Back to articles
Technology Insight

How to Configure a Linux VPS into a Zero-Knowledge File Sharing Server with ProjectSend for Agency Clients

May 26, 2026

Introduction: The Growing Liability of Public Cloud Storage

In the modern agency ecosystem—whether you manage corporate branding, architectural designs, financial consulting, or legal marketing—the data you handle is your most valuable asset. Every day, agencies exchange high-value deliverables, source codes, financial audits, and pre-launch campaigns with clients. Relying on mainstream, public cloud storage providers like Google Drive, Dropbox, or WeTransfer has become an operational risk. These platforms often retain data mining rights under their terms of service, suffer from frequent credential stuffing attacks, and strip your agency of its professional identity through generic interfaces.

For enterprise-grade clients, data sovereignty and privacy are non-negotiable. To position your agency as a premium, security-first partner, you must control your data pipeline. This guide provides a comprehensive, step-by-step blueprint to configuring a standard Linux Virtual Private Server (VPS) into a dedicated, self-hosted "Zero-Knowledge" File Sharing Server utilizing ProjectSend. By shifting to a self-hosted architecture, you ensure that third-party entities have absolute zero visibility into your client deliverables.


Why ProjectSend and a Dedicated VPS Fit the Agency Model

ProjectSend is an open-source, self-hosted file-sharing platform designed specifically for businesses to provide files to clients. Unlike generic cloud drives, it focuses on explicit client-to-file relationships. When paired with a private Linux VPS, it offers several distinct advantages:

  • Complete Data Sovereignty: Your data resides exclusively on your private disk space. No external algorithms scan your documents for telemetry or advertising purposes.
  • White-Label Branding: Eliminate third-party logos. Your clients log into an interface that features your corporate branding, domain, and security certificates, reinforcing trust.
  • Granular Access Control: Assign files to specific clients or predefined client groups, ensuring strict compartmentalization of sensitive assets.
  • Cost Efficiency and No User Caps: Public clouds charge per seat. A Linux VPS allows you to host unlimited clients and terabytes of data, capped only by your hardware resources.
What does 'Zero-Knowledge' mean in this context? While traditional zero-knowledge implies client-side encryption keys, in a self-hosted agency infrastructure, it represents operational zero-knowledge toward public tech conglomerates. You control the operating system, the database, the encryption layers, and the access logs. No outside entity holds the keys to your client environment.

Phase 1: Setting Up Your Linux VPS Environment (LAMP Stack)

To ensure optimal performance and security, we recommend provisioning a VPS running Ubuntu 24.04 LTS with at least 2 vCPUs, 4GB of RAM, and NVMe storage allocated based on your average client file sizes. Connect to your server via SSH and execute the following steps to establish a secure Linux, Apache, MySQL, and PHP (LAMP) stack.

Step 1: System Update and Core Utilities

First, update the repository index and upgrade existing packages to patch any upstream vulnerabilities:

sudo apt update && sudo apt upgrade -y

Step 2: Install Apache and MySQL Server

Install the web server and database engine. We use MySQL to store metadata, client accounts, and access logs securely.

sudo apt install apache2 mysql-server -y

Secure your database installation by running the built-in security script. Enable robust password validation policies and remove anonymous test databases:

sudo mysql_secure_installation

Step 3: Install PHP 8.x and Required Extensions

ProjectSend is built on PHP. It requires several extensions for handling file uploads, encryption, and database communication. Install them using the following command:

sudo apt install php libapache2-mod-php php-mysql php-gd php-json php-curl php-mbstring php-zip php-xml -y

Phase 2: Database Creation and Directory Security

ProjectSend requires a dedicated SQL database. Log into your MySQL console as root to configure a secure, isolated database user.

sudo mysql -u root -p

Execute the following queries within the MySQL prompt, replacing 'Strong_Secure_Password' with an enterprise-grade alphanumeric passphrase:

CREATE DATABASE projectsend_db CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'projectsend_user'@'localhost' IDENTIFIED BY 'Strong_Secure_Password';
GRANT ALL PRIVILEGES ON projectsend_db.* TO 'projectsend_user'@'localhost';
FLUSH PRIVILEGES;
EXIT;

Phase 3: Deploying and Configuring ProjectSend

Navigate to your server's web directory, download the latest stable release of ProjectSend, and configure its system paths.

Step 1: Download the Source Files

cd /var/www/html
sudo wget -O projectsend.zip [https://www.projectsend.org/download/download.php](https://www.projectsend.org/download/download.php)
sudo apt install unzip -y
sudo unzip projectsend.zip -d projectsend
sudo rm projectsend.zip

Step 2: Configure System Permissions

For absolute security, the web server user (www-data) must own the upload and configuration files, while restricting world-readable access:

sudo chown -R www-data:www-data /var/www/html/projectsend
sudo chmod -R 755 /var/www/html/projectsend

Step 3: Setup the Core Configuration File

Copy the template configuration file and input your database credentials:

cd /var/www/html/projectsend/sys.config.properties.php
# (Alternatively, older versions use sys.config.php inside the /includes/ directory)
sudo cp includes/sys.config.sample.php includes/sys.config.php
sudo nano includes/sys.config.php

Edit the file to match your created database parameters:

define('DB_NAME', 'projectsend_db');
define('DB_USER', 'projectsend_user');
define('DB_PASSWORD', 'Strong_Secure_Password');
define('DB_HOST', 'localhost');

Phase 4: Enforcing Enterprise-Grade Security and SSL Encryption

An unencrypted file-sharing portal is a massive liability. We must configure Apache to use HTTP/2, enforce strict transport security, and bind a free Let's Encrypt SSL certificate to your custom agency domain (e.g., portal.youragency.com).

Step 1: Create an Apache Virtual Host

sudo nano /etc/apache2/sites-available/projectsend.conf

Insert the following configuration layout, optimizing for secure file handling:


    ServerAdmin [email protected]
    DocumentRoot /var/www/html/projectsend
    ServerName portal.youragency.com

    
        Options +FollowSymlinks
        AllowOverride All
        Require all granted
    

    ErrorLog ${APACHE_LOG_DIR}/projectsend_error.log
    CustomLog ${APACHE_LOG_DIR}/projectsend_access.log combined

Enable the site configuration and the Apache rewrite module:

sudo a2ensite projectsend.conf
sudo a2enmod rewrite
sudo systemctl restart apache2

Step 2: Deploy TLS/SSL Certificates via Certbot

Install Certbot to automate SSL provisioning and force all traffic over encrypted HTTPS connections:

sudo apt install certbot python3-certbot-apache -y
sudo certbot --apache -d portal.youragency.com

Select the option to automatically redirect HTTP traffic to HTTPS during the prompt sequence. This ensures all file packets are encrypted using TLS 1.3 during transit.


Phase 5: Optimizing PHP for Large Agency Deliverables

By default, PHP severely limits file upload sizes (often capped at 2MB). Since video assets, raw design packages, and legal records frequently span gigabytes, we must adjust php.ini variables.

sudo nano /etc/php/8.x/apache2/php.ini

Locate and adjust the following parameters to match your agency’s maximum file size demands (e.g., 4 Gigabytes):

upload_max_filesize = 4000M
post_max_size = 4000M
memory_limit = 512M
max_execution_time = 3600
max_input_time = 3600

Restart your Apache service to commit these runtime variables:

sudo systemctl restart apache2

Conclusion: Launching the Web-Based System Installation

With the backend infrastructure securely sealed, navigate to [https://portal.youragency.com/install/index.php](https://portal.youragency.com/install/index.php) via your web browser. The ProjectSend interactive installer will verify your server dependencies, automatically populate database tables, and prompt you to establish your master Administrator credentials.

Once inside the dashboard, navigate to the Options menu to disable public registrations, upload your corporate branding vectors, and enable automated email notices. You now possess a private, highly secure, fully white-labeled file sharing node that insulates your client communication workflows from global data networks—a significant competitive edge and a powerful baseline metric for client retention.

How to Configure a Linux VPS into a Zero-Knowledge File Sharing Server with ProjectSend for Agency Clients | DPTCloud