Skip to content

Privacy and preparation

How to transfer terabytes of data securely

By SourceX Editorial · Updated

Short answer

To transfer terabytes of data securely, pick the method by where the data lives and the bandwidth you can sustain, then apply the same controls to every method: encryption in transit and at rest, a hashed file manifest, keys sent separately, expiring access and a signed receipt. For licensing deals, seller-hosted storage or encrypted drives usually fit best.

Key takeaways

  • Estimate transfer time from the throughput you actually sustain, not the rated speed of your connection.
  • Seller-hosted storage with expiring, read-only access keeps the master copy under the supplier's control.
  • Encrypted drives suit very large or on-premises archives, provided keys travel by a separate channel.
  • A manifest with a hash for every file lets both sides prove the delivery arrived complete and unchanged.
  • Revoking access stops new downloads; the license's deletion terms govern copies already made.

What decides the right way to move terabytes?#

The right way to move terabytes is decided by three facts: where the data sits now, how much upload bandwidth you can dedicate without hurting operations, and what the receiving side can accept. Security rarely decides the method, because every serious option can be made secure; it decides the controls you add.

Work out the transfer time first. Divide the dataset size by the throughput you can sustain in your available window, not the line's rated speed, and add time for retries and verification. The table shows the raw arithmetic for common sizes and speeds. If the answer is longer than the delivery schedule allows, a physical shipment or a copy inside the same cloud is usually the practical choice.

The figures are arithmetic only, using decimal terabytes and a link that runs at that rate around the clock. Real transfers add protocol overhead, retries, hashing and the hours when the link is needed for normal work, so treat them as a floor rather than a forecast.

Then check the receiving side. Some buyers prefer to pull from a bucket in a cloud region they already use; others accept drives at a secure intake location. Agree on format, partitioning and the verification method before anything moves.

What decides the right way to move terabytes?
Dataset sizeAt 100 Mbps sustainedAt 1 Gbps sustainedAt 10 Gbps sustained
1 TBAbout 22 hoursAbout 2.2 hoursAbout 13 minutes
10 TBAbout 9 daysAbout 22 hoursAbout 2.2 hours
50 TBAbout 46 daysAbout 4.6 daysAbout 11 hours

How do the four transfer methods compare?#

The four transfer methods differ mainly in what limits speed, what drives cost and who controls the copy while it moves. All four can pass a buyer's security review if the controls described below are applied.

Cloud providers also offer physical transfer appliances that they ship to you and load into their storage. Models, regions and availability change, so check the provider's current documentation before planning around one.

How do the four transfer methods compare?
MethodBest fitSpeed driverCost driversMain security watch-out
Network push to the buyerSmaller deliveries over a strong, dedicated uplinkSustained upload throughput and latencyStaff time, bandwidth, transfer tool licensesCredentials for the buyer's endpoint; half-finished transfers left on servers
Seller-hosted cloud storageData already in your cloud account; the buyer pullsThe buyer's download throughputStorage and egress charges in your accountOver-broad access policies and links that never expire
Cloud-to-cloud copyBoth sides use the same providerThe provider's internal network, usually the fastest pathProvider transfer and egress chargesCross-account roles left in place after delivery
Encrypted drivesVery large archives, slow uplinks, on-premises storageCopy speed to disk plus shippingDrives, courier, staff time to load and verifyKeys shipped with the drives; packages without tracking

Why seller-hosted storage is usually the default#

Seller-hosted storage is usually the default for licensing because the master copy never leaves the supplier's account. The buyer gets read-only access to one prepared bucket or container for a fixed window, and every download is logged where the supplier can see it.

Set it up as a separate delivery location, not a folder inside production storage. Grant access to the buyer's specific account or role rather than through a public or shareable link, block writes and deletes, switch on access logging and set the expiry date when you create the grant.

Some providers let the bucket owner shift download charges to the requester. Check whether yours does, and agree in the deal terms who bears transfer costs, so a large pull does not surprise either side.

Controls every transfer needs#

Every transfer needs the same core controls whatever the method, because the risks are the same: interception, tampering, an incomplete copy and access that outlives the license.

Write these into a delivery plan both sides sign before anything moves. A control agreed in advance is far easier to enforce than one requested after the data arrives.

  • Encryption in transit through the transfer tool's or provider's secure protocol, and encryption at rest on every intermediate copy.
  • Keys and passphrases sent by a separate channel to a named person, never in the same email, package or bucket as the data.
  • A manifest listing every file with its path, size, record count and a cryptographic hash such as SHA-256.
  • Verification on arrival: the buyer recomputes the hashes and returns a signed receipt that matches the manifest.
  • Least-privilege access: one buyer identity, read-only, scoped to the delivery location, with an expiry date.
  • Download and access logs kept with the delivery record.
  • Revocation at the end of the window, followed by whatever deletion or return terms the license sets.

How to prepare a manifest and chain of custody#

A manifest and a chain of custody record together prove what was delivered, when and to whom. The manifest describes the contents; the custody record tracks every handoff of the data or of the drives that carry it.

Partition large datasets into archives of manageable size by system, year or record type rather than one enormous file. A failed or corrupted part can then be resent alone, and the buyer can verify progress as parts arrive.

How to prepare a manifest and chain of custody
RecordWhat it containsWho signs
File manifestPaths, sizes, record counts, hashes, dataset version and date rangeSupplier, at release
Transfer logMethod, start and end times, endpoints or tracking numbersSupplier operator
Drive custody formDrive serial numbers, encryption method, seal numbers, courier handoffsEach person who handles the drives
ReceiptHashes recomputed by the buyer and any mismatchesBuyer
Access closure noteDate access was revoked and where logs are keptSupplier
Deletion or return certificateWhat was deleted or returned at license end, and howBuyer

Shipping encrypted drives without losing control#

Shipping encrypted drives keeps control when the drives are encrypted before they leave the building, the keys travel separately and every handoff is signed. Hardware-encrypted drives and full-disk encryption with a strong passphrase both work; what matters is that a lost package exposes nothing.

Use tamper-evident packaging, a tracked courier with signature on delivery and a named recipient at the buyer. Send the passphrase only after the buyer confirms receipt and the seal numbers match, and keep your own encrypted copy until the buyer's receipt confirms every hash.

Drives also suit archives that never lived in the cloud, such as on-premises file servers, scanned document stores or backups from a retired system. Loading straight from the source to an encrypted drive avoids an extra cloud copy that would need its own access controls and deletion.

Illustrative: a 3PL delivers years of warehouse records#

Illustrative: a fictional third-party logistics company licenses several years of warehouse management scan events, transportation records and scanned proof-of-delivery images. The event and shipment data sit in its cloud data warehouse; the images live on an on-premises file server, and the warehouses share a modest internet uplink.

The CTO chose two methods. Structured data went to a separate bucket in the company's own cloud account, with read-only access granted to the buyer's account for a fixed window and logging switched on. The image archive went on hardware-encrypted drives with a custody form, and passphrases followed by a separate channel once the seals were checked.

Both deliveries shared one manifest. The buyer's receipt flagged a hash mismatch in one partition, which was resent alone. At the end of the window the company revoked access and filed the logs with the delivery record, and the license's deletion terms now govern the buyer's copy.

How SourceX handles large deliveries#

SourceX handles large deliveries as the Delivery step of the SourceX five-step transaction, after Supply, Rights, Preparation and Approval are complete. Large datasets remain in storage the seller controls or travel on encrypted drives; SourceX never hosts multi-TB datasets, and it records the handover method and its details instead.

The manifest, receipt and access closure note join the SourceX Evidence Packet alongside provenance, licensing rights, permitted use, the privacy record and release authorization, so the supplier can show exactly which version was released and under which approval.

Frequently asked questions

How long does it take to send 10 TB of data?

At a sustained 1 Gbps, 10 TB takes about 22 hours of pure transfer time; at 100 Mbps it takes about nine days. Add time for retries, hashing and verification, and for any hours when the link is needed for normal work. If the result misses your delivery date, use a cloud-to-cloud copy or encrypted drives.

Who pays the egress charges when the buyer downloads from our bucket?

By default the account that owns the storage usually pays for data leaving it, so settle this in the deal terms. Options include building the cost into the license, using a requester-pays option where your provider offers one, or delivering by cloud-to-cloud copy or drives instead. Check your provider's current pricing before choosing.

Is a shareable link from a file-sharing service good enough?

For terabytes of licensed records it usually is not. Shareable links often cannot be tied to one identity, may not expire by default and give limited download logs. Use them only for small, non-sensitive files such as a copy of the manifest, and deliver the dataset itself through a controlled method.

Do we need encryption at rest if the connection is already encrypted?

Yes. Encryption in transit protects data while it moves; encryption at rest protects each copy that sits somewhere along the way, such as a staging bucket, a drive in a courier's van or a buyer's intake server. Data spends far longer sitting in those places than crossing a network.

Can we take data back after the buyer downloads it?

No technical step can recall a copy that has already been downloaded. Revocation stops further access, while the license governs existing copies through use limits, deletion or return at term end and a signed certificate. That is why the contract terms and the transfer plan should be agreed together.

Should we compress the data before sending it?

Compression helps for text-heavy data such as logs, tickets and CSV exports, and does little for images, audio or files that are already compressed. Compress by partition, hash the compressed files rather than the originals, and test that the buyer can open a sample before the full transfer starts.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify