Request files from clients. They never sign up.
Send one link with a checklist. Your client uploads with no account, and every file is sealed to your keys in their browser — so we store only ciphertext, never a readable copy.
14-day trial, no limit · then free for 1 open request at a time · no card · clients never pay
ShieldFive File Request at a glance
| What it does | A firm sends a client one link with a checklist of the documents it needs; the client uploads them from a phone or computer. |
|---|---|
| What the client needs | A current browser, the link and the PIN. No account, no sign-in, no app, no plugin. |
| Encryption | Each file and its name are encrypted in the client’s browser to the firm’s keys (ML-KEM-1024 with X25519, XChaCha20-Poly1305). We store only ciphertext and never hold your keys. |
| PIN | Required, at least 4 characters, sent separately. Wrong guesses slow the link down and then lock it. |
| File size | Up to 5 GB per file; about 2 GB per request by default. |
| Files per request | 25 by default, adjustable from 1 to 100. Any file type. |
| Link expiry | Up to 7 days on the free plan; 7, 30 or 90 days, or none, on the Firm plan and during the trial. |
| Notifications | The firm is emailed when something arrives. On the Firm plan, if you add the client’s email, they get up to two reminders while required items are missing. |
| Price | 14-day trial with everything unlocked, no card. Then free for 1 open request at a time, or €29 per seat per month (€290 per year). Clients never pay. |
| Hosting | EU, with a data-processing agreement on every seat. |
How it works
Create a request
Add a title, a checklist of the documents you need, and an optional message. You get one shareable link.
Your client uploads — no account
They open the link, see the checklist, and drag files in. Each file is sealed to your keys in their browser before it uploads. No signup, no app.
You decrypt in your browser
Received files appear in your inbox as ciphertext. You unlock and decrypt them locally — we never hold a key or a readable copy.
Sealed to you, ciphertext to us
Every upload is encrypted on the client’s device to your public key. We store only ciphertext of the documents, their names, and your checklist, and never hold your keys.
Post-quantum by default
Files are sealed with a hybrid of ML-KEM-1024 and X25519 via the open-source @shieldfive/crypto core — on for every request, not a paid add-on.
EU-hosted, DPA on every seat
Ciphertext and metadata live in the EU, and a GDPR data-processing agreement is included on every seat — not gated behind an enterprise call.
Built for the people who collect documents
Anyone who asks clients for paperwork — and can’t afford a readable copy sitting on someone else’s servers.
Document checklists
What a client supplies for a common filing, transcribed from the issuing authority’s own page. Each one opens in the composer as a template.
How it compares
The difference is always the same: with the tools below, the host can read your intake. Here, only you can.
Guides
Free to start
For the first 14 days everything is unlocked. After that the free plan allows 1 open request at a time, links that last up to 7 days and no automatic client reminders, with no card. For unlimited open requests, client reminders, your logo, links up to 90 days or with no expiry — and one shared inbox when teammates join — the Firm plan is €29 per seat per month (€290 per seat per year). The firm’s decryption identity is sealed to each member, so colleagues share one inbox without sharing personal keys. Your clients never pay.
Questions
- Do my clients need an account?
- No. Your client opens the link, sees the checklist, and uploads — no account, no password, no app. Only you need a free ShieldFive account, because files are sealed to your keys.
- Can ShieldFive read the documents?
- No. Each file is sealed to your public key in the client’s browser (a hybrid of ML-KEM-1024 and X25519). We store only ciphertext; you decrypt in your own browser. The honest limit: like any web app we serve the JavaScript, so the property is “encrypted in the browser, ciphertext at rest”, not a claim that no server could ever be subverted.
- How much does it cost?
- 14 days with everything unlocked, then free for 1 open request at a time, with links that last up to 7 days and no automatic client reminders. No card. The Firm plan is €29 per seat per month (€290 per year) for unlimited open requests, automatic client reminders, your logo, and links that stay open up to 90 days or with no expiry, plus a shared inbox when teammates join. Your clients never pay and never sign up.
- Is it GDPR-friendly?
- Ciphertext and metadata are stored in the EU, and a data-processing agreement is included on every seat. Because the documents are encrypted to your keys before upload, we process only ciphertext and never hold your keys.
- Can my whole team share one inbox?
- Yes. Add seats and the firm’s decryption identity is sealed to each member’s account, so colleagues share one inbox without ever sharing personal keys.
Step-by-step, with the limits, the PIN and what your client sees: Requesting documents from a client