Collecting bank statements and financial documents from bookkeeping clients
To collect bank statements, credit card statements, receipts and invoices from bookkeeping clients each month, send each client a ShieldFive document request: one link that lists the documents for that period, which the client opens on a phone or computer and uploads to without creating an account. Each file is encrypted in the client's browser before upload, so ShieldFive stores only ciphertext and never holds your keys.
Specs
Updated .
| Client needs an account? | No. No account, no sign-in, no app. The client needs the link and the PIN. |
|---|---|
| PIN | Required, at least 4 characters, chosen by you and sent separately from the link. |
| Max file size | 5 GB per file. |
| Max per request | About 2 GB in total by default. |
| Files per request | 25 by default, adjustable from 1 to 100. |
| File types | Any type: PDF statements, phone photos of receipts, spreadsheets and CSV exports. |
| Checklist | Up to 100 requested items per request. You write the list; reuse it each month with Send this checklist to another client. |
| Link expiry | Up to 7 days on the free plan. 7, 30 or 90 days, or no expiry, on Firm seats and during the 14-day trial; 30 days by default. |
| Reminders to you | An email when files arrive, and a reminder to follow up if nothing has arrived after about 3 and 7 days. Every plan. |
| Reminders to the client | On Firm seats and during the trial, if you add the client's email: at most 2, after about 3 and 7 days, while required items are missing. One click stops them. |
| Your branding | Your firm name and logo on the upload page and the client reminder, on Firm seats and during the trial. |
| Plans | 14-day trial with everything unlocked, no card. Then free with 1 open request at a time, or a Firm seat at €29 per month (€290 per year). Clients never pay and do not use a seat. |
| Encryption | Client-side, in the client's browser, to your firm's public keys. File names and the checklist are encrypted too. ShieldFive never holds the keys. |
Steps
- Unlock your vault, open Requests and choose Request documents.
List what you need for the period, one per line, naming the account and the month: "Business checking statement, September", "Credit card statement, September", "Receipts over $75", "Sales invoices issued". End a line with "(optional)" to mark it optional.
Set a PIN and an expiry that covers your close date. Add the client's email if you want ShieldFive to remind them.
Select Create secure link. Send the link in your month-end email or message, and give the PIN another way, such as by text or on the phone.
The client uploads a PDF download or a phone photo into each slot. They can send what they have and come back to the same link for the rest. If a document came another way, or is not needed this month, mark that item received or not needed.
When you are emailed that something arrived, open Requests and use Download & decrypt. Revoke the link once you have everything; received files stay in your vault.
Next month, open the request and choose Send this checklist to another client to start a new link with the same list. You can reuse it for the same client or a different one.
Compared with email, file-sharing links and client portals
| Email attachments | Generic file request (Dropbox, OneDrive) | Client portal | ShieldFive document request | |
|---|---|---|---|---|
| Client needs an account? | No | No | Usually a login; some portals also accept uploads by link | No. A link and a PIN |
| List of what you need | In the email text | One upload box per request | Varies by portal | One upload slot per document, required or optional |
| Who can read stored files | Both mail providers, and anyone with mailbox access | The provider can decrypt by default | Usually the vendor holds the keys | Only your firm. ShieldFive stores ciphertext |
| Turn it off | Cannot recall a sent attachment | Close the request | Remove access | Revoke the link, or let it expire |
| Also does billing, e-signature, workflow | No | No | Usually yes | No. It only collects documents |
Limits
ShieldFive does not send the link for you. Part of the decryption key is in the
#fragment of the link and never reaches our servers, so you send the link yourself, and it has to arrive complete. The client-reminder email cannot contain the link for the same reason.There are no recurring requests. Each month you create a new link, though Send this checklist to another client copies the list for you.
It collects documents. It does not connect to bank feeds, read statements or post transactions to your accounting software.
Clients choose files, not folders. The page has to stay open while files encrypt and upload.
Nothing identifies the uploader automatically. If you need to be certain who sent a document, confirm it with the client through a channel you already trust.
The upload page is code ShieldFive serves, so the client trusts that code at the moment of upload, as with every browser-based encryption product.
Full details of every limit are in Requesting documents from a client. For the workflow in short, see Document requests for bookkeepers, and for why email is a poor channel for financial records, Email vs secure file sharing.