Collecting bank statements and pay stubs from loan applicants

To collect bank statements, pay stubs, W-2s, tax returns and ID from mortgage or loan applicants, send each borrower a ShieldFive document request: one link with the list of documents the file needs, which the borrower opens on a phone or computer and uploads to without creating an account. Each file is encrypted in the borrower's browser before upload, so ShieldFive stores only ciphertext and never holds your keys.

Specs

Updated .

ShieldFive document request specs for collecting loan application documents
Client needs an account?No. No account, no sign-in, no app. The client needs the link and the PIN.
PINRequired, at least 4 characters, chosen by you and sent separately from the link.
Max file size5 GB per file.
Max per requestAbout 2 GB in total by default.
Files per request25 by default, adjustable from 1 to 100.
File typesAny type: PDF statements, phone photos, scans.
ChecklistUp to 100 requested items. A Mortgage application packet template, transcribed from the CFPB's loan application packet list, is built in.
Link expiryUp to 7 days on the free plan. 7, 30 or 90 days, or no expiry, on Firm seats and during the 14-day trial; 30 days by default.
Reminders to youAn email when files arrive, and a reminder to follow up if nothing has arrived after about 3 and 7 days. Every plan.
Reminders to the clientOn Firm seats and during the trial, if you add the client's email: at most 2, after about 3 and 7 days, while required items are missing. One click stops them.
Your brandingYour firm name and logo on the upload page and the client reminder, on Firm seats and during the trial.
Plans14-day trial with everything unlocked, no card. Then free with 1 open request at a time, or a Firm seat at €29 per month (€290 per year). Clients never pay and do not use a seat.
EncryptionClient-side, in the client's browser, to your firm's public keys. File names and the checklist are encrypted too. ShieldFive never holds the keys.

Steps

  1. Unlock your vault, open Requests and choose Request documents.
  2. Start from the Mortgage application packet template, or list the documents yourself, one per line. Add what your lender asks for beyond the standard packet, such as "Bank statements, all pages" or "Letter explaining large deposit". End a line with "(optional)" to mark it optional.

  3. Set a PIN and an expiry that covers your closing timeline. Add the borrower's email if you want ShieldFive to remind them.

  4. Select Create secure link. Send the link by email or text, and give the PIN another way, such as on the phone.

  5. The borrower uploads a PDF or a phone photo into each slot. They can send what they have today and come back to the same link when the next statement or pay stub arrives.

  6. When you are emailed that something arrived, open Requests and use Download & decrypt. If the underwriter asks for one more document, raise the file limit on the live request with Raise the file limit or send a new request. Revoke the link once the file is complete; received files stay in your vault.

Compared with email, file-sharing links and client portals

Collecting loan documents: email, file-sharing links, client portals and ShieldFive compared
Email attachmentsGeneric file request (Dropbox, OneDrive)Client portalShieldFive document request
Client needs an account?NoNoUsually a login; some portals also accept uploads by linkNo. A link and a PIN
List of what you needIn the email textOne upload box per requestVaries by portalOne upload slot per document, required or optional
Who can read stored filesBoth mail providers, and anyone with mailbox accessThe provider can decrypt by defaultUsually the vendor holds the keysOnly your firm. ShieldFive stores ciphertext
Turn it offCannot recall a sent attachmentClose the requestRemove accessRevoke the link, or let it expire
Also does billing, e-signature, workflowNoNoUsually yesNo. It only collects documents

Limits

  • ShieldFive does not send the link for you. Part of the decryption key is in the # fragment of the link and never reaches our servers, so you send the link yourself, and it has to arrive complete. The client-reminder email cannot contain the link for the same reason.

  • It collects documents. It does not verify income or assets, pull credit, or connect to a loan origination system.

  • Clients choose files, not folders. The page has to stay open while files encrypt and upload.

  • Nothing identifies the uploader automatically. If you need to be certain who sent a document, confirm it with the client through a channel you already trust.

  • The upload page is code ShieldFive serves, so the client trusts that code at the moment of upload, as with every browser-based encryption product.

Full details of every limit are in Requesting documents from a client. For what the CFPB packet contains and why email is a poor channel for it, see How mortgage brokers can collect bank statements and pay stubs securely, and for the list itself, the mortgage application checklist.