Secure upload portal
Controlled inbound files
A secure file upload portal, with a clear route back to your team
Collect sensitive documents from clients, suppliers and applicants without asking them to improvise. Each upload can be linked to the intended exchange, recipient and access conditions.
The upload journey
Secure file upload without a public drop zone
The person uploading is usually outside your organisation and using your system for the first time. The path has to be short enough that they complete it and controlled enough that you can rely on what arrives.
- Select. The file, bundle or complete folder, whatever its size.
- Enter the route. A named, protected path instead of a public mailbox.
- Upload with progress. Visible confirmation that something is happening.
- Store and record. Governed destination, with arrival details retained.
Where intake matters
Six collection points worth taking off email.
These are the flows where a shared mailbox is doing work it was never designed for, usually holding sensitive material indefinitely with no clear owner.
A mailbox is not an intake process
Shared inboxes accumulate personal and commercial data, grant access to whoever has the credentials and rarely have a retention rule anybody applies.
Client onboarding
Identity documents, proof of address and signed agreements from people using your systems for the first time.
Supplier submissions
Tender responses, specifications and compliance documentation arriving against a deadline.
Recruitment
Applications, references and right-to-work documents, all carrying personal data with a defined retention need.
Claims and case files
Evidence, photographs and reports from customers or third parties, often large and unstructured.
Project delivery
Drawings, datasets and media from contractors, where size alone rules out email.
Two ways to receive a file
The difference shows up when somebody asks what you were sent.
Both routes get the file to you. Only one of them leaves you able to say who sent it, when it arrived and what has happened to it since.
What collecting by email costs
Convenient to set up, and progressively harder to govern as volume and sensitivity build.
- Anyone with the credentials. Access is to the mailbox, not to a specific submission.
- No size headroom. Large submissions arrive split, compressed or not at all.
- Nothing expires. Attachments remain until somebody manually clears them.
- Attribution by header. Sender identity rests on an address that was typed in.
What a governed route gives you
A defined path with an owner, a record and controls that match the sensitivity of what you are collecting.
- Named submitters. You know who uploaded, not just which address it came from.
- Any size. Complete folders and large media without an improvised workaround.
- Defined retention. Material has an expected lifetime from the moment it lands.
- An arrival record. Time, contents and submitter retained together.
Designing the intake
Four decisions that determine whether people use it.
An upload route competes with an email address that already works. It has to be at least as easy, or the mailbox quietly wins and you have deployed a portal nobody sends to.
Decide what you are asking for
Be specific about which documents you need and in what form. Vague requests produce partial submissions, repeated exchanges and frustrated senders. A clear list also supports minimisation, because you collect what the purpose requires instead of whatever the person decides to send.
Make the first step obvious
The submitter should understand within a few seconds what to do and roughly how long it will take. Anything that requires an explanation from your team is a step you will pay for repeatedly, in support time and in submissions that never arrive.
Plan for failure
Test what happens with an oversized file, an interrupted connection, an expired invitation and a restricted device. Each should produce a clear message and a route to a person. A dead end at this point usually ends with the material arriving by email instead.
Decide where it goes next
Intake is not storage. Define who owns arriving material, where it moves to and how long it stays in the collection point. Without that, a portal becomes the same accumulation problem as the mailbox it replaced, just with better access control.
What the submitter does
Four steps, from their side of the exchange.
Written from the perspective of somebody who does not work for you, has not used the system before and is doing this between two other tasks.
Receive the request
A clear invitation stating what is needed and roughly how long it takes.
Add the files
Whatever the size, including a folder, without installing anything.
Confirm identity
A verification step proportionate to what is being collected.
Get confirmation
Visible acknowledgement that it arrived, so nobody sends it twice by email.
The quiet benefit
A good intake route improves your data protection position and your service at the same time.
Collecting only what you asked for, from a person you can identify, with a known retention period, is a minimisation and accountability improvement. It also happens to look more professional to the client.
Governed collection
Replace the shared mailbox for one intake workflow.
Start a seven-day trial for up to five users, or ask for a demonstration built around your onboarding or supplier submission process.