All insights

How should advisers share documents with clients securely?

2 min readBy Brendon Whiting, Founder · 26 June 2026

With links restricted to the named recipient and given an expiry, rather than attachments. If a document goes to the wrong address a link can be revoked and an attachment cannot, and for a firm holding client financial information that difference is the difference between a mistake and a notifiable breach.

Advice work generates exactly the documents you least want misdirected: statements of advice containing a client's complete financial position, identity documents, account details, insurance and estate information. The default habit of attaching them to email surrenders control of that copy permanently, provides no record of who opened it, and offers no remedy when the address was mistyped, which remains the most common cause of privacy incidents in professional services.

The setting that matters is the link type. Anyone-with-the-link works for whoever holds it, including in a forwarded email months later, which is convenient and inappropriate for this material. Specific-people requires the recipient to verify who they are and is the right default. Add expiry so links do not outlive their purpose, and set view rather than edit unless collaboration is intended. These can all be tenant defaults, which is far more reliable than instructing people.

Receiving matters as much as sending and gets almost no attention. Clients email identity documents and bank statements because nobody gave them another route, so highly sensitive material accumulates in mailboxes with no structure and no retention. An upload link that deposits documents straight into the client area solves the security and the record-keeping problem together, and clients generally find it easier than attaching files. If you want it configured so the secure path is the quick one, call 1800 456 567.

Make the secure route the quick one

We configure sharing so restricted expiring links are the default, and client documents arrive in the client file rather than a mailbox.

Frequently asked questions

Those are exactly what should not sit in a mailbox indefinitely, and they usually do. Passports, licences and bank statements arriving as attachments end up duplicated across devices with no retention and no structure. An upload link into the client area puts them where your controls apply from the moment they arrive.

Not necessarily, and many advice platforms include one worth using. Where the portal is clunky enough that staff avoid it, a properly configured secure link is better than a portal nobody uses, because the security of a route people bypass is zero. Judge it on whether staff actually use it.

Long enough for the client to act and no longer, which for most documents is weeks rather than indefinitely. Expiry matters because links outlive their purpose silently, and a live link from three years ago in a forwarded email is an exposure nobody remembers creating.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.