copy, or the wrong version ships. ### One link per recipient, at full speed Boita moves data with an accelerated transfer engine over UDP with its own rate control. A transfer climbs to your line rate and holds it whether the broadcaster is across town or the lab is abroad. Big deliveries run as parallel sessions sized to your plan, and transfers checkpoint as they run, so a dropped link or a closed laptop resumes rather than restarts. Send a share link per recipient with an expiry, an optional password and a download limit, straight from Boita by email with a message. The recipient opens a clean page, sees the file list and sizes and downloads without creating an account. The sender dashboard shows who viewed and downloaded which file, so the account manager can see which broadcaster has collected its version. ### Rushes in, masters out An upload portal is a request link a production company or DIT uses to send rushes, camera originals or a director’s cut into a folder you choose. Each upload lands in its own dated inbox folder with the sender’s name attached, on a token that can write to that folder only, and both sides get an email when it completes. Nobody with a portal link can see anything else in your workspace. For labs and finishing houses, a watch folder in the desktop app turns a delivery folder into a standing instruction: a DCP or master dropped there uploads on its own once it has stopped changing, and a render that is still being written never ships half-done. ### Proof that the right version landed The server records a checksum for every file at transfer time and shows it in the file details, so a lab can confirm the DCP it received is the one you sent. Every link can be revoked in seconds; download tokens expire in minutes, so a superseded version stops being downloadable the moment you pull it. Delivery receipts list files, checksums, timestamp and who downloaded, as a PDF on Studio and above, where share pages and portals also carry your logo and colours on your own domain. A 200 GB graded master on Pro, over a 1 Gbps line, is on the server in about an hour, plan-limited at 450 Mbps. Plans are flat monthly amounts, billed in INR with GST invoices in India and in your own currency elsewhere, with no per-GB fees and no charge when a broadcaster downloads a version twice. - Line-rate transfers over distance; parallel sessions per plan - One share link per recipient, with expiry, password and download limits - Sender dashboard: who downloaded which version, and when - Upload portals for rushes and camera originals - Checksums on every file; receipts and branded pages on Studio and above ### FAQ **Q: Can a broadcaster download a version without an account?** A: Yes. They open the share page and download: through the free Boita app for full speed and resume, or in the browser with nothing to install on the slower HTTPS path. **Q: How do we stop an old version being downloaded after a fix?** A: Revoke the link. Download tokens expire in minutes, so revocation stops new and resumed downloads at once. Then send a fresh link for the new version. **Q: Can the share page carry the agency’s branding?** A: Yes, on Studio and above: your logo, colour and a line of your own on share pages, portals and delivery emails, on a custom domain such as delivery.youragency.com. **Q: Is a DCP folder treated any differently from a single file?** A: No. Boita moves any file or folder as is, and a folder of many files runs as parallel sessions like anything else. Images, PDFs and video get previews; there is no DCP validation. Related: Share links and receipts (https://boita.io/send); Upload portals (https://boita.io/portals); VFX and post-production (https://boita.io/use-cases/vfx-post-production); Secure transfer for NDA content (https://boita.io/solutions/secure-file-transfer-for-nda-content) ## Large-file transfer for architecture, engineering and construction URL: https://boita.io/use-cases/architecture-engineering-construction A federated BIM model, a week of laser scans and a folder of visualisation renders do not fit the tools a practice already has. Boita gets them between the office, consultants and the site cabin at the speed of the connection, resumes when the site link drops, and records a checksum for every file. ### The model is bigger than the pipe Architecture, engineering and construction projects generate files that outgrow email and shared drives quickly: federated BIM models in the tens of gigabytes, point clouds from laser and drone scans that run to terabytes, and visualisation renders for client sign-off. They move between a design office, a structural or MEP consultant, a visualisation studio and a site office, often across cities, and the site end usually has the worst connection. Ordinary uploads run over TCP, which slows with every millisecond of round trip and stumbles at every lost packet. A point-cloud upload from a site cabin tends to fail overnight and start again in the morning. Posting a drive works until it is late or arrives corrupt. ### Transfers that hold line rate and survive the site link Boita moves data with an accelerated transfer engine over UDP with its own rate control. A transfer climbs to your line rate and holds it whatever the distance, and large jobs run as parallel sessions sized to your plan. Transfers checkpoint as they run: when the site connection drops, the transfer waits and resumes where it stopped, and completed files are never re-sent. Install the desktop app on the site laptop and point a watch folder at the folder where scans are offloaded. New files upload as they appear, once they have stopped changing, with the window closed. State is kept locally, so a reboot does not re-upload the week. Allowed hours per folder and a bandwidth window enforced by the transfer server keep the site connection free during the day. A 50 GB model issue goes out from the office on Pro, over a 1 Gbps line, in about fifteen minutes, plan-limited at 450 Mbps. A 200 GB week of scans from a site cabin on a 100 Mbps line takes about four and a half hours, line-limited; the calculator on the home page models your own line. ### Issue to consultants, receive from surveyors Send a model issue or a render set as a share link with an expiry, an optional password and a download limit. The consultant opens a page, sees the files and sizes and downloads without an account; the sender dashboard shows who has collected what, and a reminder before the link expires lets a live issue be extended with one click. Receiving scans from a survey subcontractor works in reverse through an upload portal: a request link into a folder you choose, each delivery in its own dated inbox folder with the sender’s name attached, and an email to both sides. ### Verified, organised and priced for a practice Every file shows the checksum the server recorded on arrival, so a truncated point cloud is caught at ingest rather than when the model fails to open. Deleted files sit in the trash for a recovery window, and when an upload replaces a file the previous copy is kept as a version. Folder permissions per member or group (Studio and above) mean a consultant sees only their discipline’s folder. Plans are flat monthly amounts sized by storage, retention and seats, with no per-GB transfer fees and free downloads, so a heavy scanning month does not become a surprise bill. Indian practices are billed in INR with GST invoices; others see the same plans in their own currency. - Line-rate, resumable transfers from site connections - Watch folders on the site laptop; allowed hours and bandwidth windows - Share links and upload portals with no accounts for consultants - Checksums on every file; trash with a recovery window; versions - Folder permissions per member or group (Studio and above) ### FAQ **Q: Can Boita open or view BIM models and point clouds?** A: No. Boita moves and stores any file type as is. Images, PDFs and video get previews; model and point-cloud viewers are not planned. **Q: What happens when the site connection drops mid-upload?** A: The transfer waits and resumes from its checkpoint when the link is back. Nothing already uploaded is sent again. **Q: Can a consultant see only their own folder?** A: Yes. On Studio and above, folder permissions give a member or group view, download, upload or manage rights on one folder and nothing else. On any plan, share links and portals give outsiders access to exactly one folder. **Q: Is there a Linux client for a site server or NAS?** A: Yes. The desktop app ships as AppImage or .deb, and the headless boita-agent runs watch folders on a server under systemd. Related: Drone, survey and GIS (https://boita.io/use-cases/drone-survey-gis); Engineering, CAD and BIM (https://boita.io/use-cases/engineering-cad-bim); Desktop app and watch folders (https://boita.io/desktop); Transfer files between offices (https://boita.io/solutions/transfer-files-between-offices) ## Shipping multi-gigabyte game builds to publishers, QA and platform holders URL: https://boita.io/use-cases/game-development-builds A build is due to the publisher every night and it grew again this sprint. Boita moves multi-gigabyte builds and asset packs at the speed of your connection, ships each nightly from a watch folder on its own, and records a checksum so QA tests the build you actually sent. ### Builds get bigger; the deadline does not move Game studios move a lot of large files on a schedule: nightly builds to an external QA team, milestone builds to a publisher, submission packages to platform holders, and asset packs and source art to and from outsourcing partners. A modern build runs to tens of gigabytes; a milestone with symbols runs to hundreds, and the publisher is usually on another continent. Consumer file-sharing tools and browser uploads run over TCP, which slows with distance and halves its rate at every lost packet, so the nightly build lands in the morning, or fails at 95 percent and needs a producer to restart it. ### Nightly builds that ship themselves Point a watch folder in the Boita desktop app at the build server’s output folder and a folder in your workspace. Each new build uploads on its own once the build system has finished writing it; a file is sent only after it has stopped changing for a set number of seconds, so a half-written package never ships. State is kept locally, so a restart does not re-upload last week’s builds. Two watch folders come with Pro; Studio has no limit. Uploads run through an accelerated transfer engine over UDP with its own rate control, at your line rate regardless of distance, as parallel sessions sized to your plan. Transfers checkpoint as they run and resume after a network drop, sleep or reboot. Allowed hours per watch folder are live; include and exclude patterns, so a watch folder skips intermediate files, are coming. A 60 GB nightly build on Pro, over a 1 Gbps office line, is on the server in about eighteen minutes, plan-limited at 450 Mbps; a 200 GB milestone with symbols takes about an hour. The calculator on the home page models your own line. ### One link per QA vendor or publisher Send each build as a share link with an expiry, an optional password and a download limit, by email from Boita with the build notes as the message. The QA lead opens a page and downloads without an account; the sender dashboard shows who downloaded which build and when. Revoke a link the moment a build is superseded: download tokens expire in minutes, so a pulled build stops being downloadable immediately. Assets coming back from an outsourcing partner arrive through an upload portal, a request link into a folder you choose; each delivery lands in its own dated inbox folder with the sender’s name attached and an email to both sides. ### Verified builds, flat pricing, pipeline hooks The server records a checksum for every file at transfer time and shows it in the file details, so QA can confirm the package they are testing matches the one the build server produced. Two-factor authentication and a per-workspace audit log are on every plan, and recipient verification by one-time email code names who downloaded. Plans are flat monthly amounts with no per-GB fees and free re-downloads, so ten testers fetching the same 60 GB build costs nothing extra. Scoped API keys and signed webhooks (Pro and above) let the build pipeline create the share and learn when the publisher downloads it; the headless Linux agent and the boita CLI run the upload from the build server itself. - Watch folder on the build server output; nightly builds ship on their own - Line-rate transfers over distance; resume after any interruption - One link per vendor with expiry, password, download limit and instant revocation - Checksums on every file; audit log and recipient verification - API keys, webhooks, the Linux agent and the boita CLI ### FAQ **Q: Can our build pipeline create the share link automatically?** A: Yes. Use boita upload and boita share from the CLI, or the REST API with a TypeScript or Python SDK (Pro and above); a signed webhook tells you when the publisher downloads. **Q: Does a 200 GB milestone build have a size limit?** A: No per-file cap; your storage quota is the limit. Pro includes 1 TB, Studio 10 TB and Enterprise is custom. **Q: Our build server runs Linux. Can it run the watch folder?** A: Yes. The headless boita-agent runs watch folders under systemd, controlled from the web app, and the desktop app ships as AppImage or .deb. **Q: Do QA testers each need a Boita seat?** A: No. Recipients of a share link need no account or seat. Seats are for members of your workspace who upload and manage files. Related: Desktop app and watch folders (https://boita.io/desktop); Watch-folder automation (https://boita.io/solutions/watch-folder-automation); VFX and post-production (https://boita.io/use-cases/vfx-post-production); Plans (https://boita.io/pricing) ## Delivering RAW shoots and client galleries for photography studios URL: https://boita.io/use-cases/photography-studios A wedding is 4,000 RAW files; a catalogue shoot is a week of them. Boita moves whole shoots to a retoucher at the speed of your connection, gives clients a clean link with no account, and lets a second shooter send their cards straight into your workspace. ### A shoot does not fit a consumer link Photography studios move large sets of files in both directions: RAW shoots to a retoucher or lab, finished galleries to a client, catalogue images to an e-commerce team, and cards from a second shooter back to the studio. A single wedding runs to hundreds of gigabytes in RAW; a catalogue shoot runs to more. Consumer file-sharing tools cap the size or meter every gigabyte, and their browser uploads run over TCP, which stalls over distance and fails at the last percent of a big folder. ### Whole shoots, at full speed Boita moves data with an accelerated transfer engine over UDP with its own rate control. A transfer holds your line rate whether the retoucher is in the next suburb or another country, and a folder of thousands of files runs as parallel sessions sized to your plan. Transfers checkpoint as they run, so a dropped connection or a closed laptop resumes rather than restarts. Drag a shoot folder into the desktop app, or point a watch folder at the folder where cards are ingested so a shoot uploads on its own while you edit. Files are sent only once they have stopped changing, and the queue runs with the window closed. ### Galleries clients can open; cards assistants can send Send a finished gallery as a share link with an expiry, an optional password and a download limit, by email from Boita with a message. The client opens a page, sees a preview of every image, and downloads without an account. The sender dashboard shows when they downloaded, you get a reminder before the link expires, and extending or resending is one click. An upload portal is a request link into a folder you choose: a second shooter, an assistant or a client sending reference images uses it to upload straight into your workspace. Each upload lands in its own dated inbox folder with the sender’s name attached, and both of you get an email when it completes. Your logo and colours on share pages and portals, on your own domain, come with Studio and above. ### Flat plans for studios that shoot every week Every file shows the checksum the server recorded on arrival, so a corrupt RAW is caught before the retoucher opens it. Deleted files sit in the trash for a recovery window, and storage usage is shown on every page with an email before you reach your quota. A 300 GB wedding in RAW reaches the retoucher from a studio on Pro, over a 1 Gbps line, in about an hour and a half, plan-limited at 450 Mbps; the calculator on the home page models your own line. Plans are flat monthly amounts sized by storage, share retention and seats: Free gives a 10 GB workspace with three-day share retention; Pro gives 1 TB, 14 days, three seats, the desktop app, password-protected links and portals; Studio gives 10 TB, 30 days and fifteen seats. There are no per-GB fees and no charge when a client downloads their gallery again, and Indian studios are billed in INR with GST invoices. - Whole RAW shoots at line rate; resume after any interruption - Share links with expiry, password and download limits; no client account - Upload portals for second shooters and assistants - Checksums on every file; trash with a recovery window - Previews and branded pages; flat plans, no per-GB fees ### FAQ **Q: Can a client preview photos before downloading?** A: Yes. Previews render on the share page for images, PDFs and video. Recipients download at full speed through the free Boita app, or in the browser with nothing to install on the slower HTTPS path. **Q: Is there a limit on the number of files in a shoot?** A: No. A folder of thousands of RAW files runs as parallel sessions like any other transfer; your storage quota is the only limit. **Q: Can I stop a client from sharing the link onwards?** A: Add a password and a download limit, turn on recipient verification so only the named email can open it, and revoke the link when the job is done. Watermarked previews and downloads are on Studio and above. **Q: Can I send from my phone on location?** A: Yes. Boita for iOS and Android uploads photos and videos as originals over HTTPS at standard speed, and “Send from my computer” picks files on your Mac or PC from the phone and has the desktop app send them on the fast path. Related: Share links (https://boita.io/send); Upload portals (https://boita.io/portals); Large-file transfer for remote teams (https://boita.io/solutions/large-file-transfer-for-remote-teams); Plans (https://boita.io/pricing) ## Transferring multitrack sessions, stems and mixes for audio and music production URL: https://boita.io/use-cases/audio-music-production A session folder with two hundred tracks of 96 kHz audio is not an email attachment. Boita moves sessions, stems and masters between studios, mix engineers and dubbing teams at the speed of the connection, resumes if the link drops, and shows a checksum so the mix engineer opens the session you sent. ### Sessions move between many hands Audio and music production is a chain of hand-offs: a tracking studio sends the session to a mix engineer, the mix goes to a mastering house, stems go to a film’s re-recording mixer, and dubbing and localisation teams in several countries exchange dialogue reels and mixed stems for each language. A multitrack session at high sample rates runs to tens of gigabytes, and a feature’s stems and deliverables run to hundreds. Consumer file-sharing tools cap the size or meter the bytes, and their browser uploads run over TCP, which slows with distance and drops at the last file of a large session folder. Sending to a mastering house on another continent takes a night. ### Whole session folders at line rate Boita moves data with an accelerated transfer engine over UDP with its own rate control. A transfer climbs to your line rate and holds it whatever the distance, and a session folder with hundreds of files runs as parallel sessions sized to your plan. Transfers checkpoint as they run: a dropped link, a closed laptop or a reboot resumes where it stopped, and completed files are never re-sent. Drag the session folder into the desktop app for macOS or Windows, or point a watch folder at a bounce or export folder so stems upload on their own as they are printed. A file is sent only once it has stopped changing, so a bounce still being written never ships, and the queue runs from the menu bar or tray with the window closed. ### Links for engineers, portals for dubbing studios Send a mix or a set of stems as a share link with an expiry, an optional password and a download limit, by email from Boita with the revision notes as the message. The engineer opens a page, sees the file list and sizes and downloads without an account; the sender dashboard shows who downloaded which revision. Revoke a link in seconds when a mix is superseded. For localisation, give each dubbing studio an upload portal: a request link into a folder you choose. Each language’s delivery lands in its own dated inbox folder with the sender’s name attached, on a token that can write to that folder only, and both sides get an email when it completes. An engineer can leave a note on a file or the whole delivery from the share page, without a review-tool licence. ### Verified, private, on a flat plan Every file shows the checksum the server recorded on arrival, so a stem that was truncated in transit is caught before the session opens. Transfers are encrypted end to end by the engine and share pages are HTTPS only; two-factor authentication and a per-workspace audit log are on every plan. Sender-side encrypted delivery keeps an unreleased album unreadable to anyone, including Boita, until the recipient enters the passphrase. A 50 GB multitrack session on Pro, over a 1 Gbps line, reaches the mix engineer in about fifteen minutes, plan-limited at 450 Mbps. Plans are flat monthly amounts with no per-GB fees and no charge for re-downloads, so a mastering house fetching the stems twice costs nothing; Indian studios are billed in INR with GST invoices. - Session folders at line rate; parallel sessions per plan; resume - Watch folders on bounce and export folders - Share links with expiry, password and download limits; no engineer account - Upload portals per dubbing studio, each delivery in its own inbox folder - Checksums on every file; sender-side encryption and comments on share pages ### FAQ **Q: Do WAV, AIFF or session files need special handling?** A: No. Boita moves any file or folder as is. It does not transcode or alter audio. **Q: Can we make sure only the mastering engineer opens a link?** A: Add a password (Pro and above) and a download limit, and turn on recipient verification so the engineer confirms their email with a one-time code before the files are shown. **Q: What if the same session is sent twice?** A: A transfer that resumes never re-sends completed files. Sending a folder again today creates a new transfer; skipping files already on the server by checksum is on the roadmap. **Q: Can a dubbing studio abroad upload without a Boita plan?** A: Yes. A portal link needs no account or plan. The page offers the free Boita app for full speed and resume, or a browser upload with nothing to install on the slower HTTPS path. Related: Share links (https://boita.io/send); Upload portals (https://boita.io/portals); Advertising and film production (https://boita.io/use-cases/advertising-film-production); Secure transfer for NDA content (https://boita.io/solutions/secure-file-transfer-for-nda-content) ## Transferring evidence sets and forensic images for legal and e-discovery teams URL: https://boita.io/use-cases/legal-ediscovery A forensic image or a document production is large, sensitive and has to be shown to have arrived unaltered. Boita moves it at the speed of your connection, records a checksum for every file, and puts expiry, passwords and an audit log on every link. ### Large, sensitive, and every step on the record Legal and e-discovery work moves a lot of data between parties who do not share systems: a document production to opposing counsel, a forensic image of a laptop or phone to an examiner, hearing bundles and video evidence to chambers, and collections from a client’s IT team. A forensic image runs to hundreds of gigabytes, a production to terabytes, and everyone involved needs to show that what arrived is what was sent. Consumer file-sharing tools were not designed for this: browser uploads over TCP stall over distance and fail midway on large images, with little control over who can open a link and for how long. ### Integrity you can show, at full speed Boita moves data with an accelerated transfer engine over UDP with its own rate control, at your line rate regardless of distance, as parallel sessions sized to your plan. Transfers checkpoint as they run and resume after any interruption. Transfer sessions are encrypted end to end by the engine and the web app is HTTPS only. The server records a checksum for every file at transfer time. Compare it with the hash the examiner recorded at acquisition and you have shown the copy is bit-for-bit identical. Delivery receipts list files, sizes, checksums, timestamp and who downloaded, with a CSV verification report, and as a PDF on Studio and above. A 500 GB forensic image reaches the examiner from a firm on Pro, over a 1 Gbps line, in about two and a half hours, plan-limited at 450 Mbps. The calculator on the home page models your own line and distance. ### Controls on every link, and a record of every action Every share link has an expiry. Add a password and a download limit, get an email when it is downloaded, and revoke it at any time; download tokens expire in minutes, so a revoked link stops resumed transfers too. Recipient verification by one-time email code names who downloaded, and sender-side encrypted delivery keeps files unreadable to anyone, including Boita, until the recipient enters the passphrase. Inside the firm, workspaces have owner, admin and member roles, two-factor authentication, and an audit log of logins, shares, downloads, deletions and admin actions. Collections from a client arrive through an upload portal: a request link into a folder you choose, each delivery in its own dated inbox folder with the sender’s name attached. ### What Boita is, and is not Boita is a transfer and storage service. It is not a review platform, it does not process or index documents, and it does not claim any certification today; an independent penetration test is planned, a DPDP statement is published, and files and the transfer server run in AWS Mumbai. Each workspace has its own storage root and encryption key; a data processing summary is published at /legal/dpa. On Enterprise, legal hold stops anything being deleted until it is lifted, and legal-hold export packages collect a matter’s files and records. Plans are flat monthly amounts sized by storage, retention and seats, with no per-GB fees and no charge for re-downloads. - Line-rate, resumable, encrypted transfers of images and productions - Checksum on every file; receipts with a verification report - Expiry, password, download limits and instant revocation on every link - Roles, two-factor authentication and an audit log per workspace - Recipient verification and sender-side encryption; legal hold on Enterprise ### FAQ **Q: Does Boita provide chain of custody?** A: It provides the evidence for one: a server-recorded checksum on every file, a delivery receipt naming who downloaded what and when with a CSV verification report (PDF on Studio and above), and a per-workspace audit log. **Q: Can opposing counsel download without an account?** A: Yes. They open the share page, enter the password if you set one, and download: through the free Boita app for full speed and resume, or in the browser with nothing to install on the slower HTTPS path. **Q: Can Boita staff see our files?** A: Support works from metadata, and with sender-side encryption nobody at Boita can read the files. Break-glass access to unencrypted contents will require a ticket, a second approver and a time limit, and appear in your audit log; this process is being built. **Q: Can we export the audit log for a matter file?** A: Yes, on Enterprise: export the audit log or stream it to your SIEM, and produce a legal-hold export package for a matter. On other plans the log is viewable in the workspace. Related: Security posture (https://boita.io/security); Data processing summary (https://boita.io/legal/dpa); Secure transfer for NDA content (https://boita.io/solutions/secure-file-transfer-for-nda-content); Medical imaging (https://boita.io/use-cases/medical-imaging) ## Moving sequencing runs and microscopy sessions for life sciences and genomics URL: https://boita.io/use-cases/life-sciences-genomics A sequencing run is tens to hundreds of gigabytes; a whole-genome run or a cryo-EM session is terabytes, sitting on an instrument PC that is not supposed to talk to the internet. Boita moves it to the people who will analyse it at the speed of your connection, records a checksum on every file, and proves delivery when a sponsor asks. ### The instrument produces faster than the network drains A sequencer writes tens to hundreds of gigabytes of FASTQ per run, and whole-genome runs push into the terabytes once BAM and CRAM files are added. A cryo-EM or light-sheet session produces terabytes in a night. That data lands on an acquisition PC, often on an isolated VLAN, and has to reach a core facility, several labs, a bioinformatics team and collaborators abroad. The usual answers are a shared drive that copies at TCP speed over distance, a per-GB transfer service, or a portable drive. None tells you whether the copy is bit-for-bit identical, which matters when the run will be reanalysed for years. ### What Boita does about it Boita moves data with an accelerated transfer engine over UDP with its own rate control. A transfer climbs to your line rate and holds it whether the collaborator is on campus or on another continent, and large runs go as parallel sessions sized to your plan. Transfers checkpoint as they run, so a dropped link or a rebooted server resumes rather than restarts, and completed files are never re-sent. The server records a checksum for every file. Choose SHA-256 or SHA-512 for the workspace, compare it with the hash your pipeline wrote, and the copy is verified rather than assumed. A run folder of thousands of files moves as one job with its structure intact. ### Fits the instrument PC, the cluster and the pipeline On the acquisition PC, the desktop app for macOS, Windows or Linux watches the run output folder and uploads each file once it has stopped changing, so a BAM still being written never ships. On a headless acquisition server or a cluster login node, the Linux agent runs as a systemd service with watch folders up and down. Allowed hours and bandwidth windows are enforced by the transfer server, so a run drains overnight. The boita command line drops into pipeline scripts, and the REST API with a Python SDK and signed webhooks (Pro and above) lets a workflow start analysis the moment a run has landed. A core facility gives each lab an upload portal with a form for sample identifiers, so data comes in labelled, in its own dated inbox folder. ### A worked example A 500 GB whole-genome run leaves a core facility on Pro, over a 1 Gbps campus line, in about two and a half hours; the plan ceiling of 450 Mbps is the limit, not the line. A 3 TB cryo-EM session on Studio over the same line is line-limited and takes about six and three-quarter hours, an overnight window. What a collaborator abroad sees on the way down depends on distance and loss on their side; the calculator on the home page models it. - Line-rate, resumable transfers of FASTQ, BAM, CRAM and microscopy stacks - Watch folders on the instrument PC; the Linux agent on acquisition servers - boita CLI, REST API and Python SDK for pipelines (Pro and above) - Upload portals with forms for labs sending samples in - Checksum on every file; receipts with a verification report ### Proof and controls Delivery receipts list every file, its size, its checksum, the timestamp and who downloaded it, with a CSV verification report and a PDF on Studio and above: what a sponsor asks for. Share links carry an expiry, an optional password and a download limit; recipient verification by email code names the person who downloaded. Sender-side encrypted delivery with a passphrase keeps a dataset unreadable to anyone, including Boita, until the recipient enters it. SSO, retention rules and legal hold are on Enterprise. ### FAQ **Q: Does Boita do anything to FASTQ, BAM or CRAM files?** A: No. Files move and are stored as they are, with a checksum recorded on arrival. Boita does not compress, index or interpret them. **Q: The sequencer PC is on an isolated VLAN. Can it still send?** A: It needs outbound access to Boita on the fast path (UDP) or, failing that, HTTPS. Many facilities allow that from the acquisition server alone; the Linux agent sends from there and a download watch folder feeds the cluster. **Q: Can a pipeline wait until a run has fully arrived?** A: Yes. A signed webhook fires when a portal upload or a transfer completes, and boita wait-receipt blocks in a script until every invited recipient has downloaded a delivery. Related: Research data (https://boita.io/use-cases/research-data); Desktop app, agent and watch folders (https://boita.io/desktop); API, SDKs and CLI (https://boita.io/developers); Upload portals (https://boita.io/portals) ## Exchanging CAD assemblies, scans and simulation results with partners URL: https://boita.io/use-cases/engineering-cad-bim An assembly is not one file; it is a folder of thousands of linked parts, and one missing part breaks it. Boita moves whole folder trees with their structure intact at the speed of your connection, records a checksum on every file, and gives suppliers a portal to send their parts back the same way. ### The assembly breaks if one file is missing Mechanical, plant and product engineering teams exchange assemblies of thousands of part files that reference each other by relative path; a supplier who receives them flattened, or with one part dropped by a failed upload, opens a broken model. Point-cloud scans run to hundreds of gigabytes, CFD and FEA results to tens of gigabytes per case, and BIM coordination means a federated model going to every discipline weekly, with external references that only resolve if the folder layout survives. Consumer sharing tools and browser uploads run over TCP, slow down with distance and stall at the last percent of a big folder; an FTP server keeps the structure but leaves no record of what arrived or who fetched it. ### Whole trees, structure intact, verified Boita moves a folder as a folder. Sub-folders, relative paths and file names arrive as they left, over an accelerated transfer engine that uses UDP with its own rate control to hold your line rate whatever the distance, in parallel sessions sized to your plan. Transfers checkpoint as they run and resume after any interruption; completed files are never re-sent. The server records a checksum for every file, so a truncated part is caught at ingest rather than when the assembly fails to open. When an upload replaces a file, the previous copy is kept for the retention window and can be restored from Files. Numbered sets such as scan tiles or result frames show as one row with a gap warning, and move, copy and rename at scale are sequence-aware and verified before anything is deleted. ### Fits the file server, the suppliers and the project Point a watch folder on the file server, through the desktop app or the headless Linux agent, at the issue folder: whatever engineers drop there uploads on its own once it has stopped changing, and a download watch folder pulls returned parts back onto the server within a minute. Each supplier gets an upload portal with a form for job number, revision and required fields, so parts arrive labelled in their own dated inbox folder. Projects group a job’s links, portals and deliveries with dates and status; search finds any file by name, tag, size, date or your own custom fields, and weekly searches can be saved. Folder permissions per member or group (Studio and above) let a supplier’s contact see one folder and nothing else. ### A worked example A 50 GB assembly of 4,000 parts goes to a supplier on Pro, over a 1 Gbps office line, in about fifteen minutes; the plan ceiling of 450 Mbps is the limit. A 400 GB plant scan on the same plan and line takes about two hours, plan-limited again. What the supplier sees on the way down depends on distance and loss on their side; the calculator on the home page models it. - Folder trees with relative paths and names intact; nothing flattened - Checksum on every file; version history when a file is replaced - Watch folders up and down on the file server, desktop or Linux agent - Upload portals with forms for suppliers; projects and custom fields - Receipts that show who collected which revision, and when ### Proof of issue Every share link has an expiry, an optional password and a download limit, and the delivery receipt records who downloaded which file and when, with per-file checksums and a CSV verification report (PDF on Studio and above), which settles which revision a partner was working from. Recipient verification by email code names the person, and a revoked link stops resumed downloads within minutes. ### FAQ **Q: Do external references still resolve after a transfer?** A: Yes, as long as they are relative. Boita keeps the folder layout and file names exactly, so references that resolved on your file server resolve on the supplier’s. Absolute paths to your own server will not, as with any copy. **Q: Can Boita open or view CAD, BIM or point-cloud files?** A: No. Boita moves and stores any file type as is. It previews images, PDFs and video; model and point-cloud viewers are not planned. **Q: What happens when a supplier uploads a revision with the same file names?** A: The upload replaces the file and the previous copy is kept as a version for the retention window. Restore or delete any version from Files. Related: Architecture, engineering and construction (https://boita.io/use-cases/architecture-engineering-construction); Upload portals (https://boita.io/portals); Projects and search (https://boita.io/projects); Replace your FTP server (https://boita.io/solutions/replace-ftp-server) ## Delivering satellite and aerial imagery to customers, tile by tile URL: https://boita.io/use-cases/satellite-earth-observation An acquisition is thousands of tiles and tens of terabytes, and a different subset of it is due to each customer every day. Boita moves tiled datasets at the speed of your connection, records a checksum per tile, and can put a delivery straight into the customer’s own bucket. ### Daily deliveries to many customers, each of them huge Satellite and aerial imagery providers, and the analytics companies that buy from them, move tiled datasets: GeoTIFF or cloud-optimised GeoTIFF tiles in their thousands, SAR scenes, and daily acquisitions that run to tens of terabytes. Each customer wants their footprint, on time, in a form their pipeline can ingest without a person clicking through a download page. Ordinary uploads over TCP crawl over the distance to a customer on another continent, an FTP server leaves nobody sure which tiles arrived, and per-GB transfer services make a daily feed unaffordable. ### Thousands of tiles as one verified job Boita moves a folder of tiles as a single job over an accelerated transfer engine that uses UDP with its own rate control, holding your line rate whatever the distance, in parallel sessions sized to your plan. Transfers checkpoint and resume after any interruption; completed tiles are never re-sent. The server records a checksum for every tile and shows it in the file details. Numbered sets such as scene_0001.tif to scene_0480.tif appear as one row with the range, count, size and a gap warning, so a missing tile is visible before the customer finds it. Delivery receipts carry per-tile checksums, verified downloads and a CSV verification report, with a PDF on Studio and above. ### Fits the ground station, the pipeline and the customer’s bucket A ground station or processing centre pushes acquisitions in through an upload portal or a watch folder on the headless Linux agent, which runs as a systemd service and is controlled from the web app. The boita command line and the REST API with TypeScript and Python SDKs create shares, start transfers and list files from a pipeline; signed webhooks tell it when a delivery lands or a customer downloads (Pro and above). On Enterprise, auto-delivery pairs a workspace folder with the customer’s own S3-compatible bucket or transfer server: every tile that lands is pushed there within minutes, sub-folders kept, retried on failure, with a delivery log and a webhook per file. Import from an S3-compatible bucket works the other way, running on our servers rather than through a laptop. Azure Blob and native GCS connectors are coming; GCS works today through its S3-compatible endpoint. ### A worked example A 10 TB acquisition reaches the workspace from a processing centre on Enterprise, over a 10 Gbps line, in about five hours, plan-limited at 4.5 Gbps. A 1 TB customer subset goes out on Studio over a 2.5 Gbps line in about an hour, plan-limited at 2.25 Gbps. What the customer sees on the way down depends on the distance and loss on their side, which the calculator on the home page models. - Line-rate, resumable transfers of tiled datasets; nothing re-sent - Numbered tile sets as one row with gap detection - Checksum per tile; receipts with a CSV verification report - CLI, REST API, SDKs and webhooks for the pipeline (Pro and above) - Auto-delivery to the customer’s S3-compatible bucket (Enterprise) ### Controls for licensed data Imagery is licensed, so every share link has an expiry, an optional password and a download limit, and can be revoked at any time; download tokens expire in minutes. Recipient verification by email code names the person who downloaded. Priority lanes send a deadline delivery ahead of routine ones, and bandwidth windows keep the daily feed off the office connection during working hours. An audit log is on every plan, exportable to your SIEM on Enterprise. ### FAQ **Q: Can deliveries land directly in a customer’s bucket?** A: Yes, on Enterprise. Auto-delivery pushes every file landing in a workspace folder to the customer’s S3-compatible bucket or transfer server, with a delivery log and a webhook per file. **Q: Does Boita reproject, tile or read the metadata of imagery?** A: No. Tiles move and are stored as they are, with a checksum recorded on arrival. Boita is the delivery path, not a processing step. **Q: How do we know a customer received every tile?** A: A numbered set shows a gap warning if a tile is missing, and the delivery receipt lists every file with its checksum and whether the download verified. **Q: Is there a per-GB fee on a daily multi-terabyte feed?** A: No. Plans are flat monthly amounts sized by storage, retention and seats; no per-GB transfer fees and no charge for downloads. Related: Drone, survey and GIS (https://boita.io/use-cases/drone-survey-gis); API, SDKs and CLI (https://boita.io/developers); Enterprise (https://boita.io/enterprise); Drive and file sets (https://boita.io/drive) ## Moving training sets and model checkpoints between labs, vendors and the cloud URL: https://boita.io/use-cases/ml-datasets A dataset is either millions of small files or a handful of huge shards, and a checkpoint is tens of gigabytes every epoch. Boita moves both shapes at the speed of your connection, from a script or a watch folder, and into or out of your own bucket. ### Two awkward shapes, and the cloud in the middle Machine learning and data teams move training sets to an annotation vendor and get labels back, ship datasets from a lab to the cloud where the GPUs are, and pull checkpoints of tens of gigabytes per epoch back down for evaluation. The data is either millions of small samples, where per-file overhead dominates, or a few sharded archives of hundreds of gigabytes, where a single stalled stream wastes a night. Consumer sharing tools cap sizes or meter the bytes, sync tools choke on millions of files, and a browser upload over TCP to another continent never reaches the line rate you pay for. ### Small files batched, big shards in parallel Boita moves data with an accelerated transfer engine over UDP with its own rate control, holding your line rate whatever the distance. A few huge shards run as parallel sessions sized to your plan. A tree of millions of small files is grouped into transfers by the desktop app or the agent, in batches of up to 500 files or a ten-second window, so the per-file cost of an ordinary upload does not apply. Transfers checkpoint and resume after any interruption; completed files are never re-sent. The server records a checksum for every file, and the delivery receipt carries per-file checksums with a CSV verification report, so an evaluation run uses the checkpoint that was actually written. ### Fits training scripts and object storage The boita command line runs in a training script or a scheduler job on the Linux agent, and the REST API with a Python SDK, scoped API keys and signed webhooks (Pro and above) does the same from your own code. Import from an S3-compatible bucket pulls a dataset into the workspace on our servers, not through a laptop. On Enterprise, auto-delivery pushes everything landing in a workspace folder to your own S3-compatible bucket within minutes, sub-folders kept and retried on failure. GCS works today through its S3-compatible endpoint; Azure Blob and native GCS connectors are coming. An annotation vendor sends labels back through an upload portal with a form for batch identifiers and file-type rules, into its own dated inbox folder, with an email to both sides when it lands. ### A worked example A 1 TB dataset leaves a lab on Pro, over a 1 Gbps line, in about five hours, plan-limited at 450 Mbps; a 40 GB checkpoint on the same plan takes about twelve minutes. The same 1 TB on Studio over a 1 Gbps line is line-limited and takes about two and a quarter hours. What the far end sees depends on the distance and loss on its side; the calculator on the home page models it. - Millions of small files batched into transfers; huge shards in parallel sessions - boita CLI, REST API and Python SDK for scripts (Pro and above) - Import from an S3-compatible bucket; auto-delivery to your bucket (Enterprise) - Upload portals with forms for annotation vendors - Checksum on every file; receipts with a CSV verification report ### Controls on proprietary data Sender-side encrypted delivery with a passphrase keeps a dataset unreadable to anyone, including Boita, until the recipient enters it. Share links carry an expiry, an optional password and a download limit, recipient verification by email code names who downloaded, and a revoked link stops resumed downloads within minutes. Folder permissions per member or group (Studio and above) give a vendor’s contact one folder and nothing else. Two-factor authentication and an audit log are on every plan; SSO, IP allow-lists and audit export to a SIEM are on Enterprise. ### FAQ **Q: Is there a Python SDK?** A: Yes. The REST API is described in OpenAPI with TypeScript and Python SDKs, scoped API keys and a webhook console with test and retry, on Pro and above. The boita CLI ships with the Linux agent. **Q: How does Boita handle a dataset of two million small files?** A: The desktop app or agent groups new files into batches of up to 500 and sends each batch as one transfer. Your storage quota is the only limit on count. **Q: Can we go straight to our own bucket instead of Boita storage?** A: On Enterprise, auto-delivery pushes every file landing in a workspace folder to your S3-compatible bucket within minutes. Import from an S3-compatible bucket runs from the web app on our servers. Azure Blob and native GCS connectors are coming. Related: API, SDKs and CLI (https://boita.io/developers); Integrations and storage connectors (https://boita.io/integrations); Life sciences and genomics (https://boita.io/use-cases/life-sciences-genomics); Security posture (https://boita.io/security) ## Scheduled off-site copies from a NAS or file server URL: https://boita.io/use-cases/backup-dr-nas Your backup plan probably has a gap between the NAS and somewhere else. Boita fills it: a headless agent on the server sends what changed after hours, the transfer server holds the rate you set, a checksum is recorded for every file, and a second site can pull the copy down the same way. ### The off-site copy that never quite happens Most teams have a NAS or a file server, a local backup of it, and an intention to keep a copy somewhere else. The copy is the part that slips: a sync tool over TCP to a far-away region takes days for the first run, the office connection cannot be tied up during the day, and nobody can say whether last month’s copy is intact. Boita is not a backup application. It does not take snapshots, deduplicate or restore a machine bare-metal. It is the fast, verified copy from your server to somewhere else, and on to a second site, that the plan is missing. ### What Boita does about it The headless Linux agent installs in one line on Ubuntu, Debian or RHEL, runs as a systemd service under its own user, and is controlled from the web app. An upload watch folder pointed at the share sends new and changed files once they have stopped changing, in batches, with a rescan every minute; unchanged files are skipped. Allowed hours such as 22:00 to 06:00 keep it off the day’s traffic, and a workspace bandwidth window (a cap during office hours) is enforced by the transfer server, not just the client. Transfers run over an accelerated transfer engine on UDP with its own rate control, at line rate whatever the distance, and resume after any interruption; completed files are never re-sent. The server records a checksum for every file and shows it in the file details. ### A second site, versions and an archive tier A download watch folder on the agent at a second site pulls anything new or changed onto its own server within a minute, folder layout kept, and never deletes locally. Nothing is deleted on the source either: watch folders do not mirror deletions in either direction. When an upload replaces a file, the previous copy is kept as a version for the retention window and can be restored from Files. Folders you must keep but rarely open can move to the archive tier with a manifest and restore on demand (Studio and above); Enterprise adds retention rules per folder and a legal hold that stops anything from being deleted for good until it is lifted. ### A worked example A first copy of a 5 TB NAS on Studio, over a 1 Gbps office line, takes about eleven hours, line-limited; run it over a weekend and it is done by Monday. After that, a 200 GB nightly delta on Pro over the same line takes about an hour inside a 22:00 to 06:00 window, plan-limited at 450 Mbps. Distance to the second site does not change these figures on the fast path; loss on the line does, and the calculator on the home page models it. - Linux agent as a systemd service; watch folders up and down - Allowed hours per folder; bandwidth windows enforced by the server - Nothing deleted locally, ever; versions kept for the retention window - Checksum on every file; delivery receipts as proof - Archive tier with manifest and restore (Studio and above); retention rules and legal hold (Enterprise) ### Proof it happened, and what is coming Every file shows its server-recorded checksum, the audit log records uploads, downloads and deletions, and a delivery receipt with per-file checksums and a CSV verification report (PDF on Studio and above) is the document for an auditor who asks whether the copy exists and is intact. A Docker image and NAS packages for the agent are coming; today it installs on Ubuntu, Debian or RHEL, x86_64 or arm64, on any server or VM next to the NAS. ### FAQ **Q: Is Boita a backup product?** A: No. It has no snapshots, no deduplication and no bare-metal restore. It is a fast, verified copy from your server to Boita and to a second site, with versions, an archive tier and checksums, alongside the backup software you already run. **Q: Will Boita ever delete files on our NAS?** A: No. Upload watch folders only send; download watch folders only fetch and never delete locally. Deletions are not mirrored in either direction. **Q: How do we restore?** A: Download from the web app, the desktop app or the CLI at line rate, or let a download watch folder rebuild the tree on a fresh server. Files in the archive tier are restored on demand first, with the restore time shown. Related: Archives and backups (https://boita.io/use-cases/archives-backups); Desktop app, agent and watch folders (https://boita.io/desktop); Watch folders and the agent (https://boita.io/docs/desktop-watch-folders); Plans (https://boita.io/pricing) ## Getting print-ready artwork to the press and proofs to the brand, correctly the first time URL: https://boita.io/use-cases/print-packaging A press in another city is waiting on a 3 GB PDF, and the brand owner is waiting on a proof. Boita moves the artwork at the speed of your connection, takes the job in through a portal with a form so it arrives correctly labelled, and lets the brand approve or request changes on the delivery page. ### Big files, tight deadlines, and a lot of back and forth Prepress and packaging teams move print-ready PDFs and layered artwork of hundreds of megabytes to several gigabytes each, high-resolution image libraries, and dielines, between the brand, the studio and a press that is often in another city. A job that arrives with the wrong name, a missing font or an RGB file where CMYK was expected costs a round of emails and a day. Email cannot carry the files, consumer sharing links stall over distance and give the press no record, and an FTP server accepts anything without asking what it is. ### Jobs come in correctly, the first time An upload portal is a request link a customer uses to send a job into a folder you choose, with a form: job number and required fields, dropdowns, file-type and naming rules checked before the upload starts, a maximum file count, and a deadline with invited uploaders, a reminder 48 hours before and an overdue nudge. Each job lands in its own dated inbox folder with the answers attached, and both sides get an email when it completes. Delivery specs per portal or folder flag off-spec files on arrival, so a file that does not match the job is marked before anyone opens it. Portals and share pages carry your logo, colour and a line of your own, on your own domain (Studio and above). ### Proofs approved on the delivery page Send a proof as a share link. The brand owner opens a page, sees a preview of every image and PDF without downloading, and on Studio and above marks it up, approves or requests changes per file; approvers are reminded, and every decision lands on the receipt. Threads with @mentions keep the conversation on the file rather than in an inbox. Once approved, the press receives its own link with an expiry, an optional password and a download limit, and the receipt shows who downloaded which file and when, with per-file checksums. ### A worked example A 3 GB print-ready PDF reaches the workspace from a studio on Pro, over a 1 Gbps line, in about a minute, plan-limited at 450 Mbps. A 50 GB image library for a catalogue takes about fifteen minutes on the same plan and line. What the press sees on the way down depends on the distance and loss on its side; the calculator on the home page models it. - Portals with a form: job number, required fields, file-type and naming rules, deadline with reminders - Delivery specs that flag off-spec files on arrival - Review and approval on the delivery page, with image and PDF mark-up (Studio and above) - Receipts with per-file checksums; branded pages on your own domain (Studio and above) - Line-rate, resumable transfers; no per-GB fees ### Fits the studio and the press Transfers run over an accelerated transfer engine on UDP with its own rate control, at your line rate whatever the distance, and resume after any interruption. The desktop app for macOS, Windows and Linux moves whole job folders, sends from Finder or Explorer with a right click, and a watch folder on the output folder ships approved artwork on its own once it has stopped changing. Projects group a job’s links, portals and proofs with dates and status, and automations (Studio and above) can turn a landed folder into a delivery link or post to Slack the moment files arrive. ### FAQ **Q: Can a customer send a job without an account?** A: Yes. A portal link needs no account or plan. The page offers the free Boita app for full speed and resume, and a browser upload with nothing to install on the slower HTTPS path. **Q: Does Boita preflight PDFs?** A: Not in the prepress sense. Portal forms check file type, name and count before an upload starts, and delivery specs flag files that do not match the spec on arrival. Fonts, colour profiles and bleed are still checked in your prepress software. **Q: Can the portal live on our own domain with our logo?** A: Yes. Branded portals and share pages, and a custom domain such as uploads.yourstudio.com, are on Studio and above; certificates are issued for you. Related: Upload portals (https://boita.io/portals); Review and approval (https://boita.io/review); Portal forms and delivery specs (https://boita.io/docs/upload-portals); Client upload portal (https://boita.io/solutions/client-upload-portal) # Solutions URL: https://boita.io/solutions ## Send large files from India, at the speed of your connection URL: https://boita.io/solutions/send-large-files-india Distance is the tax on every upload from India. TCP slows down with every millisecond of round trip to a server in Europe or the US. Boita’s engine ignores distance, and the plans are flat, in INR, with GST invoices. ### Why uploads from India feel slow Most services put their servers in North America or Europe. A packet from Pune to Los Angeles takes a quarter of a second to get there and back, and TCP, the protocol under ordinary uploads, needs a round trip to notice each lost packet and then halves its speed. On a long, slightly lossy route that means a 1 Gbps office line delivers a small fraction of its capacity, and a 2 TB delivery takes days. Boita moves data with an accelerated transfer engine over UDP with its own rate control. The transfer climbs to your line rate once and holds it whatever the distance. Big jobs run as several parallel sessions, sized to your plan, so a single delivery can use your whole connection. Try the speed calculator on the home page with your own numbers; it states the model it uses. ### Resume, verify, prove Transfers checkpoint as they run. A dropped link, a closed laptop or a power cut resumes where it stopped; completed files are never re-sent. The server records a checksum for every file at transfer time and shows it in the file details. The sender dashboard shows who opened and downloaded what, and the delivery receipt, with the checksum verified on every completed download, exports as a PDF on Studio and above. ### Links your client can open, and portals they can upload to A share link has an expiry, an optional password and a download limit; recipients open a page and download without an account, in the browser with nothing to install or at full speed through the free Boita app. An upload portal is the reverse: a link a client abroad uses to send you plates or camera originals, landing in its own inbox folder in your workspace with an email to both sides. ### Built and billed in India Boita is built and operated by a small team in Pune. Plans are flat monthly amounts in INR with GST invoices and a GSTIN field, with no per-GB transfer fees and no charge for downloads or re-downloads. Support is in your time zone, and files, the transfer server and the database run in AWS Mumbai; the Trust page lists every location and sub-processor. Visitors outside India see the same plans in their own currency. - UDP-based acceleration that holds line rate over distance - Parallel sessions per plan; resume after any interruption - Checksums on arrival; receipts as PDF on Studio and above - Share links and upload portals with no accounts for the other side - Flat INR plans, GST invoices, no per-GB fees ### FAQ **Q: How much faster is Boita than a normal upload from India?** A: It depends on your line and the route. The calculator on the home page models TCP over your chosen route against Boita at your line rate and states its assumptions. Your plan’s session allowance and the far end are the real ceilings. **Q: Will my client abroad need to pay for anything?** A: No. Recipients download from a share page and clients upload through a portal without an account or a plan. **Q: Do you issue GST invoices?** A: Yes. Indian subscriptions are billed in INR with GST invoices and a GSTIN field. **Q: Is my data stored in India?** A: Yes. Files, the transfer server, the application and the database run in AWS Mumbai, with encrypted backups in Mumbai and Singapore. The Trust page lists every location and sub-processor; DPDP Act obligations are reflected in its retention table. Related: Speed calculator (https://boita.io/#calculator); Share links (https://boita.io/send); Plans (https://boita.io/pricing); VFX and post-production (https://boita.io/use-cases/vfx-post-production) ## A client upload portal that needs no account and no instructions URL: https://boita.io/solutions/client-upload-portal Inbound material is half the job and the half most tools ignore. A Boita portal is a link you send once: the client opens it, types their name, adds files, and the upload lands in its own folder in your workspace at full speed. ### What a portal is A portal is a request link tied to a folder you choose in your workspace. Anyone with the link can upload into it; nobody with the link can see anything else. One link can serve a whole production or a single client, and the sender’s name and email are attached to what arrives. Each upload is isolated in its own dated inbox folder on an upload-only token scoped to exactly that folder and direction, expiring in minutes. Used against any other path, the transfer server refuses it. Both the workspace owner and the person uploading get an email when the upload completes. ### Uploads that finish Portal uploads run through the same accelerated engine as everything else: UDP-based acceleration at the client’s line rate, parallel sessions, resume after a drop, and a checksum recorded for every file on arrival. Clients can upload files or whole folders straight from the browser with nothing to install, over the standard HTTPS path; for very large sends the page offers the free Boita app, which uses the fast path at their full line rate. Every arriving file can be reviewed and approved or rejected from the web or the phone; rejected uploads go to the trash, not into your folders. ### Set up in a minute Pick the folder that should receive material, create a portal link for it, and send it. Add a form if you need details with the files: required fields and dropdowns such as a job number or sample id, allowed file types, naming rules and a size cap, so the first upload is the right one. Give the request a deadline and invite named uploaders; they get a reminder 48 hours before and a nudge after. When their upload lands you get an email, the files carry checksums, and the inbox folder tells you who sent what and when. - Request links into any folder; sender name attached - Per-upload inbox folders on single-purpose tokens - Browser uploads with nothing to install; the free app for full speed - Forms, file rules, size caps, deadlines and reminders - Completion email to owner and sender; checksums recorded on arrival - Branded portals on your own domain on Studio and above ### Which plan Upload portals are included from the Pro plan. Your logo and colours on the upload page, portals on your own domain with the certificate issued for you, and portals embedded in your own site are on Studio and above. A download watch folder in the desktop app or the Linux agent makes anything a client uploads appear on your NAS or server within a minute, sub-folders intact. ### FAQ **Q: Can a client see other clients’ uploads?** A: No. Each upload is isolated in its own inbox folder on a token that can write to that folder only, in one direction, for a few minutes. **Q: Is there a size limit on portal uploads?** A: No per-file cap; your storage quota is the limit. Storage usage is shown on every page with an alert before you reach it. **Q: Do I get told when something arrives?** A: Yes. Both the workspace owner and the uploader receive a completion email, and the upload is recorded in the workspace audit log. **Q: Can the portal carry our branding?** A: Yes, on Studio and above: your name, logo, colour and a line of your own on every upload page and email, and the portal on a hostname of yours such as uploads.yourcompany.com. Related: Upload portals (https://boita.io/portals); Broadcast and OTT delivery (https://boita.io/use-cases/broadcast-ott-delivery); Security posture (https://boita.io/security); Plans (https://boita.io/pricing) ## Watch-folder automation for render output and deliveries URL: https://boita.io/solutions/watch-folder-automation A watch folder is a standing instruction: whatever lands here goes there. The Boita desktop app for macOS, Windows and Linux, and the headless agent on servers, run it in the background, only send files that have stopped changing, and never re-send what is already on the server. ### How a watch folder behaves Choose a local folder and a workspace folder in the desktop app. From then on, new and changed files upload on their own. A file is sent only after it has stopped changing for a set number of seconds, so a frame the renderer is still writing never ships. New files are grouped into transfers rather than one session per frame, which keeps thousands of small frames efficient. State is kept locally. Quit the app, reboot the machine or lose the network and the watch folder resumes where it left off without re-uploading the whole tree. Transfers run from the menu bar or system tray with the window closed; pause, resume and cancel per transfer with speed, ETA and files done. ### Same engine, full speed Watch-folder uploads use the accelerated transfer engine built into the app: UDP-based acceleration that holds your line rate over any distance, parallel sessions sized to your plan, resume after any interruption, and a checksum recorded for every file on arrival. There is no second client to install or keep updated; the engine ships inside one download for macOS (universal, notarised), Windows or Linux (AppImage and .deb), with automatic updates. ### Both directions, on desktops and servers A download watch folder runs the other way: point the app at a workspace folder and a local folder, and anything a client uploads through a portal, or a colleague drops in, lands on your NAS or server within a minute, sub-folders intact; nothing is ever deleted locally. On a render node, a lab instrument PC or a backup box without a display, the headless Linux agent runs the same watch folders up and down under systemd, controlled from the web app, and the boita CLI uploads, downloads and shares from scripts. A watch folder can send only between chosen hours, and the workspace can cap transfers during office hours, enforced by the transfer server rather than the app, so an overnight copy leaves the day’s connection alone. Deliver-from-Resolve and Deliver-from-Avid presets set the right file types and a longer stability wait for renders that grow. A preset also sets which file types are sent and which never leave (partial renders, project files, indexes); name patterns are coming. Watch folders are one-way per folder, not a two-way sync. - Stability wait: files sent once they stop changing - Restart-safe local state; batched sends - Background queue in the menu bar and tray - Download watch folders; headless Linux agent and CLI - Allowed hours and bandwidth windows enforced by the server; patterns coming ### Which plan The desktop app, the Linux agent and the CLI are included from the Pro plan, with two watch folders. Studio has unlimited watch folders and fifty parallel sessions; Enterprise is custom. ### FAQ **Q: Does a watch folder re-upload everything after a reboot?** A: No. State is kept locally, so the app picks up where it stopped and completed files are never re-sent. **Q: Can I limit a watch folder to certain file types or hours?** A: Hours, yes: a watch folder sends only between the hours you choose, and a workspace bandwidth window caps transfers during office hours. Include and exclude patterns by file type are coming; today a watch folder sends everything that lands in it. **Q: Is it two-way sync?** A: No. Each watch folder is one-way: an upload watch folder sends local files to a workspace folder, a download watch folder pulls a workspace folder to a local one. A deletion on one side is never mirrored to the other. **Q: Does it run on a render node without a display?** A: Yes. The headless Linux agent runs watch folders up and down from the shell under systemd, and ships with the boita command-line client for scripts. Related: Desktop app and watch folders (https://boita.io/desktop); VFX and post-production (https://boita.io/use-cases/vfx-post-production); Drone, survey and GIS (https://boita.io/use-cases/drone-survey-gis); Plans (https://boita.io/pricing) ## An alternative to per-GB transfer services and per-seat transfer suites URL: https://boita.io/solutions/alternative-to-per-gb-transfer Two kinds of tool dominate large-file transfer: services that meter every gigabyte, and enterprise suites that charge per seat. Boita is priced like neither: flat plans sized by storage, retention and seats, nothing per GB, downloads always free. ### What per-GB metering costs a team Per-GB transfer services are simple to start with and expensive to keep using. At a typical published rate of US$0.25 per GB, a single 1 TB delivery costs about US$250, and a team moving 10 TB a month pays roughly US$30,000 a year before storage, which is itself metered per GB per month after a few free days. Re-downloads count against your credit too, so a client who fetches a package twice costs you twice. The pricing model punishes the customers who move the most, which is everyone with a deadline and a lot of data. ### What per-seat suites cost a team Enterprise transfer suites are usually sold per seat, often in USD or EUR, with per-transfer size caps on lower tiers and upload portals and watch folders reserved for higher ones. They punish teams: every producer, coordinator and vendor contact who needs to send becomes a licence. Consumer file-sharing tools sit at the other end, cheap per seat but with browser-only TCP uploads that stall over distance and no proof of delivery. ### How Boita is priced Boita charges for the storage and speed you keep, and nothing for the bytes you move. Four plans are sized by storage (10 GB to 10 TB, custom above), share retention (3 to 30 days), seats (1 to 15) and how many parallel sessions a single transfer may use. There are no per-GB transfer fees, no download or re-download charges, and no per-transfer size caps; if storage overage ever applies it is shown before it happens, never after. Plans are billed in INR in India with GST invoices, and in USD, EUR, GBP, AED, SGD or AUD elsewhere. Free is 10 GB; Pro is ₹499 a month with 1 TB and Studio ₹7,999 a month with 10 TB, shown in your own currency outside India. ### Speed is part of the comparison Per-GB services move data over TCP or HTTP through an edge network; consumer tools use a plain browser upload. Boita moves data with an accelerated transfer engine over UDP with its own rate control, at your line rate regardless of distance, in parallel sessions, with resume and a checksum on every file. Upload portals and the desktop app with watch folders are included from the Pro plan rather than reserved for enterprise tiers. - Flat monthly plans; no per-GB transfer fees - Downloads and re-downloads free, no per-transfer size cap - Portals and desktop app from Pro, not from an enterprise tier - UDP acceleration, parallel sessions, resume, checksums - INR with GST invoices in India; local currency elsewhere ### FAQ **Q: Is there really no per-GB charge, even for downloads?** A: Correct. Plans are flat. Downloads and re-downloads are free. Lower plans carry a fair-use transfer allowance; if you are consistently far above it we talk to you about the right plan before anything is limited. **Q: What do I pay for, then?** A: Storage included in the plan, share retention, seats and how many parallel sessions a transfer may use. API keys and webhooks start on Pro; Enterprise adds a dedicated bandwidth lane, SSO and auto-delivery to your own servers. **Q: Where do the per-GB figures on this page come from?** A: From a public price list of a per-GB service, summarised in our product specification: US$0.25 per GB and storage metered after a few free days. Those terms change; check the service’s own page for current figures. **Q: Can I try it before paying?** A: Yes. Every workspace starts on Free with 10 GB and share links, with nothing to install; upgrade when you need the desktop app, portals or more storage. Related: Plans and comparison (https://boita.io/pricing); Speed calculator (https://boita.io/#calculator); Send large files from India (https://boita.io/solutions/send-large-files-india); Research data (https://boita.io/use-cases/research-data) ## An alternative to shipping hard drives URL: https://boita.io/solutions/alternative-to-shipping-hard-drives A courier is a transfer with a two-day latency, no resume and no checksum. Boita moves the same terabytes over the connection you already have, at line rate regardless of distance, and shows you when they arrived and that they arrived intact. ### What a drive actually costs Shipping a drive feels free because the bandwidth is. The rest is not: the drive itself, the courier, the customs form when it crosses a border, the day or two in transit, the person who has to copy the data on at one end and off at the other, and the occasional drive that arrives late, damaged or not at all. A drive that lands corrupt is discovered only when someone tries to read it, which is usually the day the data was needed. Studios ship drives because uploading was slower. Over TCP, an ordinary upload of 2 TB to another continent can take days, and a dropped connection often means starting again. That comparison changes when a transfer holds line rate. ### Move it over the wire, at the speed of the wire Boita moves data with an accelerated transfer engine over UDP with its own rate control. The transfer climbs to your line rate and holds it whether the far end is across town or across an ocean. Big jobs run as parallel sessions sized to your plan, so a single delivery can fill an office connection. Try the speed calculator on the home page with your own line and destination; it states the model it uses. Transfers checkpoint as they run. A dropped link, a closed laptop or a power cut resumes where it stopped, and completed files are never re-sent. Start a 5 TB job on Friday evening from the desktop app for macOS, Windows or Linux; it runs from the menu bar or tray with the window closed, and nobody has to sign for it. ### Know it landed, know it is intact The server records a checksum for every file at transfer time and shows it in the file details, so the receiving side can confirm the copy against the original before anyone does a day’s work on it. Send the result as a share link with an expiry, an optional password and a download limit; the recipient opens a page and downloads without an account, and the sender dashboard shows when they did. For data coming back the other way, an upload portal gives the sender a link into a folder you choose. For a recurring delivery, a watch folder in the desktop app turns a local folder into a standing instruction: whatever lands here goes there, sent once it has stopped changing, restart-safe. Allowed hours per watch folder and a workspace bandwidth window, enforced by the transfer server, let the copy run overnight without touching the day’s work. ### When a drive still makes sense If your connection is very slow relative to the data, a drive can still win on raw hours: run the calculator and compare. For everything else, the wire is faster, cheaper and verifiable. Plans are flat monthly amounts sized by storage, retention and seats, with no per-GB fees and no charge for downloads; a Pro workspace includes 1 TB of storage and Studio 10 TB, with Enterprise custom above that. Studio and above can also move finished folders to an archive tier with a manifest and restore them on demand. - Line-rate transfers over any distance; parallel sessions per plan - Resume after any interruption; nothing re-sent - Checksum on every file, visible before the data is used - Share links and upload portals with no accounts for the other side - Flat plans, no per-GB fees; India billing in INR with GST ### FAQ **Q: How long would 2 TB take over our line?** A: It depends on your line and the far end. The calculator on the home page models an ordinary TCP upload over your route against Boita at your line rate and states its assumptions. **Q: Our office connection is slow. Can we use it overnight only?** A: Yes. Start the transfer in the evening; it runs in the background and resumes if anything drops. A watch folder can be limited to chosen hours, and a workspace bandwidth window caps transfers during the day. **Q: What if the recipient’s network blocks UDP?** A: Boita falls back to an HTTPS path automatically. It is slower but still resumable and encrypted, and the app shows which path is in use. **Q: Is there a cheaper option for data we just need to keep?** A: Yes. On Studio and above, finished folders move to an archive tier with a manifest and come back on demand. A verifiable cold tier on decentralised storage is coming, on request. Related: Speed calculator (https://boita.io/#calculator); Archives and backups (https://boita.io/use-cases/archives-backups); Send large files from India (https://boita.io/solutions/send-large-files-india); Plans (https://boita.io/pricing) ## Replace your FTP server with something clients can actually use URL: https://boita.io/solutions/replace-ftp-server An FTP server is a shared password, a client to install, a transfer that stalls over distance and a directory nobody has cleaned in years. Boita replaces it with links anyone can open, portals anyone can upload to, a workspace with roles, and an engine that fills your connection. ### Why the FTP server is still there FTP survives in studios and agencies because it does one thing that consumer tools do not: it accepts a 500 GB folder without a per-GB bill. Everything else about it is a cost. Clients need a client and a set of credentials that gets shared around; transfers run over TCP and slow down with distance; a dropped upload leaves a half-written file with no way to tell; there is no expiry, no download count, no notification and no record of who took what. Plain FTP also sends passwords and data in the clear, and even the secured variants leave the server itself for you to patch. ### What replaces each part Transfers run through an accelerated transfer engine over UDP with its own rate control, at your line rate regardless of distance, as parallel sessions sized to your plan. They checkpoint as they run and resume after a drop, sleep or reboot, and the server records a checksum for every file on arrival, so a half-written file is impossible to mistake for a finished one. Outbound, a share link replaces the download directory: expiry, an optional password, a download limit, an email when it is downloaded, and a sender dashboard of who took what. Recipients open a page and download without credentials or an account. Inbound, an upload portal replaces the incoming directory: a request link into a folder you choose, each upload in its own dated inbox folder with the sender’s name attached, on a token that can write to that folder only. ### A workspace instead of a shared login Members join by email invitation with owner, admin or member roles, and seats are counted per plan. Two-factor authentication is live, and a per-workspace audit log records logins, shares created and opened, downloads, deletions and admin actions. Every upload and download runs on a token minted for that operation, scoped to exact paths and direction and expiring in minutes; nobody holds a standing credential to the transfer server. Folder permissions per member or group are on Studio and above, workspace policies cap link expiry and require a password on every link, and single sign-on is on Enterprise. Files sit in a Drive with folders, rename, move, search and a trash with a recovery window, and storage usage is on every page with an email before you reach your quota. ### Automation and migration A watch folder in the desktop app for macOS, Windows or Linux replaces the script that pushed to FTP: point a local folder at a workspace folder and new files upload on their own once they have stopped changing, restart-safe. The headless Linux agent runs the same watch folders on a server under systemd, and the boita CLI works from scripts. Scoped API keys and signed webhooks are included from Pro; Enterprise workspaces can auto-deliver anything landing in a folder to their own transfer server or S3-compatible bucket. Migrating is a transfer like any other: install the desktop app on the machine that can see the FTP data and upload the folders you want to keep. Plans are flat monthly amounts sized by storage, retention and seats, with no per-GB fees; the desktop app and portals are included from Pro. - Line-rate, resumable transfers with a checksum on every file - Share links and portals instead of shared FTP credentials - Roles, invitations, two-factor authentication and an audit log - Per-operation tokens; no standing credential to leak - Watch folders, agent, CLI and API keys from Pro; auto-delivery and SSO on Enterprise ### FAQ **Q: Do clients need to install anything?** A: No. Recipients download and portal uploaders upload straight from the browser over the standard HTTPS path; for very large sends the page offers the free Boita app for full speed and resume. **Q: Can we keep our folder structure?** A: Yes. Upload the folders as they are; Boita keeps the tree, and members browse it in the Drive with search across every folder. **Q: Can a script or pipeline push files like it did to FTP?** A: Yes. The boita CLI uploads, downloads, lists and shares from a script, the headless Linux agent runs watch folders under systemd, and scoped API keys with signed webhooks are included from Pro. **Q: What about a client whose IT only allows HTTPS?** A: Boita falls back to an HTTPS path automatically when UDP is blocked. It is slower but still resumable and encrypted, and the app shows which path is in use. Related: Drive and storage (https://boita.io/drive); Upload portals (https://boita.io/portals); Client upload portal (https://boita.io/solutions/client-upload-portal); Security posture (https://boita.io/security) ## Secure file transfer for NDA and pre-release content URL: https://boita.io/solutions/secure-file-transfer-for-nda-content Unreleased work needs three things from a transfer tool: only the right person can open it, you can prove what they got, and you can shut it off. Boita puts expiry, passwords, download limits and revocation on every link, records a checksum for every file, and logs every action in the workspace. ### What pre-release material needs A cut of an unreleased film, a game build under embargo, a campaign that has not launched, a client’s unreleased product photography: the material is the same shape as any large delivery, but the consequences of a leak are not. Consumer file-sharing links live forever by default, can be forwarded to anyone, and tell you nothing about who opened them. Studios sign NDAs with their clients and then hand the files to a tool that cannot honour them. ### Controls on every link, today Every Boita share link has an expiry. Add a password, which is available on Pro and above, cap the number of downloads, and get an email when someone downloads. The sender dashboard shows views and downloads per file and per recipient, so you know who collected what and when. Send by email from Boita rather than pasting a link into a chat. Revocation is immediate. Download tokens are minted per download and expire in minutes, so pulling a link stops new and resumed transfers at once, not at the next expiry. A reminder arrives before a link expires, so a live delivery is extended deliberately rather than left open. ### Inside the workspace Workspaces have owner, admin and member roles with invitation by email, two-factor authentication with recovery codes, and an audit log of logins, shares created and opened, downloads, deletions and admin actions. Each workspace has its own storage root on the transfer server with explicit path restrictions, tested for cross-tenant escapes on every change, and every upload or download runs on a token scoped to that operation. Transfer sessions are encrypted end to end by the engine, and web and share pages are HTTPS only. The server records a checksum for every file at transfer time and shows it in the file details, so both sides can confirm the delivered cut is the one that was sent. The delivery receipt shows who viewed and downloaded, with the integrity check on every completed download, and exports as PDF on Studio and above. ### Verified recipients, encrypted deliveries, and what is not claimed Recipient verification, on Pro and above, restricts a link to named email addresses confirmed by a one-time code before anything about the files is shown, so the receipt names who downloaded. Sender-side encrypted delivery works on every plan: set a passphrase when you send and the files are encrypted on your machine before they leave it; Boita never holds the passphrase. Embargoed links serve nothing before their opening time, view-only links have no download button, and on Studio and above every preview and download can carry the recipient’s name as a watermark. Workspace policies cap link expiry and require a password on every link; single sign-on, IP allow-lists, device policies and DLP hooks are on Enterprise. Enforced MFA for every member is coming. Boita does not claim any certification today. SOC 2 Type II is in progress and a penetration test follows; staff access to file contents is being put behind a ticketed, approved, time-limited process that appears in your audit log. Ask for the security overview. - Expiry, password, download limit and download notification on every link - Instant revocation through per-download tokens - Roles, two-factor authentication and an audit log per workspace - Checksums on every file; receipts with a PDF export on Studio and above - Recipient verification from Pro; passphrase encryption on every plan; SSO and DLP on Enterprise ### FAQ **Q: Can a recipient forward the link to someone else?** A: An open link can be forwarded, which is why passwords, download limits and revocation exist. Recipient verification on Pro and above restricts a link to named, code-verified email addresses, which closes that gap. **Q: Can Boita staff see the files?** A: Support works from metadata. Break-glass access will require a ticket, a second approver and a time limit, and appears in your audit log. With sender-side encrypted delivery we never hold the passphrase, so we could not read the files at all. **Q: Can we force two-factor for everyone in the workspace?** A: Two-factor authentication and passkeys are live per account. A workspace policy that enforces it for all members is coming; on Enterprise, members can sign in through your own identity provider with single sign-on. **Q: Is Boita approved for studio content-security assessments?** A: Not yet. Boita does not claim a certification. SOC 2 Type II is in progress, a penetration test follows, and industry assessments are being pursued. A written security programme is available on request. Related: Security posture (https://boita.io/security); Share links (https://boita.io/send); Legal and e-discovery (https://boita.io/use-cases/legal-ediscovery); Advertising and film production (https://boita.io/use-cases/advertising-film-production) ## Transfer files between offices with a watch folder at each site URL: https://boita.io/solutions/transfer-files-between-offices Two offices, one project. Boita’s desktop app runs a watch folder at the sending site so new files upload on their own, holds line rate across the distance between the two, and lets the receiving office pull from a workspace folder that both sides can see. ### The inter-office problem A studio with a Pune office and a Mumbai office, a practice with a head office and a site cabin, a company with a production unit in one country and a finishing unit in another: work moves between locations every day, and the tools usually in place were designed for one building. A VPN and a shared drive over TCP crawl over any real distance; cloud sync tools designed for documents choke on multi-gigabyte files and thousands of frames; and the manual answer, someone uploading a folder at the end of the day, depends on that someone. ### A watch folder at the sending end Install the Boita desktop app on a machine at the sending office and point a watch folder at the folder where finished work lands, mapped to a folder in your workspace. New and changed files upload on their own; a file is sent only after it has stopped changing for a set number of seconds, so something still being written never ships. New files are grouped into transfers rather than one session per file, state is kept locally so a restart does not re-scan the tree, and the queue runs from the menu bar or tray with the window closed. Transfers run through an accelerated transfer engine over UDP with its own rate control, at your line rate regardless of the distance between offices, as parallel sessions sized to your plan. A dropped link resumes where it stopped and completed files are never re-sent. Two watch folders come with Pro; Studio has no limit. ### The receiving end Members at the receiving office sign in to the same workspace and see the folder fill up in the Drive, with each file’s size, uploader and the checksum the server recorded on arrival. They download what they need through the desktop app at full speed, with the same resume. A download watch folder at the receiving office, on a desktop or through the headless Linux agent on the NAS, makes anything landing in the workspace folder appear locally within a minute, hands-free in both directions. Each watch folder is one-way and the pair is not a two-way sync: a deletion at one office is not mirrored to the other. Two-way sync is on the roadmap. ### Fits a company, not just a project Both offices are members of one workspace with owner, admin and member roles, two-factor authentication and an audit log of who uploaded, downloaded and deleted what. Storage usage is shown on every page with an email before you reach your quota. Allowed hours per watch folder and a workspace bandwidth window, enforced by the transfer server, let the inter-office copy run overnight; include and exclude patterns are coming. Folder permissions on Studio and above keep each site to its own folders. Plans are flat monthly amounts sized by storage, retention and seats, with no per-GB fees in either direction, so a daily flow between two sites costs the same on a busy week as a quiet one. Enterprise workspaces can auto-deliver from a workspace folder to their own transfer server or S3-compatible bucket. - Watch folder at the sending office; files ship as they finish - Line-rate transfers between sites; resume; nothing re-sent - Download watch folder or Linux agent fills the receiving NAS - Allowed hours and bandwidth windows; two-way sync coming - Flat plans; roles, two-factor authentication and audit log for the whole company ### FAQ **Q: Is this a two-way sync between the offices?** A: No. An upload watch folder at one office and a download watch folder at the other move files in one direction each; nothing is deleted on either side. Two-way sync is on the roadmap. **Q: Can both offices run watch folders into the same workspace?** A: Yes. Each machine with the desktop app can run watch folders into folders you choose. Pro includes two watch folders and Studio has no limit. **Q: What about a site with a poor connection?** A: The transfer holds whatever line rate the site has and resumes after every drop. Limit the watch folder to chosen hours and cap daytime transfers with a workspace bandwidth window, so the site connection stays free during the day. **Q: Can it push straight to the other office’s server?** A: Yes, on Enterprise: pair a workspace folder with your own transfer server or S3-compatible bucket and every file that lands is pushed there within minutes, retried on failure. On other plans a download watch folder does the job from the receiving machine. Related: Desktop app and watch folders (https://boita.io/desktop); Watch-folder automation (https://boita.io/solutions/watch-folder-automation); Architecture, engineering and construction (https://boita.io/use-cases/architecture-engineering-construction); Plans (https://boita.io/pricing) ## Large-file transfer for remote and distributed teams URL: https://boita.io/solutions/large-file-transfer-for-remote-teams A distributed team is a set of home connections in different cities, all trying to move the same large files. Boita gives them one workspace, an engine that fills whatever connection each person has, links and portals for the people outside, and the roles and audit trail an employer needs. ### Remote work is a transfer problem An editor at home in one city, a colourist in another, a producer travelling, freelancers in three time zones: every hand-off between them is a multi-gigabyte transfer over a home or hotel connection. Consumer file-sharing tools and browser uploads run over TCP, which slows with distance and stalls on lossy Wi-Fi, so the file arrives after the meeting it was for. Sync tools built for documents choke on large media, and per-GB services turn a daily habit into a bill nobody budgeted. ### Every connection, at its full rate Boita moves data with an accelerated transfer engine over UDP with its own rate control. Each transfer climbs to that person’s line rate and holds it whatever the distance to the server, as parallel sessions sized to your plan. Transfers checkpoint as they run: a dropped Wi-Fi, a closed laptop or a move between networks resumes where it stopped, and completed files are never re-sent. If a network blocks UDP, Boita falls back to an HTTPS path automatically and the app shows which path is in use. The desktop app for macOS, Windows and Linux runs the queue from the menu bar or tray with the window closed, with pause, resume and cancel per transfer; right-click "Send with Boita" in Finder or Explorer to get a link. Point a watch folder at an export folder and finished work uploads on its own once it has stopped changing; state is kept locally, so a restart does not re-upload. ### One workspace, and links for everyone else Members join by email invitation with owner, admin or member roles, and seats are counted per plan: three on Pro, fifteen on Studio, custom on Enterprise. Everyone browses the same Drive with folders, search, a trash with a recovery window and the checksum the server recorded for every file, so a colleague can confirm the export they downloaded is the one that was sent. For clients and freelancers outside the workspace, a share link with an expiry, an optional password and a download limit needs no account, and the sender dashboard shows who downloaded what. An upload portal lets a freelancer send finished work into a folder you choose, landing in its own dated inbox folder with their name attached and a completion email to both sides. Folder permissions on Studio and above keep a freelancer to one client folder and nothing else. ### Controls an employer needs, priced for a small team Two-factor authentication, passkeys and a per-workspace audit log of logins, shares, downloads, deletions and admin actions are live, as are workspace policies that cap link expiry and require a password on every link. Single sign-on and SCIM provisioning are on Enterprise; enforced MFA for all members is coming. Comments on share pages let a remote reviewer leave a note without a review-tool licence; Studio adds review roles, approvals and a frame-accurate player. Plans are flat monthly amounts sized by storage, retention and seats, with no per-GB fees and free re-downloads, billed in INR with GST invoices in India and in your own currency elsewhere. - Line-rate transfers from home connections; resume across network changes - HTTPS fallback when a network blocks UDP - One workspace with roles and seats; links and portals for outsiders - Checksums on every file; two-factor authentication; audit log - Comments and policies on every plan; folder permissions from Studio; SSO on Enterprise ### FAQ **Q: Does every team member need the desktop app?** A: For full speed and watch folders, yes; it is included from Pro for macOS, Windows and Linux. The web app covers browsing, sharing and workspace admin, and the browser path works with nothing installed, more slowly. **Q: A freelancer works from a hotel with bad Wi-Fi. Will their upload finish?** A: The transfer resumes after every drop and never re-sends completed files, and it falls back to HTTPS automatically if the hotel network blocks UDP. **Q: Can we remove a freelancer’s access when the job ends?** A: Yes. Remove the member from the workspace, or if they worked through links and portals, revoke those links; download tokens expire in minutes, so revocation is immediate. **Q: Do we pay more when the team moves more data?** A: No. Plans are flat; there are no per-GB fees. Lower plans carry a fair-use transfer allowance, and if you are consistently far above it we talk to you about the right plan before anything is limited. Related: Desktop app and watch folders (https://boita.io/desktop); Drive and storage (https://boita.io/drive); Transfer files between offices (https://boita.io/solutions/transfer-files-between-offices); Photography studios (https://boita.io/use-cases/photography-studios) ## Archive deliveries on decentralised storage, with proof they are still there URL: https://boita.io/solutions/verifiable-archive-on-decentralised-storage Most archives are a promise: the provider says the data is there, and you find out otherwise when you ask for it back. Boita’s verifiable archive tier, coming and available on request, moves aged deliveries out of hot storage to a cold tier that produces cryptographic proof the data is still held, and restores them on demand with the restore time shown. ### Why “trust us” is not an archive A studio closing a project, a firm keeping a production for years, a broadcaster with a decade of masters: all pay to keep data they rarely open, on the provider’s word that it is still intact. The failure is found at restore time, which is the one moment it cannot be fixed. Proof-of-storage changes the question from “do you trust the provider” to “show me”. Decentralised storage produces a cryptographic proof, at intervals, that a specific piece of data is still being held as agreed. Boita records that proof on the file record for each archived item, so the evidence that a close-out archive still exists is something you can see, not something you were told. ### How the archive tier works The archive is a cold tier for data that will not change: aged deliveries and close-out sets that must be kept but are rarely opened. Studio and above can already archive finished folders with a manifest and restore on demand; the decentralised backend with proof-of-storage is what is coming. A worker moves them out of hot storage to the archive, records the storage reference and the proof-of-storage on each file, and the file stays visible in your Drive with its size and the checksum the server recorded when it first arrived, so a restored copy can be verified against the original. Restoring is on demand and not instant: the expected restore time is shown, and the files come back to hot storage, where they can be downloaded or shared at full speed. Workspaces that need India data residency get a domestic cold object-storage archive instead of decentralised storage, with the same restore flow. ### Cold costs less than hot, and the trade is time Hot storage on the transfer nodes is built for speed: transfers write into it at line rate and recipients download from it minutes later. Cold storage is built for price per terabyte, and the trade is time: a restore takes a while. That is why the archive is priced as a separate cold tier, so a workspace pays hot rates only for the data it is actively moving and a lower rate for what it is keeping. Prices are not yet announced; the tier will be quoted on request alongside your plan. ### Integrity anchoring, and what the archive is not Delivery receipts, exported as PDF on Studio and above, list files, sizes, server-recorded checksums, timestamp and recipient. As an optional add-on for Studio and Enterprise workspaces, the hash of a receipt can be anchored on a public ledger, giving a tamper-evident record that a specific delivery existed at a specific time. It is an integrity feature, not a storage one; the files themselves never go on a ledger. The archive tier is only ever a destination for cold data. Transfers never run through it: uploads, downloads, share links, portals and watch folders all work against hot storage, at line rate, as they do today. Deletion on decentralised storage takes effect when the storage agreement expires rather than immediately, which is one reason India-residency workspaces get a domestic archive. - Cold tier for aged deliveries; coming, available on request - Proof-of-storage recorded on every archived file - Restore on demand with the restore time shown; domestic archive for India residency - Receipt-hash anchoring as an optional integrity add-on on Studio and Enterprise - Never part of the transfer path; priced separately ### FAQ **Q: What is proof-of-storage?** A: A cryptographic proof, produced by the archive storage provider at intervals, that the data is still being held as agreed. Boita records it on the file record for archived items. **Q: Is Boita storing our files on a blockchain?** A: No. Hot storage on the transfer nodes is where every transfer lands and where files are downloaded from. The archive tier is an optional cold destination for aged data; decentralised storage is one backend for it, and India-residency workspaces use a domestic object store instead. **Q: How long does a restore take?** A: It is not instant. The expected restore time is shown when you request one, and the files return to hot storage. **Q: What does the archive tier cost?** A: It is priced as a separate cold tier, lower per terabyte than hot storage, and quoted on request when it ships. Prices are not yet announced. Related: Archives and backups (https://boita.io/use-cases/archives-backups); Drive and storage (https://boita.io/drive); Legal and e-discovery (https://boita.io/use-cases/legal-ediscovery); Glossary (https://boita.io/glossary) ## Send 100 GB files, or 500 GB, or 1 TB: how long it takes and what it costs URL: https://boita.io/solutions/send-100-gb-files A 100 GB file is too big for email and most consumer sharing links, and slow enough over an ordinary upload that people still post drives. Here is what limits the transfer, three ways to send it with Boita, and how long each size takes per plan. ### Why 100 GB does not fit the usual tools Email stops at tens of megabytes. Consumer sharing tools cap each transfer, a few gigabytes free and a few hundred paid, and expire the link after days; the upload runs in a browser tab over TCP, and a dropped Wi-Fi sends you back to the start. Per-GB services take 100 GB and bill for every gigabyte. None were designed for a lab, a survey team, a hospital or a render farm. ### What happens over TCP when the server is far away An ordinary upload is limited by distance, not by your line. TCP waits a round trip to learn a packet was lost, then halves its rate; on a long route with a little loss, a 1 Gbps office connection delivers a small fraction of itself. Boita’s accelerated transfer engine runs over UDP with its own rate control, climbs to your line rate and holds it whatever the distance, in parallel sessions sized to your plan; if UDP is blocked it falls back to HTTPS. ### Three ways to send it with Boita From the browser, with nothing to install: sign in, drop the files, get a link. The upload runs over the standard HTTPS path and resumes after an interruption; it suits tens of gigabytes when nothing can be installed. From the desktop app for macOS, Windows or Linux, for full speed and resume: drop files on the send window, right-click “Send with Boita” in Finder or Explorer, or point a watch folder at an export folder; on a server, the Linux agent and boita CLI do the same. Through a portal, when you are receiving: a link the other side uploads into, with a form, file rules, a deadline and reminders, each upload in its own inbox folder. - Browser: nothing to install, HTTPS path, slower - Desktop app, agent and CLI: full line rate, resume - Portal: the other side uploads into your folder ### How long 100 GB, 500 GB and 1 TB take, by plan Throughput is the lower of your plan ceiling and your line. Plan ceilings are Free 20 Mbps, Pro 450 Mbps, Studio 2.25 Gbps and Enterprise 4.5 Gbps and up, from 45 Mbps sessions (10 Mbps on Free). 100 GB is 800,000 megabits: about 30 minutes on Pro over a 1 Gbps line, plan-limited at 450 Mbps; about 2.2 hours on Pro over a 100 Mbps home line, line-limited; about 13 minutes on Studio over a 1 Gbps line, line-limited. On Free the arithmetic gives about 11 hours at 20 Mbps, but Free includes 10 GB of storage, so 100 GB is a Pro job. 500 GB is 4,000,000 megabits: about 2.5 hours on Pro and 1.1 hours on Studio over a 1 Gbps line. 1 TB is 8,000,000 megabits: about 4.9 hours on Pro; on Studio about 2.2 hours over a 1 Gbps line and about an hour over 2.5 Gbps, where the 2.25 Gbps ceiling takes over. An ordinary TCP upload depends on distance and loss; the calculator on the home page models your route. ### What the recipient sees, and what it costs The recipient gets a page with the file list and sizes and downloads without an account, in the browser or at full speed with resume in the free app. You see who viewed and downloaded what, with the checksum recorded at transfer time verified on every download; Studio and above export the receipt as PDF and CSV. Every link has an expiry; add a download limit, a password or recipient verification (Pro and above), or a passphrase that encrypts the files before they leave your machine. Plans are flat: Free ₹0 with 10 GB, Pro ₹499 with 1 TB, Studio ₹7,999 with 10 TB, Enterprise custom, in local currency outside India. No per-GB fee, no download charges, no size cap. ### FAQ **Q: Can I send 100 GB on Free?** A: No: Free has 10 GB of storage and two sessions at 10 Mbps. 100 GB needs Pro, with 1 TB of storage and the desktop app. **Q: Does the recipient need an account or the app?** A: No. They open a page and download in the browser; the free app is optional. **Q: What if my upload is interrupted?** A: It resumes where it stopped, in the app, agent or browser; completed files are never re-sent. **Q: Is there a maximum file size?** A: No; your plan’s storage quota is the only limit. Related: Share links (https://boita.io/send); Desktop app, agent and CLI (https://boita.io/desktop); Plans (https://boita.io/pricing); Docs: sending files (https://boita.io/docs/sending-files) ## Resumable file transfer: what resume actually means, and where it works URL: https://boita.io/solutions/resumable-file-transfer Every tool says it resumes. The question is what happens to the 600 GB you had already sent when the connection dropped. Boita checkpoints during the transfer, never re-sends a completed file, and picks up after a drop, a sleep, a reboot or a quit, on the desktop app, the headless agent and the browser path. ### What resume really means A transfer of a 1 TB folder is thousands of files and a long tail of partial ones. A tool that “retries” starts the current file again, and a tool that only remembers which files finished throws away hours of a single large file. Boita’s accelerated transfer engine checkpoints as it runs: when a transfer restarts, files already on the server are skipped, and a file that was part-way through continues from where it reached rather than from zero. That holds across the interruptions that actually happen: the Wi-Fi drops, the lid closes, the machine reboots for an update, you quit the app, the office loses power overnight. Reopen the app, or let the agent restart under systemd, and the queue carries on; nothing that already arrived is re-sent. ### Where it works On the desktop app for macOS, Windows and Linux, every upload and download resumes, including watch folders: state is kept locally, so a restart does not re-scan or re-upload the tree. On the headless Linux agent and the boita CLI, a job that dies with the shell or the host resumes when it is run again. On the browser path, with nothing installed, an upload or download over HTTPS resumes after an interruption too; it is slower than the fast path, and also what Boita falls back to when a network blocks UDP. - Desktop app: resume after drop, sleep, reboot or quit; watch folders restart-safe - Linux agent and CLI: resume when the job runs again - Browser path: resumable over HTTPS, slower, nothing to install - Completed files never re-sent; partial files continue from their checkpoint ### Why it matters: site offices, field laptops, overnight jobs A survey team offloading a week of captures from a site cabin, a field laptop sending microscopy stacks from a hotel, a hospital pushing a study to a referral centre, a render farm delivering overnight, a NAS copying to a second site after hours, a games studio shipping a build before a deadline: all of them start transfers nobody will be watching. Without real resume, a two-second outage at three in the morning costs the whole night. With it, it costs two seconds. ### Tokens, revocation and checksums after a resume Every download runs on a token minted for that download, scoped to exact paths and one direction, expiring in minutes; a resumed download is issued a fresh token from the same link, so a recipient who lost their connection can carry on. The other side of the same design is revocation: pull the link and there is no token to resume with, so new and resumed transfers stop at once rather than at the next expiry. The server records a checksum, SHA-256 or SHA-512 as chosen per workspace, for every file once it is complete, whatever route it took. A file assembled across three sessions and two reconnects carries one checksum for the whole file, shown in its details, and the delivery receipt shows the integrity check on every completed download; a half-written file cannot be mistaken for a finished one. ### A worked example A 1 TB job on Pro over a 1 Gbps line runs at the plan ceiling of 450 Mbps and takes about 4.9 hours. Say the connection drops at hour three: about 607 GB has arrived. On resume the remaining 393 GB takes about 1.9 hours, so the job finishes at roughly five hours instead of eight; a tool that restarts from zero pays the full 4.9 hours again. How long an ordinary upload would take depends on distance and loss; the calculator on the home page models it. ### FAQ **Q: Does a resumed transfer re-send files that were already complete?** A: No. Files already on the server are skipped and a part-sent file continues from its checkpoint. **Q: What happens if the link is revoked while a download is paused?** A: The download cannot resume. Tokens are minted per download and expire in minutes; revoking the link stops new and resumed transfers immediately. **Q: Is the checksum still valid after a resume?** A: Yes. The checksum is recorded on the complete file at the end of the transfer, however many sessions or reconnects it took, and verified on every completed download. **Q: Does the browser upload resume too?** A: Yes, over HTTPS. It is slower than the fast path in the app or agent, but an interruption does not send you back to the start. Related: Desktop app, agent and CLI (https://boita.io/desktop); Docs: troubleshooting (https://boita.io/docs/troubleshooting); Docs: watch folders (https://boita.io/docs/desktop-watch-folders); Send 100 GB files (https://boita.io/solutions/send-100-gb-files) ## An alternative to consumer file-sharing tools, for teams that have outgrown them URL: https://boita.io/solutions/alternative-to-consumer-file-sharing Consumer sharing links are fine until the first 200 GB delivery, the first client who asks for proof, or the first upload that stalls at 80 percent. Boita is built for the point where a team has outgrown them: links that carry terabytes, receipts with checksums, portals for inbound work, a desktop app and agent, and flat plans. ### Where consumer sharing links run out The pattern is the same in a lab, a hospital, an engineering practice, a games studio or a print house. A per-transfer size cap that the paid tier raises but never removes. Expiry games: a link that dies in a week unless someone pays. No receipt beyond “opened” and no checksum, so nobody can prove what arrived. Nothing for inbound work beyond inviting an outsider into a folder. Upgrades priced per gigabyte or per seat, so the people who move the most pay the most. And the mechanics: uploads run in a browser tab over TCP, which slows with distance and stalls on lossy Wi-Fi, with no watch folder, no command line and no agent for a server. No audit log says who downloaded what, which matters the first time a client asks. ### The two side by side, by category By category, naming nobody: - Transfer size: capped per transfer. Boita: no per-transfer cap; the storage quota is the limit - Expiry: fixed and short unless you pay. Boita: an expiry you set, a reminder before it lapses, one-click extend - Proof: an “opened” notice. Boita: who viewed and downloaded, a checksum verified on every download, PDF and CSV on Studio and above - Inbound: an invitation into a folder. Boita: portals with a form, file rules, deadlines and review - Upload path: browser only, over TCP. Boita: browser too, plus a desktop app, agent and CLI on the fast path - Resume: restart from the top. Boita: checkpoints; completed files never re-sent - Controls: a password at best. Boita: download limits, recipient verification, passphrase encryption, embargo, view-only, instant revocation - Records: none. Boita: an audit log of logins, links, downloads, deletions and admin actions - Price: per gigabyte or per seat. Boita: flat plans, no per-GB fee, downloads free ### Links that survive terabytes A Boita share link carries a file or a whole folder tree, whatever the size, with an expiry, a download limit and an email when it is downloaded; a password and recipient verification from Pro. Recipients open a page and download in the browser with nothing to install, or at full speed with resume in the free app. Transfers run through an accelerated transfer engine over UDP with its own rate control, at your line rate whatever the distance, in parallel sessions sized to your plan: a 1 TB delivery on Pro takes about 4.9 hours over a 1 Gbps line, plan-limited at 450 Mbps. ### Receipts, portals and the tools behind the link The server records a checksum for every file at transfer time. The receipt shows who viewed and downloaded, when, with the integrity check on every completed download; a delivery note as PDF is on every plan, and Studio and above export the receipt as PDF with a CSV verification report. A portal turns the direction round: a link a supplier, a referring clinic or a subcontractor uploads into, with a form, file rules, a size cap, a deadline and reminders, each upload in its own inbox folder for review before it goes anywhere. Behind the link, from Pro: the desktop app for macOS, Windows and Linux with upload and download watch folders; the headless Linux agent and boita CLI; scoped API keys, signed webhooks and SDKs; Zapier, Make and n8n through REST hooks. Studio adds Slack and Teams, automations, review and approval, branding and your own domain. ### What it costs Plans are flat: Free ₹0 with 10 GB, Pro ₹499 with 1 TB, Studio ₹7,999 with 10 TB, Enterprise custom, in USD, EUR, GBP, AED, SGD or AUD outside India. No per-GB fee, no charge for downloads or re-downloads, GST invoices in India. Data is held in AWS Mumbai. ### FAQ **Q: Do our clients have to change anything?** A: No. They receive a link and open a page, as before, and download without an account; the free app is optional. **Q: Can we move our existing folders over?** A: Yes. Upload the folders as they are from the desktop app, or import from an S3-compatible bucket; Boita keeps the tree. **Q: Do we lose the browser upload our team is used to?** A: No. The web app uploads from the browser over the standard HTTPS path; the desktop app is there when speed and resume matter. **Q: Is there a free plan?** A: Yes. Free has 10 GB, share links with expiry and the sender dashboard. Related: Share links (https://boita.io/send); Upload portals (https://boita.io/portals); Alternative to per-GB transfer (https://boita.io/solutions/alternative-to-per-gb-transfer); Plans (https://boita.io/pricing) ## S3 to on-prem transfer, and back: object storage to your own servers at line rate URL: https://boita.io/solutions/s3-to-on-prem-transfer Tens of terabytes in a bucket and a server in the building that needs them, or the reverse. Boita imports from any S3-compatible bucket on its own servers; a download watch folder, the Linux agent or the CLI then pulls the data on-prem at line rate with resume, and upload watch folders or auto-delivery send it back. ### Why a browser download or a sync client is the wrong tool Pulling 10 TB out of object storage through a browser, a cloud console or a sync client built for documents means a TCP stream per object, throttled by distance to the region, a restart from the top when a laptop sleeps, and no record that what landed matches what was stored. Every team hits it eventually: an ML team pulling a training set to a GPU box, a lab restoring an archive to an instrument PC, a geospatial firm bringing imagery on-prem, an IT team seeding a backup appliance. ### Bucket to on-prem in two steps Step one: import. Connect the bucket and choose what to pull; the import runs on our servers into a workspace folder, not through your laptop. Any S3-compatible bucket works, on every plan, and the workspace shows each file with its size and the checksum recorded on arrival. Step two: pull it on-prem at line rate. Put a download watch folder on the server, in the desktop app or the headless Linux agent under systemd, pointed at that workspace folder; everything that lands appears on the NAS within a minute, sub-folders included, and nothing is ever deleted locally. Or script it with boita download from the CLI. The transfer runs through the accelerated transfer engine over UDP, in parallel sessions, resuming after any interruption. Throughput is the lower of the plan ceiling and the line. 10 TB is 80,000,000 megabits. On Studio, fifty sessions at 45 Mbps allow 2.25 Gbps, so over a 1 Gbps line the pull is line-limited: about 22 hours, unattended. On Enterprise with 100 sessions over a 10 Gbps line the 4.5 Gbps plan ceiling takes over: about 5 hours. A 10 TB set just fits Studio’s 10 TB of storage; larger sets run in batches or on Enterprise, where storage is custom. ### On-prem to bucket: the reverse Going the other way, an upload watch folder on the server, or boita upload from a script, sends new files to a workspace folder as they finish; allowed hours and a workspace bandwidth window, enforced by the transfer server, keep the day’s connection free. Enterprise pairs the folder with your own S3-compatible bucket or transfer server and pushes every file that lands within minutes, retried on failure, with a delivery log. On other plans, share the folder as a link or let the far end pull it with a download watch folder. - Import from any S3-compatible bucket, on every plan, run on our servers - Download watch folder, Linux agent or CLI pulls to the NAS at line rate with resume - Upload watch folder or CLI sends back; auto-delivery to your own bucket on Enterprise - Checksum on every file; allowed hours and bandwidth windows enforced by the server ### Other clouds, and what is not offered yet Google Cloud Storage works today through its S3-compatible endpoint; native GCS and Azure Blob Storage connectors are coming. An SFTP endpoint is coming; Boita does not offer one today. The agent as a Docker image and as packages for the common NAS platforms is coming; today it installs on any Linux server with a shell. ### What it costs, and what it does not change Boita adds no per-GB fee of its own, in either direction, and no charge for downloads. Egress from a bucket is your cloud provider’s charge and is unchanged by Boita; what changes is the hours, the retries and the person watching them. Plans are flat: Pro ₹499 with 1 TB, Studio ₹7,999 with 10 TB, Enterprise custom. ### FAQ **Q: Does Boita reduce cloud egress charges?** A: No. Egress is billed by your cloud provider whatever tool moves the data; Boita adds no per-GB fee of its own. **Q: Does the data pass through my laptop?** A: No. The import runs on our servers into your workspace; the pull runs from the app, the agent or the CLI on your server. **Q: Can it go straight from the bucket to my server without the workspace?** A: No. The import lands in your workspace first, which gives you the checksum, the audit trail and the resume; plan storage applies while it is there. **Q: Does it work with Azure or Google Cloud?** A: Google Cloud Storage through its S3-compatible endpoint today; native GCS and Azure connectors are coming. Related: Backup, DR and NAS (https://boita.io/use-cases/backup-dr-nas); ML and data teams (https://boita.io/use-cases/ml-datasets); Enterprise (https://boita.io/enterprise); Docs: watch folders (https://boita.io/docs/desktop-watch-folders) # Glossary URL: https://boita.io/glossary - **UDP acceleration.** A way of moving files that sends data over UDP with its own rate control instead of relying on TCP. TCP slows down at every lost packet and needs a round trip to recover, so it never fills a long-distance link. A UDP-accelerated transfer measures the path itself, climbs to the line rate once and holds it whatever the distance. Boita’s accelerated transfer engine works this way. - **TCP.** Transmission Control Protocol, the transport under ordinary web uploads and downloads. It is reliable but treats every lost packet as congestion and halves its speed, and it needs one round trip to the far end to notice. Over long, slightly lossy routes this is why a fast office line delivers a small fraction of its capacity. - **Line rate.** The full speed of your connection, for example 1 Gbps on a fibre line. A transfer running at line rate is limited by your link, not by the protocol or the distance. Boita is modelled at the line rate in the speed calculator; your plan’s session allowance and the far end are the real ceilings. - **Round-trip time (RTT).** The time for a packet to reach the other end and for the reply to come back, typically 200 to 300 milliseconds between India and North America. TCP throughput falls as RTT rises; UDP acceleration does not depend on it. - **Packet loss.** The share of packets that never arrive, usually a fraction of a percent on a decent route. Even small loss collapses TCP throughput over distance because each loss is treated as congestion. Boita’s engine retransmits only the lost packets and keeps the rate. - **Resumable transfer.** A transfer that checkpoints as it runs, so that after a network drop, sleep, restart or a closed laptop it continues from where it stopped rather than from the beginning. In Boita, completed files are never re-sent. - **Multi-session (parallel sessions).** Running one large transfer as several sessions at once, each using the connection fully, so a single job can fill a fatter pipe. Boita sizes the number of sessions to your plan: basic on Free, more on Pro, many on Studio, custom on Enterprise. - **Checksum.** A short fingerprint computed from a file’s contents. If two copies have the same checksum they are bit-for-bit identical. Boita’s server records a checksum for every file at transfer time and shows it in the file details, so a delivery is verified rather than assumed. - **Delivery receipt.** A record produced when a recipient finishes downloading: the files, sizes, checksums, timestamp and recipient, as PDF and email, with the integrity check on every completed download. Studio and above; the sender dashboard on every plan shows views and downloads per file and per recipient. - **Share link.** A link to a set of files that a recipient opens without an account. Every Boita share link has an expiry; you can add a password, a download limit, and an email when someone downloads. Revoking a link stops new and resumed transfers immediately. - **Download token.** A short-lived credential minted for one download, scoped to exact paths and direction and expiring in minutes. Because every transfer runs on its own token, revoking a share stops resumed transfers as well as new ones. - **Upload portal (request link).** A link that lets someone outside your workspace upload into a folder you choose, without an account. Each upload lands in its own dated inbox folder on an upload-only token scoped to that folder, and both sides get an email when it completes. - **Watch folder.** A local folder the desktop app monitors and mirrors, one way, to a workspace folder. New and changed files upload on their own once they have stopped changing. State is kept locally so a restart does not re-upload the tree. - **Stability wait.** The rule in a watch folder that a file is sent only after it has stopped changing for a set number of seconds. It keeps files still being written or copied from shipping early. - **HTTPS fallback.** The path Boita uses automatically when a network blocks UDP. Slower than the accelerated path but still resumable and encrypted; the app shows which path a transfer is on so IT knows what to open. - **Encryption in transit and at rest.** In transit: every transfer session is encrypted end to end by the engine, and web, API and share pages are HTTPS only. At rest: files are stored with server-side encryption and a distinct key per workspace, so deleting a workspace can destroy its key. Key handling is being finalised before the pilot. - **Workspace.** The unit of a Boita account: its own storage root on the transfer server, its own encryption key, members with owner, admin and member roles, seats counted per plan, and its own audit log. Nothing is shared between workspaces. - **Share retention.** How long a share link stays available by default: 3 days on Free, 14 on Pro, 30 on Studio, custom on Enterprise. You get a reminder before a link expires and can extend or resend it with one click. - **Data residency.** Where your files physically live. Boita is built and operated in India: files, the transfer server, the application and the database run in AWS Mumbai, with encrypted backups in Mumbai and Singapore. Regional nodes elsewhere are available on request for Enterprise, as is a self-managed node in your own AWS account. - **DPDP Act 2023.** India’s Digital Personal Data Protection Act. It sets out the duties of a data fiduciary (the customer deciding why data is processed) and a data processor (Boita, processing it on the customer’s instructions), including notice, consent, purpose limitation and deletion. Boita’s alignment work is in progress and reviewed with Indian counsel before launch. - **Fair use.** Plans are flat and carry no per-GB fees, but lower plans have a monthly transfer allowance so bandwidth cannot be resold. If a workspace is consistently far above it, Boita talks to the customer about the right plan before anything is limited. - **Image sequence.** A set of numbered files that belong together: tile_0001.tif to tile_2400.tif, scan_0001.dcm to scan_0512.dcm, shot_010.1001.exr to shot_010.2204.exr. Drive shows such a set as one row with its range, count, size and any gaps; moves, copies and shares treat it as one thing. - **Verifiable archive (proof-of-storage).** An optional cold storage tier, coming and available on request, where aged deliveries are moved out of hot storage to decentralised storage that produces cryptographic proof that the data is still held, and restored on demand with the restore time shown. India-residency workspaces get a domestic object-storage archive instead. The archive is never part of the transfer path. - **Audit log.** A per-workspace record of logins, shares created and opened, downloads, deletions, permission changes and admin actions, shown in the Activity feed. Enterprise workspaces export it as CSV or JSON Lines and stream it to a SIEM. - **Transfer acceleration.** The general term for moving files faster than a plain TCP upload would over the same line: a transport with its own rate control that is not slowed by distance or packet loss, run as parallel sessions, with resume and integrity built in. In Boita it is the accelerated transfer engine behind every upload, download, watch folder and agent. - **Checksum verification.** Comparing a file’s checksum (SHA-256 by default, SHA-512 by policy) recorded at transfer time with the bytes that arrived, so a delivery is checked rather than assumed. Boita records the checksum on the server for every file, shows it in the file details and on the receipt, and marks each completed download as verified. - **Speed receipt.** The line on every finished transfer that says how big, how long and how fast it was, and how much faster than a typical upload over that route. The comparison is a stated model of TCP (the Mathis model with four streams), never a measurement of another product, and the assumption is printed with it. - **Priority lane (Deadline, Background).** A per-transfer setting. Deadline makes the workspace’s other running transfers make room on the transfer node until it finishes; Background asks for a third of the session rate and stays out of the way. Enterprise workspaces also get a dedicated bandwidth lane of their own. - **Headless agent and CLI.** boita-agent is the Linux service that runs upload and download watch folders on a server, NAS or render node without a window, controlled from the web app. The boita command-line client uploads, downloads, lists, shares, waits for a receipt and tests your line from scripts. Both carry the same engine as the desktop app. - **Object storage (S3-compatible).** Cloud storage addressed as buckets and objects through the S3 API. Boita imports folders from any S3-compatible bucket (the import runs on our servers) and, on Enterprise, auto-delivers everything that lands in a folder to your own bucket. Buckets on other major clouds work through their S3-compatible endpoints; native connectors are coming. - **Embargo.** An opening time on a share link. Until then the delivery page shows a countdown and serves nothing — no previews, no downloads — and the recipient can add the moment to their calendar. Used for releases, results and anything with a publication time. - **Watermark (visible).** A per-recipient mark rendered into every preview, video and image a recipient sees or downloads from a watermarked link, carrying their name and yours. Copies are rendered once per recipient and removed when the link ends. Studio and above. - **Forensic watermark.** An invisible per-recipient mark in video deliveries that survives re-encoding well enough to be read back from a leaked clip with the "who leaked this?" tool. Enterprise. - **Review roles (viewer, reviewer, approver).** What each named recipient of a share link may do: viewers see and download; reviewers comment and request changes; approvers approve or request changes per file, with reminders. Decisions are per version and land on the receipt. Studio and above. - **Proxy (review copy).** A small derived copy of a file rendered on our servers for review: 720p H.264 video, a waveform, a contact sheet, a 2048-pixel image, one page image per PDF page. The player and viewers work from proxies; the original is never served to the browser. - **Legal hold.** A workspace policy that stops anything in scope from being deleted for good — trash is not emptied, versions are kept, send-mode links do not delete their files — until it is lifted, with the reason recorded. Enterprise can export a hold as a package for counsel. - **DLP (data loss prevention) hook.** A call to your own data-loss-prevention service before a share link is created; Boita honours the answer, so your classifier decides what may leave. Enterprise. - **SSO and SCIM.** Single sign-on: members sign in through your identity provider over OpenID Connect, routed by email domain and optionally enforced. SCIM: the same directory creates, updates and deactivates members and groups in Boita. Enterprise. - **SIEM stream.** A signed HTTPS stream of every workspace event to one endpoint of your choosing (the same signature scheme as webhooks), so your security information and event management system sees Boita activity in near real time. Enterprise. - **IP allow-list and device policy.** Network and device restrictions on a workspace: up to 200 addresses or ranges from which members may connect, with a grace window that cannot lock out the person saving it; and a policy that limits member transfers to the desktop app or to approved computers. Recipient and portal traffic is not affected. Enterprise. - **Archive tier (cold storage).** A cold, cheaper destination for finished folders: moved with a manifest, verified before anything is removed from hot storage, and restored on demand with the restore time shown. Studio and above; Enterprise adds retention rules per folder. A verifiable variant on decentralised storage is coming on request. - **Low-bandwidth mode.** A remembered switch on delivery, portal and Files pages that turns off previews, covers, thumbnails and animations so the page and the download still work on 2G, 3G or a metered connection. Suggested automatically when the browser reports a slow connection, never forced. - **API key and webhook.** A scoped workspace credential (read, or read and write) that lets scripts, the CLI and the SDKs use the same REST surface as the apps, and a signed HTTPS callback (HMAC-SHA256, retried) that tells your systems the moment a download, portal upload or transfer completes. Pro and above. # About and contact URLs: https://boita.io/about, https://boita.io/contact Boita is built by Aariko Systems (Aariko Systems OPC Private Limited), a small team in Pune, India, out of the founder's earlier 3D rendering business where deliveries of 10 to 20 TB per job were normal and the transfer was the bottleneck. Registered office: Workflo Icon Tower, Office No. 702, S. No. 114/5, 115/1, 114/6/3, Baner Road, Pune 411045, Maharashtra, India. Mailboxes: hello@boita.io (sales, pilots, press), support@boita.io (customers), security@boita.io (security, abuse, takedowns). WhatsApp +91 92252 77267. # Legal (v1, last updated 2026-09-17; governing law India, courts at Pune, Maharashtra; reviewed by counsel before public launch) ## Privacy policy URL: https://boita.io/legal/privacy We collect what is needed to run your account and move your files, keep it in India where we can, do not sell it, and delete it when you ask or when your account closes. ### Who we are Boita is operated by Aariko Systems OPC Private Limited, Workflo Icon Tower, Office No. 702, S. No. 114/5, 115/1, 114/6/3, Baner Road, Pune 411045, Maharashtra, India. For personal data you give us to open and run an account (name, email, company, billing details, usage records) Aariko Systems OPC Private Limited decides why and how it is processed and is the data fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act). For the files you store and send, and the details of the people you send them to, you are the data fiduciary and Aariko Systems OPC Private Limited is your data processor acting on your instructions; the Data processing summary describes that role. ### What we collect and why We collect only what each purpose needs: - Account data: name, email, password hash, two-factor secrets, workspace name, role. Purpose: to create and secure your account. - Billing data: company name, billing address, GSTIN or tax ID, plan, invoices. Card details are handled by our payment provider and never stored by us. Purpose: to bill you and issue invoices. - Files and metadata: the files you upload, their names, sizes, checksums, folder paths, and who uploaded them. Purpose: to store and transfer them as you instruct. - Share and portal data: recipient email addresses, link settings, views and downloads per recipient, uploader names on portals. Purpose: to deliver what you send and show you that it landed. - Transfer and security logs: IP addresses, timestamps, device and app version, transfer events, logins, audit-log entries. Purpose: to run the service, detect abuse and meet CERT-In log-retention directions. - Waitlist and contact data: what you type into the waitlist form or send to our mailboxes. Purpose: to reply to you about Boita access and pricing. ### What we do not do We do not sell personal data. We do not run advertising, third-party analytics or tracking cookies on this website or in the product. We do not read the contents of your files except when you ask for support and grant access, or when required by law; staff have no default access to file contents, and break-glass access is ticketed, approved by a second person, time-limited and recorded in your audit log. ### Legal basis and consent We process account, billing and log data because it is necessary to provide the service you asked for and to meet legal duties (tax, CERT-In). Where the DPDP Act requires consent, for example for a non-essential purpose, we ask for it separately, in plain language, and you can withdraw it as easily as you gave it. We do not process personal data of children knowingly; Boita is for businesses and adults. ### Where data is stored Boita is built and operated in India. During the pilot, file storage is in India. Account and billing systems, transactional email and the transfer control plane may use cloud infrastructure and sub-processors listed generically in the Data processing summary; a named sub-processor list is published before launch. Where a sub-processor is outside India we make sure the transfer is permitted under the DPDP Act and our contract with them. ### How long we keep it - Files: until you delete them, then in the trash for the recovery window, then purged by the retention worker. Share links expire per plan and can be extended. - Account and billing data: for the life of the account and then as long as tax and company law require (typically eight years for invoices in India). - Security and transfer logs: 180 days in India in line with CERT-In directions, unless an investigation requires longer. - Waitlist entries: until you ask us to delete them or twelve months after launch, whichever is sooner. ### Your rights You can ask for a copy of your personal data, ask us to correct it, ask us to delete it, withdraw consent where consent was the basis, and nominate someone to exercise these rights for you. Write to hello@boita.io. We reply within 30 days. If you are unhappy with our reply you can complain to our grievance officer (below) and then to the Data Protection Board of India. ### Grievance officer Snehal Pawar, Grievance Officer, grievance@boita.io, Workflo Icon Tower, Office No. 702, S. No. 114/5, 115/1, 114/6/3, Baner Road, Pune 411045, Maharashtra, India. Write with your account email and what happened; grievances are acknowledged within 48 hours and resolved within 30 days, as the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines) Rules require. ### Security Transfers are encrypted in transit, files are encrypted at rest with a key per workspace, each workspace has its own storage root, two-factor authentication is available to everyone and mandatory for our staff, and a written security programme governs how we operate. The Security page says what is live, in progress and planned. If we suffer a breach that affects you we will tell you and the authorities as the DPDP Act and CERT-In directions require. ### Changes and contact We will post changes here with a new "last updated" date and email account owners about material changes. Questions: hello@boita.io. Post: Aariko Systems OPC Private Limited, Workflo Icon Tower, Office No. 702, S. No. 114/5, 115/1, 114/6/3, Baner Road, Pune 411045, Maharashtra, India. This policy is governed by the laws of India; the courts at Pune have exclusive jurisdiction. ## Terms of service URL: https://boita.io/legal/terms You keep ownership of your files; we run the service with care and tell you plainly what is live and what is not; each side can end the agreement; Indian law and Pune courts apply. ### The agreement These terms are a contract between you (the person or organisation opening a workspace) and Aariko Systems OPC Private Limited, Workflo Icon Tower, Office No. 702, S. No. 114/5, 115/1, 114/6/3, Baner Road, Pune 411045, Maharashtra, India ("Boita", "we"). They cover the Boita web app, desktop apps, share pages, upload portals and this website. By creating a workspace or accepting an invitation you agree to them, together with the Acceptable use policy, the Privacy policy, the Refund and cancellation policy and, for business customers, the Data processing summary. If you accept for an organisation you confirm you are allowed to. ### Accounts and workspaces You must be at least 18 and give accurate details. You are responsible for what happens under your account and for keeping credentials safe; enable two-factor authentication. Workspace owners and admins control members, seats and settings, and can see the workspace audit log. Recipients of share links and uploaders on portals do not need an account and are bound by the Acceptable use policy when they use those pages. ### Plans, fees and changes Plans are described on the Pricing page and sized by storage, share retention, seats and parallel sessions. Fees are flat per billing period in the currency shown at checkout; there are no per-GB transfer fees and no charge for downloads. Storage overage, if it ever applies, is shown before it happens. We may change plans or prices with at least 30 days’ notice to workspace owners; changes apply from your next billing period. Taxes (GST in India) are added where applicable. Cancellation and refunds are set out in the Refund and cancellation policy. ### Your content You own the files you upload and everything in them. You give us only the licence we need to store, transfer, display previews of and deliver them as you instruct, and to keep backups. You are responsible for having the rights to what you upload and share, for the people you share with, and for any personal data in your files (see the Data processing summary). We do not claim ownership of, or use for our own purposes, anything you store. ### Our service We will run Boita with reasonable skill and care, keep it patched, encrypt your data in transit and at rest, and tell you plainly on the Security page what is live, in progress and planned. Boita is in a private pilot; features marked "coming" are roadmap, not promises, and pilot workspaces may see changes at short notice. We may suspend a workspace that breaches these terms or the Acceptable use policy, or where required by law, and will tell you why unless the law prevents it. ### Retention, deletion and closing your account Deleted files sit in the trash for a recovery window and are then purged. Share links expire per plan. When you cancel, your plan runs to the end of the period; your files then follow the published retention policy, and we delete workspace data within 90 days of closure except what tax or company law requires us to keep. You may export your files at any time before that. ### Acceptable use, abuse and takedowns The Acceptable use policy is part of these terms. We act on abuse reports and valid copyright takedown notices, and may disable a link, a file or a workspace while we review. Our systems may scan uploaded files for malware once that feature ships; we do not otherwise inspect contents. ### Liability To the extent the law allows: Boita is provided as described and we do not guarantee that transfers will meet a particular speed, that the service will be uninterrupted, or that a "coming" feature will ship by any date. We are not liable for indirect or consequential loss, lost profits or lost data where you have not kept your own copy. Our total liability to you in any twelve-month period is limited to the fees you paid us in that period. Nothing limits liability for fraud, death or personal injury, or anything that cannot be limited under Indian law. ### Governing law and disputes These terms are governed by the laws of India. The courts at Pune, Maharashtra have exclusive jurisdiction, subject to any arbitration we agree in writing with enterprise customers. If we cannot resolve a dispute by talking, we will each try mediation before going to court. ### Changes We may update these terms; material changes are emailed to workspace owners at least 30 days ahead. Continuing to use Boita after the change is acceptance. Questions: hello@boita.io. ## Acceptable use policy URL: https://boita.io/legal/acceptable-use Use Boita to move and store your own work with people you have a reason to share it with. Do not use it to distribute malware, infringing material or spam, or to attack anyone, including us. ### Why this exists File-sharing services are abused for phishing, malware and piracy, which harms the people who receive links and gets legitimate links blocked. This policy protects your recipients, your reputation and ours. It applies to workspace members, share-link recipients and portal uploaders. ### You may not use Boita to - Store or distribute malware, phishing kits, credential-harvesting pages or anything designed to harm a device or deceive a person. - Store or share content that infringes copyright, trade marks or other rights, including unreleased material you are not authorised to distribute. - Store or share unlawful content, including child sexual abuse material, content that incites violence, or content prohibited under Indian law. - Send unsolicited bulk links, or use share emails and portal notifications to spam or harass anyone. - Probe, scan, overload or attempt to bypass the security of Boita, the transfer server, other workspaces or share pages, including path traversal, token reuse or automated scraping. - Resell bandwidth or storage, run a public file-hosting or download-mirror service, or otherwise use a plan far beyond its fair-use allowance in a way not intended by the plan. - Impersonate another person or organisation on share pages, portals or in emails sent through Boita. - Upload personal data you do not have a lawful basis to process. ### Fair use Plans are flat and carry no per-GB fees, but lower plans have a monthly transfer allowance. If a workspace is consistently far above it we will contact you about the right plan before anything is limited. Free workspaces have limits on public links while the account is new. ### Reporting and enforcement Report abuse of a Boita link or portal to security@boita.io with the link and what you saw; we aim to review within 24 hours. Copyright owners may send takedown notices to the same address with the material identified and a statement of ownership. We may disable a link, a file or a workspace while we review, warn or suspend the account concerned, and report unlawful content to the authorities where the law requires. Decisions can be appealed by writing to hello@boita.io. ### Security research We welcome good-faith security research on our own systems within a responsible-disclosure policy published before launch. Do not test against other customers’ workspaces or data. Report findings to security@boita.io. ## Cookie policy URL: https://boita.io/legal/cookies No advertising or analytics trackers, anywhere. This site keeps one preference in your browser and loads a live-chat widget; the app uses first-party cookies to keep you signed in. ### This website (boita.io) The marketing site loads no pixels, analytics or fonts from tracking networks and sets no cookies of its own. It stores one preference in your browser’s local storage, on this domain only, and reads it back on your next visit: - Currency: the currency you chose on the pricing page (key "boita.currency"). If you never choose one, nothing is stored and the currency is worked out from your browser’s region each time. - Nothing else. Reduced-motion and colour-scheme preferences come from your operating system and are not stored by us. ### The Boita app and share pages The web app uses strictly necessary first-party cookies to keep you signed in and to protect forms against cross-site request forgery. Share pages and upload portals use short-lived first-party cookies or tokens only for the download or upload in progress. None of these are used for advertising or shared with anyone. ### Third parties The live-chat widget in the corner of this site and of the app is provided by Crisp, a support-chat service in the European Union; it sets a cookie of its own so a conversation stays together across pages, and it is listed with our other sub-processors on the Trust page. We do not use advertising networks, social-media pixels or third-party analytics. If that ever changes we will update this page, add a consent control where the law requires it, and say so in the changelog at the top of this page. ### Your choices You can clear local storage and cookies from your browser at any time. Blocking cookies for the app will sign you out; blocking local storage on this site only means your currency choice is not remembered. ## Refund and cancellation policy URL: https://boita.io/legal/refunds Monthly plans: cancel any time, you keep the plan to the end of the period, no refund for the remainder. Annual plans: pro-rata refund on request within 14 days of purchase. Overage is never refunded. ### Cancelling a monthly plan Cancel from your workspace settings at any time. The cancellation takes effect at the end of the current billing period: you keep the plan, storage and seats until then, and you are not charged again. We do not refund the remaining days of a monthly period. ### Cancelling an annual plan Annual plans can be refunded pro rata on request within 14 days of the purchase or renewal date: we refund the unused months, less any month partly used. Write to support@boita.io from the owner’s email address. After 14 days an annual plan can be cancelled but runs to the end of the year without a refund. ### Usage-based overage Storage overage, where a plan permits it, is always shown before it happens and is charged for storage actually used. It is not refundable. ### Downgrades and upgrades Upgrades apply immediately and are charged pro rata for the rest of the period. Downgrades apply at the next billing period; if your stored data exceeds the smaller plan’s quota, uploads are blocked until you are within it, but existing files remain accessible. ### Free plan and pilot The Free plan has no charges and can be closed at any time. Pilot workspaces under a separate written agreement follow that agreement where it differs from this policy. ### How refunds are paid Refunds go back to the original payment method within 7 to 10 working days of approval, in the currency charged. For Indian card and UPI payments this policy is displayed at checkout as the card networks and the Reserve Bank of India’s guidelines require. Disputes are governed by the laws of India and the courts at Pune. ### Contact Billing questions: support@boita.io. Aariko Systems OPC Private Limited, Workflo Icon Tower, Office No. 702, S. No. 114/5, 115/1, 114/6/3, Baner Road, Pune 411045, Maharashtra, India. ## Service level agreement URL: https://boita.io/legal/sla Studio: 99.9% monthly uptime. Enterprise: 99.95%. Transfer service: 99.5% on both. If we miss it, a credit lands on your next invoice without you asking. Measured by the public status page. ### What is covered This SLA applies to paid Studio and Enterprise workspaces. It covers two things: the platform (the web app, API and share/portal pages, measured as one) and the transfer service (the transfer server, the transfer port and the browser/phone transfer path). Free and Pro plans run on the same infrastructure and see the same status page but carry no credit commitment. ### Targets Monthly uptime, calendar month, measured in minutes: - Platform — Studio 99.9% (up to 43 minutes down per month), Enterprise 99.95% (up to 22 minutes). - Transfer service — 99.5% on both plans (up to 3 hours 36 minutes per month). ### How it is measured The public status page at status.boita.io checks every component from outside our network every 30 to 60 seconds. A component is down for a minute when its check fails in that minute; the platform is down when any of the web app, API or share pages is down; the transfer service is down when the transfer server, its port or the browser transfer path is down. The numbers on the status page are the numbers this SLA uses — there is no private version. ### Credits When a month misses its target, the following share of that month’s subscription fee for the workspace is credited to the next invoice: - Below target but at or above 99.0%: 10%. - Below 99.0% but at or above 95.0%: 25%. - Below 95.0%: 50%. - Platform and transfer-service credits are calculated separately and added together, up to 50% of the monthly fee in total. ### Automatic You do not need to claim. On the first day of each month we compute the previous month’s uptime from the status page, record any credit against your workspace, email the workspace owner, and apply it to the next invoice. Credits appear under Plan & billing. Credits are not paid out in cash and lapse if the workspace closes before the next invoice. ### Exclusions Downtime is not counted when it results from: - Scheduled maintenance announced on the status page at least 48 hours ahead, limited to 4 hours per month, outside 09:00–21:00 IST. - Your own network, devices, blocked UDP ports, or a third party you chose (for example your own storage destination for auto-delivery). - Suspension of the workspace for non-payment or breach of the acceptable-use policy. - Events outside our reasonable control, including failures of the underlying cloud region that also affect other providers, and lawful orders. ### Changes We may improve targets at any time and will not lower them for a workspace during a paid term. Questions: support@boita.io. Aariko Systems OPC Private Limited, Workflo Icon Tower, Office No. 702, S. No. 114/5, 115/1, 114/6/3, Baner Road, Pune 411045, Maharashtra, India. ## Data processing summary URL: https://boita.io/legal/dpa For the files you store and the people you share with, you are the data fiduciary and we are your processor. We process only on your instructions, keep storage in India during the pilot, use a short list of sub-processors, and delete on request or closure. ### Roles Under the DPDP Act 2023 the customer is the data fiduciary for customer content: the files in a workspace, their metadata, recipient details on share links and uploader details on portals. Aariko Systems OPC Private Limited is the data processor for that content and processes it only to provide the service as documented and on the customer’s instructions given through the product. Aariko Systems OPC Private Limited is itself the data fiduciary for account, billing and security-log data, as described in the Privacy policy. ### What processing takes place - Storing files in the workspace’s own storage root, encrypted at rest. - Transferring files in and out through the accelerated transfer engine, encrypted in transit, with checksums recorded. - Delivering share links and portal pages to the people the customer chooses, and sending the transactional emails the customer triggers. - Recording transfer, share and admin events in the workspace audit log. - Generating previews and receipts once those features ship. - Keeping backups and purging deleted content after the retention window. ### Sub-processors We use a small number of sub-processors, each under a written contract with data-protection terms at least as strict as ours. During the pilot they fall into these categories; a named list with locations is published before launch and customers are told 30 days before a sub-processor is added. - Cloud hosting and object storage in India for files, the transfer server and the application. - A transactional email provider for share notifications, portal completion emails and account emails. - A payment provider for subscriptions and invoices (card data never reaches Boita). - Error and uptime monitoring that receives technical logs, not file contents. ### Data residency Customer content is stored in India (AWS Asia Pacific, Mumbai), with encrypted backup copies in Mumbai and Singapore as listed on the Trust page. Regional transfer nodes elsewhere are available on request for Enterprise. Where the verifiable archive tier ships, workspaces that require India residency receive a domestic object-storage archive rather than decentralised storage. ### Security measures Encryption in transit for every transfer session and HTTPS-only web surfaces; encryption at rest with a distinct key per workspace; per-workspace storage roots with automated cross-tenant isolation tests; per-operation transfer tokens scoped to paths and direction and expiring in minutes; two-factor authentication, mandatory for staff; a per-workspace audit log; staff with no default access to file contents and a ticketed, approved, time-limited break-glass process; a written security programme mapped to NIST CSF 2.0, CIS Controls v8, OWASP ASVS and ISO/IEC 27001; and an independent penetration test as a launch gate. The Security page lists each measure as live, in progress or planned. ### Assistance, breaches and audits We help customers answer data-principal requests that concern content we hold, within the tools the product provides or on request. We notify the customer without undue delay after becoming aware of a personal-data breach affecting their content, with what we know and what we are doing, and support their duties to the Data Protection Board and to affected people. Enterprise customers can request the security overview and questionnaire answers, and, once a year, a summary of independent assessments. ### Deletion and return Customers can export their content at any time. On deletion, content sits in the trash for the recovery window and is then purged. On workspace closure, content is deleted within 90 days, including from backups as they rotate, except what law requires us to keep. On request we confirm deletion in writing. ### Signed agreement This page summarises our processing terms. Business customers who need a signed data processing agreement can request one from hello@boita.io; the signed version prevails where it differs. Governing law India; courts at Pune, Maharashtra. # Documentation ## Getting started URL: https://boita.io/docs/getting-started Create a workspace, verify your email, install the desktop app, upload your first files and send a share link — and where everything lives in the app. ### Create a workspace Sign up at [app.boita.io/signup](https://app.boita.io/signup) with your name, a workspace name (leave it blank and we use your name), your email and a password of at least 12 characters. Every new account starts on the **Free** plan with 10 GB and no card. We email you a 6-digit code straight away. It is valid for 10 minutes, five wrong attempts spend it, and asking for a new one cancels the old one. Until the code is entered you can look around, invite people and set things up, but uploads, share links, portals and watch folders wait for a verified address. Your storage is set up in the background — usually a few minutes. The app says **We are setting up the transfer storage** until it is ready and emails you when it is. A **Samples** folder with a short clip, three stills and a README is waiting so the first link takes a minute. ### The checklist The dashboard keeps a short activation checklist that ticks itself from what you actually do: 1. Verify your email 2. Install the desktop app 3. Upload your first files 4. Send a share link 5. See your first delivery receipt 6. Invite your team (on Free: create an upload portal or invite a teammate) 7. Put Boita on your phone (optional) Dismiss it whenever you like; it comes back only if you ask. ### Install the desktop app The desktop app is the fast path. It carries the transfer engine inside it, so there is nothing else to install, and it handles whole folders, resume, the queue and watch folders. Download it for macOS or Windows from [boita.io/desktop](/desktop) (Linux servers use the [agent](/docs/desktop-watch-folders#the-linux-agent)). Open it once and sign in; from then on the web app shows **Engine ready** in the header and hands transfers to it. Without the app, the browser can still send and receive over HTTPS at standard speed where your deployment has a gateway, and recipients can always download. ### Send your first delivery 1. Open **Files**, drag files in or press **Upload**. The transfer tray at the bottom right shows progress; interrupted uploads continue from where they stopped. 2. Tick the files (or a folder) and choose **Share**, or go to **Share links → New link**. 3. Set an expiry, optionally a password or email verification, type the recipients' addresses, and press **Create link**. 4. Copy the link, or let Boita email each recipient their personal link. The link opens in any browser; recipients need no account. The receipt for that link — who opened it, who downloaded what, checksums — is on the link's row under Share links. See [Share links & delivery pages](/docs/share-links). ### Find your way around | Page | What it is for | |---|---| | Dashboard | Activity summary, the checklist, what's new | | Activity | Every action in the workspace, filterable, with a daily digest by email | | Files | Your storage: folders, previews, media details, versions, import | | Projects | One page per client job that groups its links, portals and deliveries | | Transfers | Live transfers on this computer and the history from every client | | Share links | Deliveries you sent, receipts, defaults, templates, address book, your brand | | Upload portals | Pages where clients send files to you | | Watch folders | Folders on your computers that upload (or download) on their own | | Trash | Deleted items until retention ends | | Storage | Usage, bandwidth analytics | | Insights | Delivery funnel, time to open, client reports (Pro and above) | | Members | People, roles, groups, folder access | | Security | Two-factor, passkeys, sessions, workspace policies | | Plan & billing | Plan, payment, referral credits | | Automations | Rules that act when files land, plus email-in | | Developers | API keys and webhooks | | Health | What is fine and what needs attention in this workspace | | Support | Tickets and the help you are entitled to | Press **?** in the header for help on the page you are on, or **⌘K** / **Ctrl+K** to jump anywhere and run the common actions — new link, new portal, search files, open a project. ### Invite your team Members → **Invite** takes an email and a role: **admin** (everything except transferring ownership), **member** (upload, share, run portals) or **guest** (view, and download where allowed). Existing Boita accounts are added immediately; new addresses get a single-use link that lasts 7 days and must be accepted with that email. Seats are set by the plan and count members plus pending invites. See [Security & governance](/docs/security-governance) for roles, groups and folder access. ### Language Boita is English only for now: the app, the phone, the delivery and portal pages and the emails we send. There is no language menu. > Tip: on a slow connection, turn on **Low-bandwidth mode** (Files header, and the footer of every delivery page). It skips previews, covers and animations so pages load fast on 2G/3G. Boita suggests it by itself when the browser reports a slow line or Data Saver. ## Sending files URL: https://boita.io/docs/sending-files How uploads work in Boita — from the browser, the desktop app, the phone and the command line — with resume, checksums, priority lanes, versions and trash. ### Where your files go Every workspace has its own storage on the transfer node. **Files** in the app is the view of that storage: folders, sizes, modified dates, previews and, for video, the codec, resolution, frame rate and audio layout the probe found on arrival. Nothing is copied anywhere else unless you set up auto-delivery or a download watch folder. Paths are ordinary folders. A few names are refused on purpose: `..`, absolute paths, backslashes, `?`, names longer than 255 characters, trailing dots or spaces, Windows reserved names such as `con` or `lpt1`, and anything starting with `.boita-` (that prefix is reserved for internal markers such as trash and watermark copies). ### Four ways to upload | From | How | Best for | |---|---|---| | The browser | Files → **Upload** (or drag files in). Needs the free desktop app installed once — the web app finds it — or the HTTPS path when your deployment has a gateway. | Quick sends from any computer | | The desktop app | Whole folders, watch folders, the queue and resume all live here. The engine is built in; there is nothing else to install. | Everything large | | The phone | **Add → Upload files** or **Upload photos and videos** (originals, up to 50 per pick), or **Send from my computer** to pick files on a Mac or PC where the desktop app is signed in as you. | On location | | The command line | `boita upload --to ` on the Linux agent, plus `download`, `ls`, `share`, `wait-receipt` and `speed`. `--json` for scripts. | Render farms, NAS, pipelines | The web app shows which path it has: **Engine ready** in the header when the desktop app is running, **Standard speed (HTTPS)** when it is falling back to the gateway, and an install prompt when neither is available. See [Desktop app & watch folders](/docs/desktop-watch-folders) and [Troubleshooting](/docs/troubleshooting). ### Resume, integrity and speed - **Resume.** An interrupted transfer continues from where it stopped when you start it again; identical files that already landed are skipped rather than re-sent. - **Checksums.** The transfer node records a checksum for every file on arrival — SHA-256 by default, SHA-512 if an admin chooses it under Security → Checksum policy. Checksums appear on delivery receipts and the verification report ([Share links](/docs/share-links#receipts)). - **Parallel sessions.** Big jobs run as several sessions at once, up to the number your plan allows ([Billing & plans](/docs/billing-plans)). - **Speed receipts.** Every finished transfer of at least 8 MiB and 2 seconds gets a speed line: how big, how long, and — when it is at least 1.5× faster — how much faster than a typical upload over a normal connection across India. Hover the badge to see the assumption behind the comparison. ### Send options On the Files page, **Send options** sets two things before an upload starts: - **Priority lane.** *Normal* shares the plan rate fairly with other transfers. *Deadline* takes the full rate and slows the workspace's other running transfers to a third until it finishes. *Background* runs at a third of the session rate so it never gets in the way. - **Also deliver to.** Fan the upload out to one or more auto-delivery destinations (your own S3-compatible bucket or transfer server) the moment it lands. Destinations are set up under Auto-delivery on the Enterprise plan. A workspace admin can also cap transfers during office hours with **bandwidth windows** (days, from/to, cap in Mbps, in the workspace time zone). A transfer minted inside a window stays capped for its whole life. ### Quota Boita checks storage before it starts a transfer, not halfway through. If an upload would take the workspace over its quota the request is refused with a clear message and nothing moves. Trash still counts towards storage; empty it or shorten its retention under Trash to free space. ### Versions When a file is overwritten Boita keeps the previous copy (on by default; an admin can turn it off under Trash → Previous versions). Up to 20 versions are kept per file, for the trash retention period or a shorter number of days you choose. Restoring a version makes the current file a version itself, so nothing is lost by restoring. ### Trash Deleting moves items to Trash. They stay there for the plan's retention period — 7 days on Free, 30 days on Pro, Studio and Enterprise — and an admin can shorten (never lengthen) that window. Restore puts the item back under its original name, or `name (restored)` if the name is taken. Permanent deletion needs an admin and is blocked while a legal hold is on. ### Numbered file sets Image sequences — three or more files with the same prefix, a zero-padded counter of at least three digits and the same extension — are shown as one row such as `shot_010.[0001-0240].exr` with the frame count, and a **gaps** badge when frames are missing. This is display only; the files are stored exactly as uploaded, and recipients see the same collapsed row on the delivery page. ### Importing from elsewhere Files → **Import** brings files in from an S3-compatible bucket (AWS S3, Wasabi, Backblaze B2, Cloudflare R2, MinIO and Google Cloud Storage with interoperability keys) using access keys, or from the Google, Microsoft and other consumer cloud drives listed in the Import panel after you connect the account. Google-native documents (Docs, Sheets) cannot be imported as files. > Tip: for a folder that keeps filling — renders, camera cards, a client's drop box — set up a watch folder once instead of uploading by hand. See [Desktop app & watch folders](/docs/desktop-watch-folders). ## Share links & delivery pages URL: https://boita.io/docs/share-links Everything a share link can do — expiry, passwords, verification, embargoes, view-only, watermarks, review roles — and what the receipt records. ### Create a link **Share links → New link**, or select files in Files and press **Share**. The form: | Field | What it does | |---|---| | Items | The files or folders (up to 500 paths). | | Mode | **Drive** — files stay in your workspace. **Send** — the shared files are deleted from the workspace when the link expires (never while a legal hold is on). | | Expires in (days) | How long the link lives. Each plan has a default and a ceiling: Free 3 / 7 days, Pro 14 / 30, Studio 30 / 90, Enterprise 30 / 365. An admin can lower the ceiling for the whole workspace. | | Max downloads | Optional cap. When it is reached the link reports *download limit reached*; the count moves on completed downloads only. | | Password | 8 to 256 characters, Pro and above. It is never emailed — pass it on separately. A workspace policy can require a password on every link. | | Ask recipients to verify their email | Files stay hidden until the recipient enters a one-time code sent to their address, so the receipt names who downloaded. Pro and above. | | Available from (embargo) | Before this moment recipients see a countdown and an **Add to calendar** button; the page unlocks by itself. | | View-only | Previews and comments, no download — for approvals and pre-release material. | | Watermark | Each recipient's name burned into previews and downloaded video and images. Studio and above; files, not folders. See [Watermarks](/docs/watermarks). | | Template | Saved settings; fields you fill on the form win over the template, which wins over workspace defaults. | | Send to | Email addresses (up to 200) and WhatsApp numbers (up to 200). Each gets a **personal link** so the receipt attributes views and downloads. Leave empty to just copy the link. | | Recipient groups | Named lists from the address book, expanded on create. | | Review roles | Per recipient: viewer, reviewer or approver. Studio and above. See [Review & approval](/docs/review-approval). | | Title, Message | Shown on the page and in the invite. | | Project | Groups the link on a project page. | Creating links needs a verified email. After **Create link** you get the URL, a **Copy** button and, for WhatsApp recipients, **Send on WhatsApp** buttons with the message filled in. **Defaults & groups** (admins) sets workspace defaults — expiry, verification, comments, replies, download notices, previews, message, view-only — and manages templates and recipient groups. The address book remembers past recipients, most used first. ### What the recipient sees The delivery page is a landing page: your brand, a cover from the first preview, a sender card, the file list with sizes and thumbnails, and — when the link is pasted into WhatsApp, Slack or iMessage — a proper preview card. Numbered file sets show as one row with the frame count. Until a locked page is opened, nothing about the files leaks: no names, sizes, message or sender email. A page is locked while it has a password, while verification is pending, or before an embargo lifts. Item identifiers on the page are opaque; your folder paths are never exposed. Recipients can: - **Download all**, or tick some files and **Download N selected** — the token covers exactly those files. - Download at full speed through the free desktop app (the page prompts once), or over HTTPS through the browser where a gateway exists. - Enter the sender's passphrase for encrypted deliveries; the files are decrypted on their machine as they arrive. - Press **👍 Got it**, **🙏 Thanks** or **⚠️ Something is wrong** on their personal link. You get a push, and the receipt shows it. - Comment, reply in threads and drop timecodes when comments are on ([Review & approval](/docs/review-approval)). - **Send files back** into a `Replies/` folder in your workspace through a reply portal created on demand (needs upload portals on your plan; you can switch replies off per link). - Turn on low-bandwidth mode. Verified-email recipients are remembered on that browser for 30 days: the next verified delivery offers **Continue as you@…**, and [app.boita.io/me](https://app.boita.io/me) lists every live delivery to that address from any studio. ### Receipts Every link has a receipt (Share links → open the link). It records the sender, the items, each recipient's status — sent, viewed, downloaded, verified, reacted — every completed download with client, files, bytes, rate, duration and a hashed IP hint, a timeline of events, and the integrity report: the checksum recorded on upload for each file, the number of downloads and how many of them verified against it. A download is *verified* when the same checksum was recorded on the way out; failed transfers are never counted. Studio and above can export it: - **Delivery receipt (PDF)** — A4, with items, recipients, downloads, the integrity report and the activity trail. Receipt numbers look like `BR-XXXXXXXXXX`. - **Verification report (CSV)** — `path, size_bytes, checksum_type, checksum, downloads, verified_downloads, verified`. - **Delivery note (PDF)** — a manifest with checksums and signature lines for *Delivered by* and *Received by*, times in IST. ### After sending - **Extend**, **Re-notify pending recipients** and **Revoke** work on one link or many at once. Extending adds days (7 by default) up to the plan ceiling from the original creation date. Re-notify emails only the recipients who have not downloaded yet. - **Expires tomorrow**: the sender gets one reminder email when a live link has a day left. - **Download notice**: when *Notify on download* is on, you get an email per completed download with the speed line. - **Revoke** stops the link at once; recipients see *This link isn't available*. Watermark copies are deleted immediately. - Links on a custom domain use that domain in every email and copy button ([Branding & domains](/docs/branding-domains)). > Note: a password page allows 10 unlock attempts per five minutes per address, and a download page 30 downloads per five minutes — enough for people, not for scripts. ## Upload portals & requests URL: https://boita.io/docs/upload-portals Give clients a page that lands files straight in your folder — with a form, file rules, a size cap, a deadline with invited uploaders, reminders and review. ### What a portal is An upload portal is a public page at `/p/` (or on your own domain) where anyone with the link sends files into a folder of your workspace. No account, no install for the uploader beyond the free desktop app for full speed; the browser path over HTTPS works where a gateway exists. Portals are on **Pro and above**, and creating one needs a verified email. ### Create a portal **Upload portals → New portal**: | Field | Notes | |---|---| | Title | Required, up to 120 characters. Shown to uploaders. | | Message | Up to 2,000 characters, shown above the form. | | Folder | Where uploads land (the workspace root by default; created if missing). | | Ask uploaders to verify their email | **On by default.** A 6-digit code proves the address; the receipt and folder name carry it. Off: an optional email field for a confirmation. | | Password | 8 to 256 characters. | | Max size per upload (GB) | 0 = no limit. Checked before a transfer starts. | | Open for (days) | 0 = no expiry. Cannot exceed twelve times the plan's maximum share retention. | | Notify me on each upload | On by default: an email and a push per completed upload. | | Form fields | Up to 20, written as `project_code*, shot, notes, format:ProRes|DNxHR|H.264` — `*` makes a field required, `name:A|B|C` makes a dropdown. | | File rules | Accepted extensions (up to 50), maximum files per upload (up to 5,000), a name pattern with a hint, a minimum size. Rules are checked before a token is minted; the uploader sees exactly which file broke which rule. | | Delivery spec | Containers, codecs, minimum resolution, frame rates, audio layout, duration limits. Checked after arrival by the probe; off-spec files are flagged on the portal (*⚠ N files off spec*) rather than refused. | | Deadline | A date and time; with invited uploaders it drives reminders. | | Invite uploaders | Up to 100 email addresses who receive the request. | | Project | Groups the portal on a project page. | ### Where uploads land Each upload gets its own folder under the portal's folder: `--`, where *sender* is the verified email or typed name (lower-cased, punctuation replaced by dashes, at most 40 characters) and *id* is a short random suffix. Folders are not accepted through a portal — files only, up to the plan's storage quota, which is checked live. ### Requests, reminders and deadlines When you invite uploaders, each gets an email — *{requester} is asking you for files by {date}* — with the portal link and an **Add the deadline to your calendar** link (an `.ics` file with a reminder the day before). You can **Re-invite** at any time. With a deadline set, Boita reminds invited people who have not uploaded yet 48 hours before, and again when it is overdue; you get *Still waiting: N of M have not uploaded* at the same time. Uploads still land after the deadline — the page says so and you are told. ### What the uploader sees Your brand, the title and message, the size cap and closing date, then the password step and the email code if you asked for them, the form fields, the file picker and **Send files**. While the transfer runs they see progress; when it lands they see *Upload complete — thank you* and, if their email is known, receive *Your upload to {workspace} was received*. The page is in English and has a low-bandwidth switch. ### Review uploads Open a portal to see its uploads with sender, message, form answers, files, size and status. From the phone you can **Approve** or **Reject** an upload (rejecting moves its folder to Trash, recoverable until retention ends) and add a note; a rule can act on that decision ([Automations](/docs/automations-email-in)). ### Pause, revoke, replies **Pause** keeps the link but tells uploaders *this portal is paused*; **Resume** reopens it. **Revoke** removes it for good — the link returns *not found* at once. Reply portals created from delivery pages (*Send files back*) are ordinary portals titled *Files back to {you}* that expire with the link. > Plan: portals are included on Pro, Studio and Enterprise. A rate limit of 20 uploads per hour per link and address keeps scripts out. ## Review & approval URL: https://boita.io/docs/review-approval Give each recipient a role, approve or request changes per file, remind approvers, reply in threads with @mentions and timecodes, and export comments. ### Roles When you create a share link (Studio and above) you can give each email recipient a role: - **Viewer** — sees and downloads, cannot decide, cannot comment. - **Reviewer** — can request changes on a file and comment. - **Approver** — can approve or request changes, and comment. Addresses you do not name are viewers. Anyone opening the plain link without a personal invitation keeps the ordinary share-page rules (comments if you allowed them). Roles can be changed after sending from the link's panel; doing so re-arms the reminders. ### Deciding on a file On the delivery page every file shows its status — **Pending review**, **Approved** or **Changes requested** — and, for the right role, an **Approve** / **Request changes** control with an optional note (up to 2,000 characters). Decisions are per file and per version: if the file is replaced, it is pending again. Decisions need the personal link from the invitation or a verified email, so the receipt always says who decided. You see the same statuses in Files (an approval badge on the row), on the link's receipt, and the sender gets a push for each decision. ### Reminders Approvers with files still pending are nudged twice: 48 hours after the link was created (*Your approval is waiting: …*) and 24 hours before the link expires (*Last day to approve …*). Each reminder goes once. ### Comments Comments are on by default for every link (turn them off in workspace defaults or per link). Recipients are attributed by their personal link or verified email; otherwise the page asks for a name. Comments are up to 2,000 characters, one reply level deep, and can carry a **timecode**: type it as `00:12.400` or `00:00:12:10` and Boita reads it at the file's frame rate from the probe. You receive an email — *{author} commented on "{title}"* — and a push for each comment. In your own replies you can **@mention** teammates by first name, full name or email local part; they get *{author} mentioned you on "{title}"*. Mentions are never shown to recipients. Comments can be resolved; removing one needs an admin. WhatsApp recipients who reply to their invitation land in the same thread, marked *(WhatsApp)* — see [WhatsApp deliveries](/docs/whatsapp). ### Exports From the link's panel (Studio and above): - **Comments (CSV)** — `id, at, author, from_sender, file, timecode, timecode_ms, body, resolved, parent_id`. - **Markers** — a tab-separated file for edit suites: `name, comment, timecode, colour`, with green for resolved, blue for sender notes and red for recipient notes. > Plan: review roles, approvals and exports come with Studio and Enterprise. Comments and threads are on every plan. ## Projects & search URL: https://boita.io/docs/projects-search Group a client job’s links, portals and deliveries under one project; find files by name, tag, codec, resolution, size, date or custom fields; save searches. ### Projects A project is one page per client job. Create one from **Projects** with a name, the client, a status (**Active**, **On hold**, **Delivered**, **Archived**), start and due dates, notes and the crew (members with a **lead** or **member** role; you become a lead). Each project owns a folder — `Projects/` unless you pick another — which is created on the transfer node. Anything you create *from* the project page is grouped under it: share links, upload portals and auto-delivery rules carry the project, and transfers into its folder count towards it. The overview shows bytes sent and received, transfers, downloads, pending reviews and active links, with the crew and dates alongside. The phone shows the same page read-only. A workspace can hold up to 500 projects. Deleting a project (a lead, its creator, an admin or the owner) removes the grouping only: links, portals and rules keep working and the files stay where they are. ### Search The search box in the header, or **Search** on the phone, looks through the workspace index. Type words from the name, tags, container, codec, resolution words (`1080p`, `4k`, `uhd`, `8k`), frame rate or audio layout (`stereo`, `surround`). Use quotes for phrases, `OR` between alternatives, and `-` to exclude. A plain substring of the file name also matches. Filters narrow it further: | Filter | Example | |---|---| | Extension | `mov`, `exr` | | Tag | one of the file's tags | | Size | minimum / maximum bytes | | Modified | after / before a date | | Codec | the probe's codec name, video or audio (`prores`, `h264`, `pcm_s24le`) | | Resolution | `1920x1080` exactly, `1080p` by height, `4k`/`uhd` at least 3840 wide, `8k` | | Custom field | `key:value`, exact and case-insensitive | | Folder | a path prefix | Results respect folder permissions — you only find what you may see — and come in pages of up to 200. Files are indexed the moment an upload lands, and a reconcile walk runs every 30 seconds so anything that arrived by other means (a watch folder on another machine, an import) shows up shortly after. The results footer says when the index was last refreshed. ### Tags and custom fields Any member can tag a file: up to 30 tags per file, 40 characters each, lower-cased. Admins define **custom fields** (Files → Fields) — up to 20 per workspace, each a text, dropdown (up to 50 options) or date — which members fill per file from the details panel. Both are searchable and appear on the details panel and in project views. ### Saved searches Run a search you use every week and press **Save**. Saved searches live in the search page's sidebar for the whole workspace. Free keeps three; Pro and above have no limit. The person who saved one, or an admin, can delete it. ### Insights and client reports **Insights** (Pro and above) turns the same data into answers: the delivery funnel (sent → opened → downloaded), time to first open, recipients by domain, who sends most, storage growth, transfer speed over time and portal conversion, cached for ten minutes. **Client reports** are branded PDFs of a client's deliveries for a month — on demand, or emailed monthly on a day you choose. > Tip: a project plus a saved search (`field:client:acme` with the project folder as the path prefix) is the quickest way to see everything a client has ever received. ## Automations & email-in URL: https://boita.io/docs/automations-email-in Rules that email, post to Slack, tag or turn a landed folder into a delivery link when files arrive; an email-in address for attachments; calendar links. ### Rules **Automations** (Studio and above; admins create, everyone can read and dry-run) lets you write rules of the form *when this happens, if these conditions hold, do these things*. A workspace can have up to 50. #### Triggers - **Files land in the workspace** — an upload completes, an import finishes or an email is filed. - **A delivery is downloaded** — a recipient completes a download of a share link. - **A portal upload completes**. - **A portal upload is reviewed** — approved or rejected. - **On a schedule** — a time of day and weekdays in the workspace time zone, once per day. #### Conditions Folder prefix, file extensions (up to 50), minimum and maximum size, a specific portal, and a weekly window (days and hours). A rule with no conditions fires on every matching event. #### Actions Up to 10 per rule: | Action | What it does | |---|---| | Email | Up to 10 recipients, a subject and a body template. | | Slack | Posts to an incoming-webhook URL you paste once; it is stored as a secret and shown redacted afterwards. | | Create a share link | Turns the landed files into a delivery: expiry (up to 365 days, capped by your plan and workspace policy), up to 50 recipients, email verification, a message. Fails cleanly if the workspace requires passwords on links. | | Tag | Records a tag in the audit log so you can find and report on the run. | | Request approval | Reserved for a coming release; skipped today with a note in the run log. | Templates accept `{{file}}`, `{{files}}`, `{{paths}}`, `{{count}}`, `{{folder}}`, `{{sender}}`, `{{bytes}}`, `{{title}}`, `{{url}}`, `{{decision}}`, `{{rule}}`, `{{workspace}}` and `{{at}}`. #### Dry-run and the runs log **Test** evaluates a rule against the most recent matching event (or a sample you supply) and shows what each action *would* do — nothing is sent. Every real run is logged with its outcome; a failed action is retried on a ladder of 1 minute, 5 minutes, 30 minutes, 2 hours and 12 hours, and runs are kept for 30 days. Disabling a rule keeps it (and keeps working) even if the plan later changes. ### Email-in Every workspace on **Pro and above** can have an email-in address (Automations → Email-in; admins only). It looks like `ingest-@in.boita.io`; open the panel once to mint it, rotate it whenever you like. Mail sent there is filed under `Inbox//` — the subject slugged to 60 characters, `no-subject` if empty. Only the attachments are kept; up to 20 per mail, 25 MB each and 100 MB per mail by default, and 120 mails per hour per address. The sender gets *Your attachments reached {workspace}* on success, or *Your email to {workspace} could not be filed* with the reason. Each filed mail is an event that rules can act on. > Warning: email-in depends on an inbound mail provider being connected on your deployment; the panel says so when it is not switched on yet. ### Calendar links Two things in Boita have a moment attached, and both offer an `.ics` you can drop into any calendar: - A share link with an **embargo** — the delivery page and the invite carry **Add to calendar** with a 15-minute reminder before it opens. - A portal with a **deadline** — the request email carries **Add the deadline to your calendar** with a reminder the day before. The files use a stable identifier, so importing an updated one replaces the old entry rather than duplicating it. ## Desktop app & watch folders URL: https://boita.io/docs/desktop-watch-folders The desktop app carries the transfer engine, moves whole folders and runs watch folders; the Linux agent and the boita CLI do the same on servers. ### The desktop app Download it from [boita.io/desktop](/desktop) for macOS or Windows. It wraps the web app and carries a private transfer engine inside it — you install Boita and nothing else. The engine listens only on the local machine with a key that changes every launch. What it gives you over the browser: - **Whole folders** in the file picker, with multi-select. - **Up to 50 concurrent transfers**, each with a live rate you can change while it runs. - **Resume** after any interruption; files that already landed are skipped. - **Downloads** land in `Downloads/Boita` unless you choose a folder per transfer. - **Watch folders** (below), which keep running while the window is closed. - **Send from my computer**: a phone signed in as you can browse this computer's Home, Desktop, Documents, Downloads, Movies, Pictures, Music and mounted drives and send up to 500 items at once, straight from here over the fast path. Closing the window keeps Boita in the menu bar / tray with **Open Boita**, **Check for Updates…** and **Quit Boita**. Updates are checked on launch and every 24 hours, downloaded quietly and installed when you quit. Links such as `boita://s/` open in the app. > Note: an unsigned Windows build shows a SmartScreen warning the first time; on macOS use **Open Anyway** once in System Settings → Privacy & Security. ### Watch folders A watch folder ties a folder on this computer to a folder in the workspace, one way. **Watch folders → Add watch folder** (inside the desktop app) opens a native folder picker, then: | Field | Notes | |---|---| | Name | How it appears in the list. | | Direction | **Upload** — files dropped here go to the workspace. **Download** — keep this folder filled from a workspace folder. | | Folder in the workspace | Created for uploads; must already exist for downloads. | | Send after a file has been unchanged for | 2 to 600 seconds, 10 by default, so renders and copies finish before they go. | How it behaves: - New and changed files are offered once they have been stable for the chosen time, in batches (a 10-second window or 500 files), with a full rescan every minute. - Dot-files, `Thumbs.db`, `desktop.ini`, `~$` lock files and partial-download suffixes are ignored. - A file that fails five times is set aside until you press **Re-send all**, which re-offers everything (unchanged files are skipped by the engine). - Download watch folders fetch anything new or changed into this computer every minute, keep the folder layout, and **never delete locally**. - **Hours** limits sending to a daily window such as `22:00-06:00` in the workspace time zone; outside it the batch waits and the app retries the next minute. - **Pause** / **Resume** and **Remove** (files already uploaded stay in the workspace). The web app shows what every device reports — name, destination, device, bytes sent, last activity — and can pause or remove from anywhere; the device honours it within a minute. Each batch is checked against storage quota before it starts. Watch folders need the desktop app (or the agent) signed in: while the window is closed and signed out, the batch waits with *Boita window is not open — sign in to resume watch folders*. Plans: Free none, Pro 2, Studio 1,000, Enterprise 10,000 watch folders. ### The Linux agent For servers, NAS boxes and render nodes there is a headless agent. Install it in one line as root on Ubuntu, Debian or RHEL (x86_64 or arm64): ```bash curl -fsSL https://boita.io/downloads/agent/install.sh | sudo bash ``` It creates a `boita-agent` system user, installs to `/opt/boita-agent`, fetches the transfer engine, and enables a `boita-agent` systemd unit. Then: ```bash boita-agent init --api-key --workspace --sdk-dir /opt/boita-agent/sdk boita-agent watch add --local /srv/renders --to Renders systemctl start boita-agent ``` The API key comes from **Developers → API keys** with write scope; the agent acts as the person who created it. `watch add --from ` makes a download watch folder; `watch list | pause | resume | remove`, `status` and `version` do what they say. Configuration lives in `/etc/boita-agent/config.json` (or `~/.config/boita-agent` for non-root installs). The agent runs up to 10 transfers at once and resyncs with the web app every minute, so pausing a watch folder in the browser stops it on the server. ### The `boita` command line The agent ships a CLI for scripts and pipelines: ```bash boita upload --to [--parallel N] [--streams N] [--priority deadline|background] [--deliver-to ] boita download --to [--parallel N] boita ls [] boita share [--title …] [--expires ] [--password …] boita wait-receipt [--timeout ] # resolves when every invited recipient has downloaded boita speed [--mb 256] # eight files up, then down, from a "Speed test" folder ``` `--json` prints machine-readable output; the exit code is 1 when any transfer fails. A session that fails while it is being set up (a busy server, a dropped handshake) is retried twice with a short back-off before it counts as failed — `BOITA_TRANSFER_RETRIES=0` turns that off, and `--json` shows `attempts` on a transfer that needed one. Credentials come from `boita-agent init` or the environment: `BOITA_API_URL`, `BOITA_API_KEY`, `BOITA_WORKSPACE`, `BOITA_LABEL`, `BOITA_SDK_DIR`. ### Your connection **Transfers → Your connection** says which path this computer has — *Fast path*, *Standard speed (HTTPS)* or *No transfer path yet* — and why. **Test speed** (desktop app 1.3 or later) moves a 128 MB probe as eight files up and down and reports upload, download and a typical upload for comparison, with plain advice: if nothing moved, the accelerated port (UDP 33001) is probably blocked and IT should allow it. See [Troubleshooting](/docs/troubleshooting). ## Mobile app URL: https://boita.io/docs/mobile Browse and search files, make share links, run portals, upload photos and documents, send from a computer running the desktop app, and watch transfers. ### What the phone does Five tabs: **Home**, **Files**, **Share links**, **Portals** and **More**. Sign in with your Boita account (two-factor and passkeys work), pick a workspace, and you have the same storage and links as on the web. #### Files Browse with breadcrumbs, search within a folder, and see numbered file sets as one row with the frame count. Long-press or open an item for **Details**, **Share link**, **Download to this phone**, **Rename** (no slashes) and **Move to trash**. Select mode handles several items at once. The **Add** button offers: - **Send from my computer** — pick files on any Mac or PC where the desktop app is signed in as you. They go over the fast path from that computer; nothing passes through the phone. A computer shows up within a minute of the app running and stays available while it does. - **Upload files from this phone** and **Upload photos and videos** — originals, EXIF kept, up to 50 per pick. - **New folder**. Phone uploads and downloads use the standard-speed HTTPS path where your deployment has a gateway; the accelerated mobile engine arrives with a later store build, and the app says so on the details sheet. For multi-GB deliveries the desktop app is the fast path. #### Share links and portals Create a link with expiry presets or a date, a download limit, a password (8+ characters, passed on separately — never in the link or emails), a title, a message and download notices; copy it or hand it to the system share sheet. Open any link for its receipt. Portals show their settings and uploads; you can **Approve** or **Reject** an upload (rejecting moves it to Trash) and add a note. #### More Members (with seats), Upload portals, Projects (read-only), Trash, Storage, Insights, Transfers (All / Running / Failed, refreshing every 15 seconds while anything runs, with the speed badge), Watch folders (read-only — add, pause or remove them in the desktop app), **Your connection** (which path this phone uses and a 32 MB speed test), the **Staff console** for platform staff (read-only, with the WhatsApp inbox), Two-factor authentication, **Face ID / Touch ID / passcode lock** (locks after 60 seconds in the background or on a cold start), Notifications, Appearance (System / Light / Dark), Help centre, Terms, Third-party notices and Sign out. ### Links, QR codes and notifications Share links, upload portals and invitations open in the app when tapped, and the **Scan** button reads their QR codes (anything else is refused with *Not a Boita link*). Push notifications tell you about downloads, comments, reactions, approvals and portal uploads; they need a real device. ### Recipients on a phone Recipients do not need the app. A delivery page opens in any mobile browser, with a low-bandwidth switch that skips previews and covers; the app's public share and portal screens show the essentials — title, days left, items, size, password step — with **Open in browser** to download. > Tip: the app updates itself over the air between store releases, so features arrive without a reinstall. ## WhatsApp deliveries URL: https://boita.io/docs/whatsapp Add recipients by WhatsApp number, send each their personal link with the message filled in, and get their replies as comments on the delivery. ### Sending to a WhatsApp number On the share form, next to email addresses, type WhatsApp numbers with the country code (`+91 98765 43210, +44 7700 900123`, up to 200). Each number gets its own personal link, exactly like an email recipient, so the receipt attributes what happens next to that person. After creating the link you get a **Send on WhatsApp** button per recipient that opens WhatsApp with the message ready: > {you} sent you "{title}" with Boita. Open your delivery: {link} > Available until {date}. Press send and the row shows *(sent)*. Re-notify and the per-recipient **WhatsApp** action work the same way later. Where the workspace's WhatsApp channel has been approved for templates, Boita also sends the invitation automatically on create and on re-notify; the button remains the fallback until then. ### Replies When a recipient replies to that message, the reply lands as a comment on the delivery, marked *(WhatsApp)*, as long as comments are on for the link. Boita matches the reply to the quoted message, or to the newest live delivery to that number. The recipient gets an acknowledgement in the same chat — *Your note reached {sender} about "{title}". They will see it with the delivery.* — and you get the usual comment email and push. Messages that cannot be matched to a delivery go to the staff inbox, not to you. ### Privacy Public pages never show a full number: the receipt and the delivery page label WhatsApp recipients as *WhatsApp +91…210*. Numbers are normalised on entry; an invalid one is refused before the link is created. > Plan: WhatsApp recipients are available on every plan; template sending switches on per deployment once the channel is approved. ## Watermarks URL: https://boita.io/docs/watermarks Tick Watermark on a link and every preview, video and image a recipient sees or downloads carries their name and yours; gone when the link ends. ### What gets watermarked Tick **Watermark** on the share form (Studio and above; files, not folders). For each recipient Boita burns two lines of text — *{recipient} · {your organisation}* — into: - **Previews** on the delivery page, overlaid on the fly. - **Downloaded video**: `mp4`, `mov`, `m4v`, `mkv`, `webm`, `avi`, `mxf`, `mts`, `m2ts`, `ts`, `mpg`, `mpeg`, `wmv` — re-encoded to an H.264 MP4 with AAC audio. - **Downloaded images**: `jpg`, `jpeg`, `png`, `webp`, `tif`, `tiff`, `bmp`, `gif`, `heic`, `avif` — same type as the source. Everything else (project files, archives, documents) downloads unchanged. Sources above 12 GB are marked unsupported and download unchanged too. The text is placed large across the lower third and small in the top-left corner. ### Whose name The label is the recipient's verified email; otherwise the name on the invitation (an email, or *WhatsApp +91…210*); otherwise *link holder*. Previews use *preview* until the address is verified. Your organisation's name is the brand display name from [Branding & domains](/docs/branding-domains), or the workspace name. ### How the download works Copies are rendered once per recipient and file. The first download of a link starts the renders and the page says *Preparing your watermarked copy — N of M ready. This page will start the download by itself.*, asking again every 20 seconds until every copy exists. A copy that cannot be rendered falls back to the original so a delivery is never stuck. Copies live in a hidden folder inside your workspace, count towards storage while they exist, and are deleted when the link is revoked (immediately) or expires (by the retention worker). > Note: rendering happens on Boita's workers, not on your computer, so a large video takes a few minutes the first time each recipient asks for it. ## Branding & domains URL: https://boita.io/docs/branding-domains Your logo, colour and message on delivery pages, portals and emails; delivery mail from your own domain; share pages and portals on your own hostname. ### Your brand **Share links → Your brand** (Studio and above; admins edit, members view): - **Display name** (up to 80 characters) — shown instead of the workspace name on recipient pages, in email headers and in watermarks. - **Logo** — PNG, JPEG, WebP or SVG up to 512 KB. SVGs with scripts or event handlers are refused. The logo is served from a public, cacheable address. - **Accent** — a hex colour that recolours the buttons and the top line of the delivery card and the button in emails. - **Message** (up to 200 characters) — a line under the title on delivery and portal pages. The brand applies to delivery pages, upload portals and the recipient-facing emails (invites, upload requests, upload confirmations). If the plan later drops below Studio the settings are kept but recipients see the plain Boita look until it is back. ### Email from your own domain Also under Your brand (Studio and above): send delivery notices, upload requests and reminders, and upload confirmations from `delivery@mail.yourstudio.com` (you choose the local part). Sign-in codes, password mail, billing and support stay on Boita's own sender; **Reply-To** on every delivery mail is the person who sent it. 1. Enter the domain (one per workspace; mailbox providers such as gmail.com are refused) and the local part. 2. Add the DNS records Boita shows — a DKIM TXT record, an SPF pair on a `send.` subdomain, and a DMARC TXT record. 3. Press **Verify**. DNS can take a few minutes; the panel says *still checking* or names the records that do not match. 4. **Send me a test** delivers a real delivery-style mail to you. If verification later fails, mail falls back to the platform sender automatically and the panel says so. The feature also depends on the deployment having a sending provider connected; until then the panel reads *not switched on for this deployment*. ### Your own domain for share pages and portals Studio and above can serve delivery pages and portals on up to three hostnames of their own — `files.yourstudio.com/s/…` instead of `app.boita.io/s/…`. Under **Share links → Domains**: 1. Add the hostname. Boita shows a `CNAME` to the share host (or `A`/`AAAA` records for an apex domain) and a `TXT _boita.` verification record. 2. Add them at your DNS provider and press **Verify**. The status moves from *pending* to *active*; a failed check lists what is missing. 3. A certificate is issued automatically the first time the hostname is visited. Once active, every link and email uses the custom domain. On that hostname only `/` (which lands on your newest active portal), `/s/*` and `/p/*` are served; anything else redirects to the app. A link that belongs to another workspace is a 404 on your domain. > Plan: brand, email domain and custom domains are included with Studio and Enterprise. ## Security & governance URL: https://boita.io/docs/security-governance Two-factor and passkeys, sessions, roles and folder access, policies such as legal hold, single sign-on, admin scopes, audit exports, SIEM and IP allow-lists. ### Your account - **Passwords** are 12 to 256 characters and stored with a modern password hash. Changing yours needs the current one and signs out every *other* session; **Forgot password** sends a 6-digit code and signs out everywhere. Either way you get an email. - **Two-factor authentication** (Security page) uses an authenticator app. Enrol by scanning the QR code and entering the first code; you get ten recovery codes of the form `xxxxx-xxxxx`, shown once — each is single-use, and you can regenerate the set with a current code. Turning it off needs your password and a code. Staff accounts must have it on. - **Passkeys** — up to ten per account, registered from a signed-in session; sign in without typing an email. A passkey sign-in counts as two-factor. - **Sessions & devices** lists every sign-in with the device, a hashed hint of the address (never the address itself), whether it was two-factor verified, when it was last seen and when it expires (30 days from sign-in). Revoke one, or **Sign out every other device**. API keys cannot manage sessions or change passwords. ### Roles, groups and folder access Four roles: **owner** (one per workspace; ownership is transferred, not granted), **admin**, **member** and **guest**. Members upload, share and run portals; guests see what they are allowed to and download where permitted. Every write needs a verified email. **Groups** (Members page, admins) collect people; **folder access** grants a level on a path to a person or a group: `none` < `view` < `download` < `upload` < `manage`. The most specific path wins, and a tie takes the higher level. Without a rule, members get `manage` and guests `view` — both defaults can be changed for the workspace. Owners and admins always have `manage`. Search results and listings respect these rules. ### Workspace policies Under **Security** (admins; some owner-only): | Policy | Effect | |---|---| | Legal hold (owner) | Nothing can be deleted permanently — trash is not emptied, versions are kept, send-mode links do not delete their files — until it is lifted. The reason is recorded. | | Require a password on every link | Pro and above. | | Maximum link retention | 1 to 3,650 days, never above the plan's ceiling. | | Checksum policy | SHA-256 (default) or SHA-512, recorded per file on arrival and shown on receipts. | | Trash and versions | Retention in days (never above the plan), whether previous versions are kept, and for how long. | | Bandwidth windows | Cap transfers during office hours, per weekday and time range, in the workspace time zone. | | Daily digest | Per person: a daily summary email of the workspace's activity, or off. | ### Activity and audit **Activity** shows every action — transfers, share links and portals, files and folders, members and access, security and developers, plan and storage — with who did it and when, filterable by person and category. The same trail backs the audit exports below. ### Enterprise controls Included with the Enterprise plan: - **Single sign-on** — OpenID Connect with PKCE, one provider per workspace routed by email domain. Options: the domains it covers, whether it is *enforced* (password sign-in refused for those domains), the default role for new people, and on/off. People are created on first sign-in; your identity provider owns the second factor. - **Admin scopes** — split what admins can do: **billing** (plan, invoices, payment), **members** (invite, remove, roles), **security** (policies, SSO, sessions, exports, SIEM) and **content** (empty the trash, delete for good). The owner always has all four; without the feature every admin has all four. - **Audit and event exports** — CSV or JSON Lines of the audit log and of workspace events, up to 100,000 rows per export with a marker when truncated. - **SIEM stream** — one HTTPS endpoint per workspace receiving signed batches of events (the same signature scheme as webhooks). The secret is shown once; 50 consecutive failures pause the stream and email the owner; **Enable** resumes from where it stopped. - **IP allow-list** — up to 200 addresses or ranges (IPv4 and IPv6). Boita refuses a list that would lock out the person saving it, and the owner keeps a 15-minute grace window after every change. Blocked people see *this workspace only accepts connections from its approved networks*. **Test my current IP** tells you where you stand. - **Device policy** — require the desktop app for member transfers, and/or restrict transfers to approved computers by their install id. Recipient and portal traffic is not affected. ### Where your data lives Files sit on Boita's transfer nodes in India, encrypted in transit; checksums are recorded for every file. Recipient and uploader pages never expose your folder paths, IP addresses are hashed wherever they are shown, and every staff action on your workspace is audited with a reason. The [DPDP statement](/docs/dpdp) explains what recipient data is used for; the [Trust page](/trust) lists sub-processors, retention and backups. ## Billing & plans URL: https://boita.io/docs/billing-plans What each plan includes, how payment, GST, cancellation and referral credits work, what happens over quota, and the support you are entitled to. ### Plans Plans are flat — no per-GB fees, no download charges, no per-seat pricing. Prices are on the [pricing page](/pricing); the limits below are the defaults each plan ships with. | | Free | Pro | Studio | Enterprise | |---|---|---|---|---| | Storage | 10 GB | 1 TB | 10 TB | 100 TB | | Parallel sessions | 2 | 10 | 50 | 100 | | Seats | 1 | 3 | 15 | 1,000 | | Link expiry (default / max) | 3 / 7 days | 14 / 30 | 30 / 90 | 30 / 365 | | Trash retention | 7 days | 30 | 30 | 30 | | Watch folders | — | 2 | 1,000 | 10,000 | | Support | Standard | Priority | Chat | Dedicated | What switches on as you move up: - **Pro** — the desktop app, password-protected links and email verification, upload portals, API keys and webhooks, unlimited saved searches, email-in, insights and client reports. - **Studio** — branding, email from your domain and custom domains, receipts as PDF/CSV and delivery notes, review & approval, watermarks, automations, live chat support. - **Enterprise** — auto-delivery to your own buckets and servers, single sign-on, dedicated bandwidth on the transfer node, admin scopes, audit/event exports, the SIEM stream, IP allow-lists and device policies, a named account manager. Enterprise is arranged with us rather than bought self-serve. The plan's rate per session and session count are what the transfer engine is allowed to use; the actual speed is your line. ### Paying **Plan & billing** (the owner) picks a plan and a currency — INR in India, or USD, EUR, GBP, AED, SGD or AUD elsewhere — and pays by card or UPI through our payment provider's checkout. INR invoices add 18% GST; enter your GSTIN and the name to print on the invoice before paying. A workspace has one live subscription; to move between Pro and Studio, cancel the current one first and subscribe to the other. **Cancel** stops renewal at the end of the paid period; the workspace keeps its plan until then and drops to Free afterwards. If a renewal payment fails you are emailed and pushed at once and have **7 days** to fix it before the workspace drops to Free. ### Referral credits Every workspace has a referral code (Plan & billing). When someone signs up with it and pays their first invoice, both of you get a credit of 10% of that invoice against your next one — up to ₹5,000, or 60 in other currencies — once per pair. ### Storage and quota At 90% of quota admins get a warning by email and push; at 100% uploads stop, while downloads, links and portals keep working. Boita checks before a transfer starts, so nothing fails halfway. Trash counts towards storage. Downgrading to a plan whose quota you already exceed blocks uploads until space is freed. ### Uptime and credits Studio and Enterprise carry an uptime commitment — 99.9% and 99.95% for the platform, 99.5% for the transfer service — measured on [status.boita.io](https://status.boita.io) over 30 days. When a month misses the target, a credit lands on the billing page automatically: 10% of that month's fee below target, 25% below 99%, 50% below 95%. Details are in the [SLA](/legal/sla). ### Support | Plan | Channel | First response | Hours (IST) | |---|---|---|---| | Free | Ticket | 48 h | Mon–Fri, business hours | | Pro | Ticket | 24 h | Mon–Sat | | Studio | Ticket + WhatsApp chat | 4 h | 9:00–21:00 daily | | Enterprise | Ticket + chat + scheduled call | 2 h | 24×7 for outages, 8:00–22:00 otherwise, named account manager | Open a ticket from **Support** in the app (references look like `BT-123`); pick a category and priority, and reply in the thread until it is closed. Up to 25 open tickets per person. ### Suspension A suspended workspace refuses every write and its links stop working until it is restored; the owner is emailed with the reason. Write to support if that happens to you. ## Troubleshooting URL: https://boita.io/docs/troubleshooting What the transfer path labels mean, why a transfer is slow or fails, the port to open, what each error message means, and how to check health. ### Which path am I on? The header of the web app and **Transfers → Your connection** tell you: | Label | Meaning | What to do | |---|---|---| | Engine ready / Fast path | The desktop app (or the engine) is running on this computer. | Nothing — you have full speed and resume. | | Standard speed (HTTPS) | No engine on this computer; the browser is using the HTTPS gateway. | Install the desktop app for full speed. | | No transfer path yet | Neither the engine nor a gateway is available. | Install the desktop app; on a locked-down machine ask IT. | | Checking for the transfer engine… | The page is still looking. | Wait a moment; reload if it stays. | ### Slow or failing transfers 1. **Run Test speed** (Your connection). It moves 128 MB up and down and says plainly whether nothing moved, the line is slow, or all is well. 2. **If nothing moved**, the accelerated port is blocked at your site. Ask IT to allow **UDP 33001** outbound to the transfer host (TCP 33001 is used for the session handshake). Until then, a failed transfer in the tray offers **Retry over HTTPS**, which resends the same job through the gateway at standard speed. 3. **If the line is slow**, wired beats Wi-Fi, 5 GHz beats 2.4 GHz, and a *Deadline* lane makes this transfer take the whole plan rate. 4. **Big folders with many small files** are fine — the engine handles them — but a folder that is still being written to will keep restarting; use a watch folder with a stability delay instead. 5. **Interrupted?** Start the same transfer again; it continues from where it stopped and skips files that already landed. Failed transfers keep the error the engine reported on the Transfers page; the message there is the best clue, and support can see the same one. ### Messages you may see | Message | Meaning | |---|---| | *The transfer engine is still starting…* | The desktop app is launching; wait or reload. | | *The transfer engine is not running on this computer.* | Open the Boita app, then try again. | | *The browser transfer path is unavailable right now.* | The HTTPS gateway did not answer; try again in a minute. | | *This transfer could not be prepared.* | The request was rejected before it started; reload and try again. | | *verify your email address first* | Uploads, links and portals wait for the 6-digit code. | | *this upload would exceed the workspace storage quota* | Free space or shorten trash retention. | | *outside the allowed hours; next window opens …* | A bandwidth window or watch-folder schedule is holding the transfer. | | *this workspace only accepts connections from its approved networks* | An IP allow-list is on; ask an admin to add your address. | | *…only transfers through the Boita desktop app (device policy)* | Open the desktop app; browser transfers are switched off for members here. | | *workspace is provisioning* | Storage is still being set up; a few minutes, and you are emailed. | | *this delivery is not available yet* | The link is embargoed; the page shows the countdown. | | *download limit reached* | The link's maximum downloads were used; ask the sender to extend. | Errors from the API carry a short code — `unauthenticated`, `email_unverified`, `mfa_required`, `forbidden`, `not_found`, `validation_failed`, `path_rejected`, `quota_exceeded`, `scheduled_hold`, `plan_limit`, `rate_limited`, `share_expired`, `share_locked`, `node_unavailable`, `conflict`, `internal` — which the app shows next to the message and which the [API reference](/docs/api#errors) lists. ### Sign-in problems - **No code arrives** — check spam; a new request cancels the old code; three requests per address per ten minutes. - **Lost your authenticator** — use a recovery code. Out of recovery codes: support can help after identity checks. - **Your organisation signs in with single sign-on** — use your company's sign-in; password sign-in is switched off for that domain. ### Recipient problems - *This link isn't available* — expired, revoked, the download limit was reached, or the address is wrong. The sender can extend or re-send from Share links. - The page is slow on a phone — turn on **Low-bandwidth mode** in the footer; it skips previews and covers. - A watermarked download says *Preparing your watermarked copy* — the copies are rendering; the page starts the download by itself. ### Is it me or Boita? **Health** in the app checks your workspace: the transfer service, recent failed versus completed transfers, the preview queue, webhooks (paused after 20 consecutive failures), storage headroom and pending watermark copies, each with a remedy. [status.boita.io](https://status.boita.io) shows the platform's components, incidents and 30-day uptime. If both are fine and a transfer still fails, open a ticket from **Support** with the transfer's time and the message from the Transfers page. ## DPDP statement URL: https://boita.io/docs/dpdp For recipients and uploaders under India’s DPDP Act, 2023: what a delivery or portal page collects, why, how long it is kept, and whom to write to. > Note: this statement is a working draft published so recipients can read what Boita does with their data; it is reviewed by Indian counsel before public launch, alongside the [privacy policy](/legal/privacy) and the [data processing summary](/legal/dpa). ### Who is who When a sender (a company, a lab, a practice, a studio) sends you files, or asks you to upload files, that sender is the **data fiduciary** for the files and for your details as a recipient or uploader — it decided to send to you and it chooses the settings. **Boita** (Aariko Systems OPC Private Limited, Pune) is the sender's **data processor**: we run the pages and move the bytes on the sender's instructions. For the account and billing data of the sender itself, Boita is the fiduciary; that is covered by the [privacy policy](/legal/privacy). ### What a delivery or portal page collects | Data | Why | When | |---|---|---| | Your email address | To show you the files when the sender asked for verification, to send you the one-time code, to attribute your download on the sender's receipt, and — on a portal — to confirm your upload landed | Only if you type it | | A 6-digit code | To prove the address; it expires in ten minutes | When verification is on | | A guest token on your browser | So you are not asked to verify the same address again for 30 days, and so [app.boita.io/me](https://app.boita.io/me) can list your deliveries | After a successful verification | | Your WhatsApp number | Only when the sender addressed the delivery to it; public pages show it masked | Chosen by the sender | | A hashed hint of your IP address and your browser's description | Abuse limits on the page, and the sender's receipt; the address itself is not stored on the receipt | Every visit | | Views, downloads, reactions, approvals and comments | The sender's delivery receipt — the record that the delivery happened | When you do them | | Your name and message on a portal | So the sender knows who sent what | If you type them | | Your low-bandwidth choice | Stored on your browser only, to keep the page light | If you change it | The files themselves are the sender's; Boita stores them for the sender, records a checksum for each so both sides can prove what was delivered, and deletes copies made for you (such as watermarked renders) when the link ends. ### What we do not do We do not sell or share your details with anyone but the sender that sent to you. We do not use your address for marketing. Recipient pages carry no third-party scripts or advertising trackers. Comments and reactions are shown to the sender, never to other recipients. ### How long Recipient records live as long as the sender's link and its receipt do — links expire on a date the sender chose (at most a year on the largest plan), and receipts stay with the sender's workspace. Verification codes are kept for ten minutes; the guest token on your browser for 30 days; abuse-limit counters for minutes to hours. When a sender closes its workspace, its data — including recipient records — is deleted on the schedule in the [privacy policy](/legal/privacy). ### Your rights and whom to write to Under the DPDP Act you may ask for access, correction and erasure of your personal data, and nominate someone to exercise these rights. Because the sender decided to send to you, write to the sender first — the sender's name and email are on the delivery page. You can also write to Boita's grievance officer, who will act on the sender's behalf or forward your request: **Grievance Officer** — Snehal Pawar, grievance@boita.io, Workflo Icon Tower, Office No. 702, Baner Road, Pune 411045, Maharashtra, India. Complaints that are not resolved can be taken to the Data Protection Board of India. ### Language The delivery page, the upload page and this statement are published in English only for now. ## API reference URL: https://boita.io/docs/api Every public Boita API endpoint with parameters, request and response schemas, scopes, and examples in curl, TypeScript and Python, from the OpenAPI document. OpenAPI 3.1 document: https://boita.io/openapi.json (live: https://api.boita.io/v1/openapi.json). SDKs: @boita/sdk (TypeScript, npm) and boita (Python, PyPI), generated from the same document.