Collecting bank statements and pay stubs from loan applicants
To collect bank statements, pay stubs, W-2s, tax returns and ID from mortgage or loan applicants, send each borrower a ShieldFive document request: one link with the list of documents the file needs, which the borrower opens on a phone or computer and uploads to without creating an account. Each file is encrypted in the borrower's browser before upload, so ShieldFive stores only ciphertext and never holds your keys.
Specs
Updated .
| Client needs an account? | No. No account, no sign-in, no app. The client needs the link and the PIN. |
|---|---|
| PIN | Required, at least 4 characters, chosen by you and sent separately from the link. |
| Max file size | 5 GB per file. |
| Max per request | About 2 GB in total by default. |
| Files per request | 25 by default, adjustable from 1 to 100. |
| File types | Any type: PDF statements, phone photos, scans. |
| Checklist | Up to 100 requested items. A Mortgage application packet template, transcribed from the CFPB's loan application packet list, is built in. |
| Link expiry | Up to 7 days on the free plan. 7, 30 or 90 days, or no expiry, on Firm seats and during the 14-day trial; 30 days by default. |
| Reminders to you | An email when files arrive, and a reminder to follow up if nothing has arrived after about 3 and 7 days. Every plan. |
| Reminders to the client | On Firm seats and during the trial, if you add the client's email: at most 2, after about 3 and 7 days, while required items are missing. One click stops them. |
| Your branding | Your firm name and logo on the upload page and the client reminder, on Firm seats and during the trial. |
| Plans | 14-day trial with everything unlocked, no card. Then free with 1 open request at a time, or a Firm seat at €29 per month (€290 per year). Clients never pay and do not use a seat. |
| Encryption | Client-side, in the client's browser, to your firm's public keys. File names and the checklist are encrypted too. ShieldFive never holds the keys. |
Steps
- Unlock your vault, open Requests and choose Request documents.
Start from the Mortgage application packet template, or list the documents yourself, one per line. Add what your lender asks for beyond the standard packet, such as "Bank statements, all pages" or "Letter explaining large deposit". End a line with "(optional)" to mark it optional.
Set a PIN and an expiry that covers your closing timeline. Add the borrower's email if you want ShieldFive to remind them.
Select Create secure link. Send the link by email or text, and give the PIN another way, such as on the phone.
The borrower uploads a PDF or a phone photo into each slot. They can send what they have today and come back to the same link when the next statement or pay stub arrives.
When you are emailed that something arrived, open Requests and use Download & decrypt. If the underwriter asks for one more document, raise the file limit on the live request with Raise the file limit or send a new request. Revoke the link once the file is complete; received files stay in your vault.
Compared with email, file-sharing links and client portals
| Email attachments | Generic file request (Dropbox, OneDrive) | Client portal | ShieldFive document request | |
|---|---|---|---|---|
| Client needs an account? | No | No | Usually a login; some portals also accept uploads by link | No. A link and a PIN |
| List of what you need | In the email text | One upload box per request | Varies by portal | One upload slot per document, required or optional |
| Who can read stored files | Both mail providers, and anyone with mailbox access | The provider can decrypt by default | Usually the vendor holds the keys | Only your firm. ShieldFive stores ciphertext |
| Turn it off | Cannot recall a sent attachment | Close the request | Remove access | Revoke the link, or let it expire |
| Also does billing, e-signature, workflow | No | No | Usually yes | No. It only collects documents |
Limits
ShieldFive does not send the link for you. Part of the decryption key is in the
#fragment of the link and never reaches our servers, so you send the link yourself, and it has to arrive complete. The client-reminder email cannot contain the link for the same reason.It collects documents. It does not verify income or assets, pull credit, or connect to a loan origination system.
Clients choose files, not folders. The page has to stay open while files encrypt and upload.
Nothing identifies the uploader automatically. If you need to be certain who sent a document, confirm it with the client through a channel you already trust.
The upload page is code ShieldFive serves, so the client trusts that code at the moment of upload, as with every browser-based encryption product.
Full details of every limit are in Requesting documents from a client. For what the CFPB packet contains and why email is a poor channel for it, see How mortgage brokers can collect bank statements and pay stubs securely, and for the list itself, the mortgage application checklist.