The short answer
Accountant file sharing has two jobs: getting tax documents in from clients, and sending finished returns and statements back. There is no single best tool for both. The right one depends on which axis your firm optimizes for, and the two axes pull in different directions. If you need deep US tax-workflow fit, native Lacerte, UltraTax, Drake or CCH Axcess integration, IRS Form 8879 e-signature with KBA, document-request lists, and an established SOC 2 / ISO 27001 vendor, then SmartVault, Citrix ShareFile, TaxDome, or Suralink lead, and ShieldFive does not match that surface area. If you mainly need clients to send you files without creating an account, ShieldFive does that job: files are encrypted in the client’s browser before upload, and ShieldFive stores only ciphertext and never holds the keys.
This is a buyer comparison, not a self-pitch. ShieldFive appears here as one entry among several, positioned honestly on the encryption-and-jurisdiction axis. Where the workflow tools are stronger, the page says so plainly.
If what you need is narrower, a safe way for clients to send you their documents rather than a full practice portal, secure file sharing for accountants compares upload links, shared drives and client portals on client effort, who can read the files and cost. For moving files in both directions, including sending a completed return back, see CPA secure file transfer.
What CPA firms should actually require
The marketing pages for secure file sharing tools list dozens of features. For an accounting firm the list that matters is short, and it splits into two groups that rarely come in one product.
The confidentiality controls, these decide who can read client data if something goes wrong:
- Encryption model and key custody. Is content encrypted in transit and at rest (table stakes), and crucially, who holds the keys? If the provider holds them, the provider can decrypt, by choice, by breach, or by legal compulsion. Zero-knowledge (client-side) encryption is the only model where the provider mathematically cannot read content.
- Per-document key isolation and audit trail. A separate key per file so one compromised passphrase does not cascade, plus a log of every access, expiry, and revocation.
- Data residency and jurisdiction. Where the bytes physically sit, and which legal regime governs them. For EU clients or EU-based firms, US-hosting under Standard Contractual Clauses is a different answer than EU residency.
The workflow controls, these decide how much of your practice runs inside the tool:
- Tax-software integration. Native two-way connectors to Lacerte, ProSeries, ProConnect, UltraTax CS, Drake, or CCH Axcess that auto-file returns into client folders.
- PBC / document-request workflow. Templated, trackable provided-by-client request lists, ideally with rollforward from the prior year.
- E-signature with KBA. IRS Form 8879 signing with Knowledge-Based Authentication built in.
- Branded client portal, invoicing, CRM. The rest of practice management.
Almost no product is best at both groups. The encryption-first tools are thin on tax workflow; the tax-workflow suites are provider-decryptable. Deciding which group is non-negotiable for your firm is the whole comparison.
What the rules behind those controls actually say
That control list is not a matter of taste. It is what several overlapping obligations converge on, and which one applies to a given client changes what you are allowed to accept from a vendor.
- The FTC Safeguards Rule (GLBA). Since June 2023 the Rule has treated tax and accounting firms as financial institutions. It requires a written information security program plus encryption of customer information in transit over external networks and at rest, where feasible (16 CFR §314.4(c)(3)). For client file exchange, encryption is plainly feasible, so it is expected rather than optional.
- GDPR. Any client file carrying personal data of an EU individual pulls storage location, transfer mechanism, and processor terms into scope. This is where the residency row of the table below stops being a nice-to-have: US hosting under Standard Contractual Clauses is a defensible answer, but it is a different answer from EU residency under EU jurisdiction, and the vendor's DPA has to say which one you actually bought.
- Professional confidentiality. AICPA, ICAEW, and equivalent bodies impose a duty of confidentiality that sits on top of statutory requirements and does not lapse because a vendor's terms grant it access. A provider that can read client files is, in practice, a party you have given access to.
- State data-security law. Several US states impose encryption obligations on the data type itself, notably Massachusetts 201 CMR 17.00 and the New York SHIELD Act, and most state CPA boards now treat unencrypted email transmission of tax documents as substandard practice. That is the practical answer to whether you can send a return or a W-2 as an attachment: you can, and the regulatory exposure becomes yours the moment it leaves your outbox.
- SOC 2 alignment. Not a law, but increasingly a gate. Enterprise clients ask for it during vendor review, which is why the certification row below matters commercially even though it says nothing about who holds the keys.
None of these frameworks names a product. They specify outcomes: that sensitive data is controlled, that access is logged, and that you can demonstrate both. That last word is what turns the audit trail from a convenience into a compliance artifact. A workable minimum is sender, recipient, timestamp, access events (view and download), expiry status, and revocation events, tamper-evident and retained for at least the engagement retention period your firm policy sets, commonly seven years for tax workpapers under IRS retention guidance.
For the requirement-by-requirement map of the Safeguards Rule and IRS Pub 4557, see the FTC Safeguards Rule guide. None of this is legal advice; confirm how each obligation applies to your firm with your own counsel.
The two options most firms are really comparing against
Before the shortlist, the honest baseline. Most firms are not choosing between SmartVault and Suralink. They are choosing between what they do today and anything better, and what they do today is an email attachment or a consumer cloud drive. Both fail the list above in specific, predictable ways.
Email attachments are still the dominant transfer method in accounting because they are fast and familiar, and they are completely uncontrolled after delivery. Once sent, an attachment can be forwarded to anyone and saved anywhere, and there is no revocation mechanism. Breaches in professional services are rarely dramatic infrastructure failures; they are quiet, a link forwarded once too often, a shared folder with no expiry, a departed staff member's laptop still holding a year of engagement files.
Consumer cloud storage fixes the delivery problem and introduces a different one: the provider has full access to file content. That access can be used for scanning, threat analysis, or model training, and it can be compelled by legal process. Business tiers add admin controls and better logging, which narrows the operational risk, but they do not change key custody. The encryption architecture is the line that does not move.
| Control | Email attachment | Consumer cloud drive | A zero-knowledge platform |
|---|---|---|---|
| Client-side / zero-knowledge encryption | None; TLS in transit at best | Provider holds the keys and can read content | Files encrypted on the device before upload |
| Per-document key isolation | None | Shared account-level access | A separate key per file |
| Link expiry + revocation | None; uncontrollable once sent | Basic link controls, varies by plan | Expiry, download caps, revoke at any time |
| Channel separation / audit trail | None | Partial; logging varies by plan | Link and passphrase separable, access logged |
| Data residency | Wherever the mail providers sit | Often US by default | Determined by the provider, not by your plan tier |
Cells reflect each option's typical default. Business-tier Drive and Dropbox plans narrow some of the operational gaps but do not change provider key custody.
Every product in the comparison below clears the email bar. The rest of this page is about which of them clears the rest.
Secure file sharing for accountants, compared
The table ranks the named tools on the controls above. It is deliberately honest in both directions: the workflow suites win the integration columns, and they lose the encryption-model column. ShieldFive is the inverse. Read the per-tool notes below the table, they carry the caveats a single cell cannot.
| Capability | ShieldFive | SmartVault | Citrix ShareFile | TaxDome | Suralink |
|---|---|---|---|---|---|
| Encryption / key custody | Client-side encryption; client-code trust | Provider-managed AES-256; decryptable | Provider-managed AES-256; CMEK add-on, still server-side | Provider-managed AES-256; decryptable | Provider-managed AES-256; decryptable |
| Post-quantum | Hybrid default on web and Android, AES-GCM fallback | No | No | No | No |
| Audit trail / access log | Yes | Yes | Yes | Yes | Yes (by username + IP) |
| Tax-software integration | None | Native two-way: Lacerte/ProSeries/ProConnect/UltraTax/Drake/CCH Axcess | File-transfer: CCH/Drake/Lacerte/ProSeries/UltraTax | Drake/Lacerte/ProConnect/UltraTax | Excel-native workpaper add-in; no named tax-prep connectors |
| PBC / document-request workflow | No | Yes (incl. AI request lists) | Yes (templated) | Yes (Organizers) | Yes, dynamic request list is the core product |
| E-signature + KBA (Form 8879) | No | Yes | Yes | Yes (KBA ~$1 each) | Yes (flat-priced) |
| Named third-party certifications | None yet; open code + published internal review | SOC 2 Type 2, ISO 27001, ISO 22301 | SOC 2 Type 2, ISO 27001, ISO 27701 | SOC 2 Type I completed (Apr 2024); Type II claimed, ~May 2026; ISO 27001 AWS-level only | SOC 2 (confirm report scope) |
| EU data residency | Yes, stored in the EU, EU jurisdiction | No EU residency option found; US-hosted | EU zones on request (e.g. Dublin, Frankfurt); US-parent jurisdiction | Ambiguous; US processing contemplated | EU data center exists; US transfer possible under SCCs |
| Indicative price | Free 5 GB; paid from EUR 6/mo (1 TB); Shield+ 2 TB EUR 10/mo | From $65/user/mo (Accounting Pro, annual; $85 monthly) | From $16.50/user/mo (Advanced, annual; 3-user min) | From $800-$1,200/user/yr | Quote-based |
Cells reflect each vendor's public documentation as of 2026-06-29 and are updated as products change. "Provider-managed" means the vendor holds the keys and can technically decrypt content; it is an access-control and policy assurance, not a cryptographic one. Indicative prices change frequently, confirm on each vendor's plans page.
ShieldFive's own plans are a free 5 GB tier with no card, paid from EUR 6/mo (1 TB), and Shield+ 2 TB at EUR 10/mo, all on the pricing page.
Where each tool leads, honestly
A comparison that only flatters one product is not useful. Here is where each named tool is genuinely the stronger choice, and where it is not.
SmartVault
SmartVault leads on accounting-industry fit and procurement safety. It offers native two-way integrations with Lacerte, ProSeries, ProConnect, UltraTax CS, Drake, and CCH Axcess that auto-file returns into pre-organized client folders, AI-assisted document-request lists (SmartRequest), integrated 8879 e-signature with KBA, SmartProposal billing, and a polished firm-branded portal. As a long-established, GetBusy-backed vendor with SOC 2 Type 2, ISO 27001:2022, and ISO 22301, it reads to buyers as low procurement risk.
Where it does not lead: it is not zero-knowledge. SmartVault encrypts at rest with AES-256 but holds the keys; its "employees cannot access without permission" line is a policy control, not cryptography, so it can technically decrypt your and your clients' documents. It is US-hosted on AWS with no published EU data-residency option, and EU/UK customer data is transferred to the US under Standard Contractual Clauses. For a firm whose requirement is provider-cannot-read or EU jurisdiction, that is the gap. HIPAA and PCI are stated as support and alignment, not the same as the named SOC 2 / ISO certificates, request the actual reports under NDA.
Citrix ShareFile (Progress ShareFile)
ShareFile leads on workflow depth and regional flexibility. It has templated PBC document-request lists, IRS-compliant KBA e-signature for Form 8879 at no extra cost, tax-software file-transfer integrations (CCH, Drake, Lacerte, ProSeries, UltraTax), a dedicated income-tax-return workflow, a branded portal, and a broad set of storage zones including EU options (Dublin, Frankfurt) alongside US and others. Its compliance posture (SOC 2 Type 2, ISO 27001, ISO 27701, HIPAA option) is mature.
Where it does not lead: by default ShareFile holds the keys and decrypts server-side, downloaded files are decrypted before reaching the browser, so it is provider-decryptable, not end-to-end. Its Customer-Managed Encryption Keys option (a dual-key model via AWS KMS) moves master-key control to the customer and lets you revoke ShareFile's access, but it is still server-side encryption, not client-side zero-knowledge, and it is not available for HIPAA accounts. As a US-parent company (Progress Software, US), US legal jurisdiction applies regardless of which storage zone you pick, and non-default EU-only storage generally requires a support request.
TaxDome
TaxDome leads on breadth. It is the most consolidated practice-management suite here: CRM, pipelines and automation, secure document management, IRS-compliant e-sign with cheap KBA (~$1 each), invoicing and payments, client Organizers, and a white-label portal plus branded mobile app, with native integrations to Drake, Lacerte, ProConnect, and UltraTax. For a firm that wants one system to run the whole practice, that surface area outclasses any single-purpose file-sharing tool, ShieldFive included.
Where it does not lead: the security model is provider-decryptable. TaxDome encrypts at rest with AES-256 via AWS KMS but, in its own wording, the keys are "controlled by TaxDome", so it is not zero-knowledge: despite TaxDome's "bank-level, end-to-end encryption" marketing language, TaxDome (or anyone reaching the keys via legal process, insider access, or breach) can in principle read document contents. TaxDome completed a SOC 2 Type I audit reported in April 2024, and its own materials describe a subsequent SOC 2 Type II certification, audited via Strike Graph, with a page date indicating roughly May 2026 — confirm current report scope and completion status directly with TaxDome. ISO 27001 appears to be at the AWS-datacenter level rather than a TaxDome-held certification, so do not assume TaxDome itself is ISO 27001 certified. EU residency is ambiguous in its published docs (US processing is contemplated; SCC-based transfers), and the SOC 2 report is NDA-gated. Pricing is per-seat, billed annually upfront.
Suralink
Suralink leads on the PBC request-list workflow specifically. Its dynamic, real-time request list tightly coupled to a secure portal is the product's core, with reusable templates, rollforward, audit trails by username and IP, integrated KBA e-signature (flat-priced, not per-envelope), an Excel-native workpaper suite that works alongside Caseware and CCH/Thomson Reuters engagement tools, 50+ API endpoints, SSO, and a branded portal. For audit and tax engagements built around document requests, it is purpose-built and well-adopted. It also already offers regional data centers, including an EU data-center option and Canada, on SOC 2-compliant infrastructure.
Where it does not lead: encryption is provider-managed server-side AES-256 with no published customer-held-key, BYOK, client-side, or zero-knowledge option, so it is provider-decryptable. EU residency exists but its privacy policy still permits processing EU personal data in the US under SCCs, so confirm strict EU-only processing in writing if you need it. Its integration model is the Excel workpaper add-in and APIs rather than named tax-prep connectors (no direct UltraTax/Lacerte/Drake filing integration found), and pricing is quote-based. Confirm the current SOC 2 report scope and the present list of supported regions directly.
Sharing files alongside your tax software
ShieldFive does not integrate with any tax-preparation software. There is no plugin, no auto-filing, and no two-way sync; it sits beside whatever you already use. The workflow is the same for every product: export the return or source document from your tax software, encrypt it in the browser with ShieldFive, and send the client a link with an expiry and revocation. That wraps a provider-cannot-read layer around the file without changing how you prepare the return.
UltraTax CS
ShieldFive does not connect to UltraTax CS. Export the return or PDF from UltraTax, encrypt it in ShieldFive, and share an expiring link. The confidentiality layer is added at the sharing step, not inside UltraTax.
Lacerte
ShieldFive has no Lacerte integration. Print or export the Lacerte return to PDF, encrypt it client-side in ShieldFive, and send an expiring, revocable link instead of an email attachment.
ProSeries
ShieldFive does not integrate with ProSeries. Export the ProSeries document, encrypt it in the browser, and share it with an expiry so the file stays provider-unreadable in transit and at rest.
ProConnect Tax
ShieldFive has no ProConnect connector. Download the return or client document from ProConnect, encrypt it in ShieldFive, and share a link you can revoke once the client has retrieved it.
CCH Axcess
ShieldFive does not integrate with CCH Axcess. Export the document from CCH Axcess, encrypt it client-side, and send an expiring ShieldFive link for the highest-sensitivity files.
TaxDome
TaxDome is a full practice-management portal and is provider-decryptable; its keys are controlled by TaxDome, per its own documentation, so ShieldFive does not replace it. Firms considering ShieldFive alongside TaxDome should assess its client-code trust boundary and workflow limits before moving client files.
If what you actually want is a client portal
"Client portal" has become a category placeholder in accounting software marketing. In practice it usually means a vendor-hosted folder where clients can drop files behind a login screen. What it rarely means is per-document access control, encryption the vendor cannot bypass, or credentials that travel separately from content. The distance between those two definitions is where most portal disappointment comes from.
It helps to separate the two jobs, because most firms end up running both. Secure file sharing is the transfer primitive: an encrypted upload, a link with an expiry and a revoke, and an access log for a single document handoff. A portal is a persistent workspace, folder structure, document-request flows, and message threads that hold engagement state over time. A portal without client-side encryption still leaves the provider able to read what is stored, so the key-custody question from the table applies to both layers, not just to the transfer.
Where basic portals break down
Firms that adopt a basic portal tend to hit the same three frictions within about six months.
Clients don't use it consistently. When a client can forward a file by email in ten seconds but has to log into a portal to do the same thing in thirty, email wins. The portal quietly becomes an internal folder while clients revert to attachments.
Permissions age badly. A portal configured around one engagement accumulates stale access as the relationship changes. Access granted during year-one onboarding often no longer matches the current engagement scope, and nobody is scheduled to notice.
Audit trails are thinner than they look. Many portals record that a file was uploaded. Fewer record every external access with timestamp, IP, and download confirmation. The difference only becomes visible when a client disputes document receipt during a regulatory inquiry, which is the one moment you cannot fix it retroactively.
What to require in a client portal
- Encryption before upload. The portal should encrypt on the device, so the vendor cannot read client file contents at all. For a firm under a confidentiality duty, provider-side key access is a governance question, not a preference.
- Per-document controls, not folder defaults. Expiry, download limit, and revocation set on the individual file that was shared, rather than inherited from whatever the folder allows.
- Passphrase on a separate channel. The access link and its passphrase should travel independently. Sending both in one email removes a layer you thought you had.
- Complete, exportable access logs. Timestamp, actor identity, file accessed, action type (view, download, upload, share, revoke), originating IP, and the engagement the file belongs to, tamper-evident and exportable in a form that survives an inquiry.
Four questions settle fitness faster than any feature grid:
- Does the platform have access to file plaintext at any point?
- Can you revoke a single link after delivery, instantly, without disturbing other access?
- Can you export a timestamped log of every external access in the last 90 days?
- Are those controls available per link, or only per folder?
Most traditional portals fail at least two of the four. Of the tools above, SmartVault, ShareFile, TaxDome, and Suralink answer the last three well and fail the first by design, because they hold the keys. ShieldFive has the client-code trust limitation described below; its audit coverage is also incomplete: share access is recorded server-side, but it is not yet self-serve exportable by the account owner.
The underlying question is not whether a controlled portal is worth the switching cost. It is whether the firm could demonstrate, in an examination or a client dispute, that it kept appropriate control over client files. A mail thread with an attachment history is not that demonstration.
Where ShieldFive fits, and where it does not
ShieldFive is a client-side encrypted option with a client-code trust boundary that must be considered alongside its workflow limits.
What it is. ShieldFive provides client-side encrypted file storage, sharing and document collection. Files are encrypted on the device before upload and encrypted file data is stored in the EU. Your password never reaches our servers: the browser turns it into a separate login value with Argon2id and sends only that, and the key that opens the vault is derived separately and stays on the device. The app code is delivered by us, so the client you are served on each visit remains part of the trust boundary. This is not an absolute provider-cannot-decrypt guarantee. Web uploads default to ML-KEM-1024/XChaCha20-Poly1305 with AES-GCM fallback; Android also defaults to the hybrid format, with the same AES-GCM fallback, and reads both formats. The crypto core is open source, but the apps are not fully open source and no external security audit has been completed.
Where it does not fit. ShieldFive is encryption-first secure file sharing, not a full practice-management portal, and it would be dishonest to pretend otherwise. It has no tax-software integrations, no Lacerte, UltraTax, Drake, ProConnect, or QuickBooks connectors. It has no PBC / document-request-list workflow, no built-in e-signature or KBA for Form 8879, no invoicing, no CRM. If those workflow features are what you are shopping for, SmartVault, ShareFile, TaxDome, or Suralink are the right tools and ShieldFive is not. Two more limits stated plainly: ShieldFive has no completed third-party security audit yet, one is planned, and its review evidence today is open code and a published internal security review, not a SOC 2, ISO 27001, or any certification. And there is no US HIPAA Business Associate Agreement; ShieldFive provides encryption, access control, and audit primitives, not a turnkey HIPAA solution, so accounting work touching ePHI still needs a HIPAA-specific arrangement.
For a head-to-head against a single incumbent, see ShieldFive vs ShareFile and ShieldFive vs Content Snare; for the compliance framing on its own, the FTC Safeguards Rule guide and the GDPR file-sharing checklist; and for how the major zero-knowledge providers compare beyond the accounting niche. And if the job you are actually hiring a tool for is to collect documents from clients each filing season, the firm workflow page walks through how the request-and-upload flow works.
Which one fits your firm
The decision comes down to which group of controls is non-negotiable.
Pick a workflow suite (SmartVault, ShareFile, TaxDome, or Suralink) if your firm is US-based, runs returns through Lacerte / UltraTax / Drake / ProConnect / CCH Axcess, needs IRS 8879 e-signature with KBA and a templated document-request workflow, and a named SOC 2 / ISO certification is required during your clients' vendor review. Among these, choose Suralink if the PBC request list for audit engagements is the center of gravity, TaxDome if you want one system for the entire practice including CRM and billing, and SmartVault or ShareFile if you want a branded portal with strong tax-software auto-filing. Accept that all four are provider-decryptable and weigh whether that meets your confidentiality and jurisdiction requirements.
Consider ShieldFive if client-side encryption, EU ciphertext storage and its sharing workflow fit your requirements. Review its client-code trust boundary, client-specific encryption formats and lack of an external audit before using it for client documents. Test with disposable files and retain independent backups.
For most firms the realistic pattern is a hybrid: a workflow tool for engagement management, with zero-knowledge file sharing underneath for the highest-liability documents, M&A due diligence, audit workpapers, the client with explicit data-handling clauses. The encryption question applies to both layers, because a portal that holds the keys still leaves the provider able to read what is stored.
Whatever you shortlist, verify the two claims that matter against each vendor's live documentation before you sign: who holds the keys, and where the data legally sits. Those two answers, not the feature grid, are what your clients are trusting you to get right.
Rolling out whichever one you pick
The tool matters less than the discipline around it, and the rollout that works is narrow before it is wide.
Start with the single highest-sensitivity engagement type in your portfolio: M&A due diligence, an audit with contested workpapers, or the client whose engagement letter carries explicit data-handling clauses. Configure the new workflow there, validate it with three to five clients, then standardize across all client-facing document delivery. The transition cost is behavioral rather than technical; clients adapt once the new route is reliable and the old one stops being offered.
A short standing checklist keeps it from decaying back into attachments:
- Name the file categories that always require encrypted sharing: tax returns, financial statements, audit workpapers, payroll records.
- Set a firm-wide default expiry on every external link, so no share is an open-ended access grant.
- Write down the passphrase policy: never reused, never sent in the same message as the link.
- Give one person ownership of reviewing active shares on a monthly cadence.
- If your tool offers a country allowlist on share links, treat it as one access-control layer, bypassable over a VPN, not a residency guarantee, and pair it with expiry and a share password.
Four numbers tell you whether the policy is real rather than written: the share of external client shares carrying an active expiry and download cap; time to revocation when an engagement closes or a relationship ends; the number of links found forwarded outside the intended recipient scope; and whether you could produce a log of every external access within 24 hours if a client asked today.
This comparison reflects each vendor's public documentation as of 2026-06-29 and will be updated as the products change. Competitor facts are drawn from each vendor's own security, compliance, and pricing pages; confirm current report scope, regions, and prices directly with the vendor before a buying decision.