Collect client and case documents without a readable copy in the cloud
Privileged material — client IDs, contracts, evidence, discovery — is exactly the intake you can’t route through a generic upload tool that keeps a readable copy. Email attachments and consumer file-senders both leave plaintext on someone else’s servers.
ShieldFive File Request lets a client or opposing party upload against a checklist with no account, sealing each file to your firm’s keys in their browser. The documents exist only as ciphertext until a lawyer at your firm opens the inbox and decrypts them locally.
One fewer party holding a readable copy
Evidence and client papers are sealed to your firm’s public key on the uploader’s device. The vendor holding them has only ciphertext and never the keys — which shortens any conversation about who has had access to privileged material.
Works for people outside your systems
Clients, witnesses, and opposing counsel’s office all open the same kind of link: a checklist, a PIN, drag and drop. No account to create, no portal credentials to reset the night before a filing.
EU residency, in writing
Ciphertext and encrypted metadata stay in the EU under EU jurisdiction, with a GDPR data-processing agreement on every seat — a concrete answer when a client’s engagement terms specify where their material may sit.
A link you can retire
Each request requires a PIN and carries file and size caps, with per-link and per-IP rate limits behind it. Set it to expire, or revoke it when the intake for a matter is done, and the link stops being a way in rather than lingering in an inbox indefinitely.
Start collecting documents securely
Create a request, share one link, and your clients upload without an account — each file sealed to your keys in their browser.
Start collecting — free14-day trial, everything unlocked · then free for 1 open request at a time · no card · clients never pay
Questions
- Is this safe for privileged or confidential material?
- The files and their names are sealed to your firm’s keys on the uploader’s device and stored only as ciphertext in the EU. We never hold your firm’s keys. Each link is PIN-gated and capped, and can be set to expire or revoked. The honest limit: like any web app, we serve the JavaScript, so the guarantee is “encrypted in the browser, ciphertext at rest”, not a claim that no server could ever be subverted.
- Can several people at the firm access the same intake?
- Yes. Add seats and the firm’s decryption identity is sealed to each member’s account, so the whole practice shares one inbox without sharing personal keys.
- What happens when a lawyer leaves the firm?
- Removing a member deletes their wrapped key, so they lose access from any new device or session. Someone who had already unlocked and cached the firm key keeps access to documents received before the removal until you rotate the firm key, which re-wraps a new key to the remaining members for future requests. Rotation does not re-encrypt what was already collected.