DoD & Compliance
DoD SAFE: The Complete 2026 Guide to Secure File Sharing for the U.S. Department of Defense
DoD SAFE (Secure Access File Exchange) is the Pentagon's free, CAC-authenticated file-transfer service for sending large or sensitive files in and out of the .mil network. Here's exactly how it works in 2026, what you can and can't send, the 8 GB / 7-day limits, and how civilian contractors request a drop-off without a CAC.

If you've ever tried to email a 200 MB engineering drawing to a Pentagon program manager, you already know the .mil mail gateway rejects almost anything over 10 MB. DoD SAFE (Secure Access File Exchange) at https://safe.apps.mil exists for exactly that gap — moving large or sensitive files between DoD personnel and external partners without standing up an FTP server, mailing a USB, or paying for a commercial transfer service.
What DoD SAFE Is (and Isn't)
DoD SAFE is a web-based, government-operated file-transfer service maintained by DISA. It uses HTTPS for transport and AES-256 at rest, requires CAC (Common Access Card) authentication to upload, and enforces a 7-day expiration on every package. It is FedRAMP-aligned and authorized for CUI.
It is NOT a collaboration platform, NOT a long-term storage system, and NOT authorized for classified information (SECRET / TS use SIPRNet, JWICS, or DoD SAFE-S — a separate classified system).
Limits You Need to Know in 2026
- Max package size: 8 GB total (across all files in one drop).
- Max recipients per package: 25 email addresses.
- File retention: 7 days, then automatic, unrecoverable deletion.
- Authentication: CAC required for senders; ECA (External Certification Authority) PKI certs also accepted.
- No CAC? Receive a drop-off request from a CAC holder and upload through that one-time link.
How to Send a Package (CAC Holders)
- 1Navigate to https://safe.apps.mil and select your CAC certificate.
- 2Click 'Drop-off' and enter recipient email addresses (.mil, .gov, or .com all work).
- 3Drag your files into the upload area (max 8 GB total).
- 4Add a note, set the expiration (1–7 days), and check 'Encrypt every file' for an extra password layer.
- 5Click 'Drop-off Files'. Recipients get a notification email with a one-time download link.
How Civilian Contractors Receive Files (No CAC)
If you're a defense contractor without a CAC and need to receive files, you don't need an account at all — your government POC drops off the package and you get an email with a download link. The link works once, expires in 7 days, and requires the recipient email to match.
How to Request a Pickup (No-CAC Contractors Sending In)
Sending files INTO the .mil network without a CAC requires a 'pickup' authorization. Your government sponsor logs into SAFE, creates a 'Request a Pickup' link, and emails it to you. You then upload through that one-time link — the file lands in their SAFE inbox and they retrieve it.
What You Can and Can't Send
- ✅ Allowed: CUI, FOUO, ITAR/EAR technical data (with proper marking), engineering drawings, contract deliverables, large datasets, software builds.
- ❌ Not allowed: Classified information at any level, child sexual abuse material, malware samples without prior coordination, personal/non-government files.
DoD SAFE vs. Commercial Alternatives
DoD SAFE is free, government-owned, and DISA-operated — which makes it the default for contract deliverables and any data the government wants to keep inside its trust boundary. Commercial alternatives (Egnyte Government Cloud, Box for Government, Microsoft GCC High) are appropriate for ongoing collaboration but require contracts, FedRAMP authorization paperwork, and CMMC alignment if you handle CUI.
Cybrvault's CMMC & CUI Handling Support
Cybrvault helps Miami-area DoD contractors stand up compliant CUI workflows: CMMC Level 1 and Level 2 readiness assessments, GCC High tenant configuration, SAFE-vs-Egnyte decision support, and incident response when a CUI-mishandling event triggers DFARS 252.204-7012 reporting. Read more in our CMMC Level 1 requirements guide and NIST 800-171 checklist.
// frequently asked
Questions teams ask us
Is DoD SAFE free?+
Yes. DoD SAFE is provided at no cost by DISA to the DoD community and authorized external partners. There are no fees, account tiers, or storage charges.
Can I send classified information through DoD SAFE?+
No. DoD SAFE is authorized for unclassified data including CUI. Classified data must move through SIPRNet, JWICS, or the separate DoD SAFE-S system.
How big a file can I send through DoD SAFE?+
Up to 8 GB total per drop-off package. If you need to send more, split into multiple packages or coordinate a different transfer mechanism with your government sponsor.
Do recipients need a CAC to download from DoD SAFE?+
No. Recipients only need access to the email address the sender specified. They receive a one-time download link that works for 7 days.
How do I send files to DoD SAFE without a CAC?+
Ask your government point of contact to log into safe.apps.mil and create a 'Request a Pickup' link addressed to your email. You'll receive a one-time upload link — no CAC or account required.
// miami, fl services
Cybersecurity built for South Florida
// need help applying this?
Book a free, confidential consultation.
Our engineers can map this to your environment in 30 minutes.
Get secured// keep reading
Related articles

DoD & Compliance
Understanding DoDI 8500.01: The 2026 Cybersecurity Guide for DoD Contractors
DoDI 8500.01 is the Department of Defense's foundational cybersecurity policy — the document that sets the rules every program, contractor, and information system must follow. Here's a plain-English 2026 breakdown of what it requires, how it connects to RMF and NIST 800-53, and what contractors need to know.

Compliance & Regulation
Florida Data Breach Notification Law (FIPA): The 2026 Compliance Guide for Miami Businesses
Florida's Information Protection Act (FIPA, §501.171) gives Miami businesses just 30 days to notify customers after a breach — and the AG can fine you up to $500,000 for missing it. Here's exactly what FIPA requires in 2026, who it covers, the 30-day clock, and the incident-response checklist Cybrvault uses with Miami clients.

Personal Security
Snap Hack: Understanding the Risks and How to Protect Your Snapchat Account in 2026
Snapchat accounts are hijacked every day through phishing 'login' pages, fake third-party 'snap score booster' apps, and SIM-swap attacks. Here's how Snap accounts actually get hacked in 2026, the red flags to watch for, and the 7-step lockdown that stops 95% of takeovers.
