How to Configure a Linux VPS into a Zero-Knowledge File Sharing Server with ProjectSend: Secure Document Delivery for Agencies
Introduction: The Growing Liability of Agency File Sharing
In the modern agency ecosystem—whether you manage creative assets, corporate financial data, or legal frameworks—data is your most valuable asset and your highest liability. Every time an agency shares confidential client files through mainstream public cloud services, they introduce a third-party risk variable. Standard public clouds often scan data for telemetry, maintain access to your encryption keys, and present an attractive target for bad actors.
For enterprise clients and rigorous agencies, the status quo is no longer sufficient. True data sovereignty requires transitioning to a Zero-Knowledge infrastructure model where you maintain absolute ownership over the server, the data, and the access rights. This comprehensive guide will walk you through transforming a private Linux Virtual Private Server (VPS) into a secure, self-hosted, client-branded document exchange hub using ProjectSend.
Understanding the Architectural Principles: Self-Hosting vs. Public Clouds
Before diving into the terminal, it is crucial to understand why a self-hosted Linux VPS paired with an open-source solution like ProjectSend outperforms commercial alternatives for B2B privacy:
- Data Sovereignty: Your files reside on isolated virtual hardware under your direct administrative control, completely bypassing big-tech data mining policies.
- Granular Authorization: ProjectSend allows agencies to assign specific files to specific clients, ensuring that users only see exactly what is intended for them—no broad cloud folders, no accidental exposure.
- Auditability: Every upload, download, and login event is logged natively, creating a clear audit trail essential for compliance-heavy industries.
What is a Zero-Knowledge Mindset in Self-Hosting? While ProjectSend provides the application layer for private distribution, true security relies on your server configuration. By combining isolated database privileges, forced transport-layer encryption (SSL/TLS), and hardened Linux access controls, you achieve an operational state where no unauthorized entity can intercept client data.
Prerequisites and Environment Setup
To successfully complete this deployment, ensure you have gathered the following infrastructural components:
- A clean Linux VPS running Ubuntu 24.04 LTS or Debian 12.
- A registered domain or subdomain (e.g., portal.youragency.com) pointed to your VPS IP address via an A Record.
- Root or
sudoadministrative access to the server terminal.
Step 1: System Update and LAMP Stack Installation
ProjectSend is built on the robust PHP and MySQL architecture. We will start by updating our system packages and installing the Apache web server, MariaDB (an enterprise-grade MySQL drop-in replacement), and PHP along with its necessary extensions.
Connect to your VPS via SSH and execute the following commands:
sudo apt update && sudo apt upgrade -y
sudo apt install apache2 mariadb-server php php-mysql php-gd php-bcmath php-curl php-mbstring php-xml php-zip unzip curl -yOnce the installation finishes, verify that Apache and MariaDB are running and set to launch automatically upon system boot:
sudo systemctl enable --now apache2
sudo systemctl enable --now mariadbStep 2: Securing the Database Layer
A secure file platform requires an isolated database environment. First, run the native binary script to secure your database engine installation:
sudo mysql_secure_installationFollow the prompts to enforce strong password policies, remove anonymous users, disallow root login remotely, and drop the test database. Next, log into the MariaDB shell to construct a dedicated database and restricted user account for ProjectSend:
sudo mysql -u root -pExecute the following SQL queries within the prompt, replacing Secure_Agency_Password with a high-entropy string:
CREATE DATABASE projectsend_db CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'projectsend_user'@'localhost' IDENTIFIED BY 'Secure_Agency_Password';
GRANT ALL PRIVILEGES ON projectsend_db.* TO 'projectsend_user'@'localhost';
FLUSH PRIVILEGES;
EXIT;Step 3: Downloading and Configuring ProjectSend
With our foundation in place, we navigate to the web root directory to pull the latest stable distribution of ProjectSend directly from its official repository.
cd /tmp
curl -LO [https://www.projectsend.org/download/latest/](https://www.projectsend.org/download/latest/)
unzip latest -d projectsend
sudo mv projectsend /var/www/html/projectsendConfiguring Application Parameters
ProjectSend relies on a core configuration file to link with your database. Duplicate the distribution template and open it for editing:
cd /var/www/html/projectsend/sys.config.properties.php.dist sys.config.php
sudo nano sys.config.phpLocate the database definitions and populate them with the credentials established in Step 2:
define('DB_NAME', 'projectsend_db');
define('DB_USER', 'projectsend_user');
define('DB_PASSWORD', 'Secure_Agency_Password');
define('DB_HOST', 'localhost');Save and close the file. Now, apply rigorous ownership and permission masks to protect the application code while allowing Apache to manage uploads securely:
sudo chown -R www-data:www-data /var/www/html/projectsend/
sudo chmod -R 755 /var/www/html/projectsend/Step 4: Configuring Apache and Enforcing TLS/SSL Encryption
Transmitting sensitive documents over unencrypted channels breaks all privacy principles. We must configure a virtual host file for Apache and wrap the connection in an automated Let's Encrypt SSL certificate.
Create a new Apache configuration file:
sudo nano /etc/apache2/sites-available/projectsend.confPaste the following structural layout, ensuring you update the ServerName to your agency's domain:
ServerAdmin [email protected]
DocumentRoot /var/www/html/projectsend
ServerName portal.youragency.com
Options FollowSymLinks
AllowOverride All
Require all granted
ErrorLog ${APACHE_LOG_DIR}/projectsend_error.log
CustomLog ${APACHE_LOG_DIR}/projectsend_access.log combined
Enable the site configuration along with the Apache rewrite module, then restart the service:
sudo a2ensite projectsend.conf
sudo a2enmod rewrite
sudo systemctl restart apache2Automating SSL via Certbot
Install the Certbot client and its Apache plugin to automatically negotiate an SSL certificate and force global HTTPS redirection:
sudo apt install certbot python3-certbot-apache -y
sudo certbot --apache -d portal.youragency.comSelect the option to automatically redirect all HTTP traffic to HTTPS when prompted by the script.
Step 5: Post-Installation Wizard and Best Practices
Navigate to your domain via a web browser: [https://portal.youragency.com](https://portal.youragency.com). You will be greeted by the ProjectSend web installation wizard. Provide your agency's primary administrative details, including a secure administrator username and password.
Once inside the dashboard, configure these key agency-level preferences:
- Brand Customization: Upload your agency's logo, adjust the primary color matrix to reflect your branding guidelines, and customize the automated notification emails sent to clients.
- User Roles: Implement a strict zero-trust permission layout. Create isolated accounts for your account executives and distinct access profiles for your external clients.
- File Expiration Policies: Mitigate digital hoarding risks by setting auto-expiry values on highly confidential documents, ensuring files are automatically purged from the server disk space after a set number of days.
Conclusion: Control the Pipeline, Protect the Client
By moving away from commercial public cloud providers and deploying an isolated ProjectSend instance on your own Linux VPS, your agency takes definitive control over its security pipeline. You gain a fully branded, highly professional asset distribution system that demonstrates to enterprise clients that your agency values their digital privacy as highly as your own operational output. Maintain your server updates, use strong passwords, and confidently run a secure, zero-knowledge adjacent pipeline tailored for modern business agility.
