Solutions · Updated

Secure Document Collection for Immigration Lawyers (2026)

Compare immigration document-collection workflows, case-management features, storage locations and audit evidence. Review ShieldFive’s client-code trust boundary before using client documents.

An immigration case runs on documents the client holds and the firm needs: passports and biographic pages, I-797 receipt and approval notices, the financial evidence behind an I-864 Affidavit of Support, birth and marriage certificates, and — on a hard USCIS clock — the evidence packet answering a Request for Evidence. Collecting those files is where most firms lose time and, occasionally, control of the data: they arrive by email, by WhatsApp photo, and on paper, from a client who is often filing in a second language on a phone and unwilling to create yet another account. This page compares the tools that solve that collection problem, and it separates them on one axis that matters more for immigration than for almost any other practice area: whether the vendor holding the files can read them.

This is a buyer comparison, not a self-pitch. ShieldFive appears as one entry among tools with far longer track records in this market, several of which do the entire immigration workflow ShieldFive does not touch. Where they lead, the page says so plainly. ShieldFive's own immigration document-collection page is the marketing version of its pitch; this is the honest version, with the gaps named. If what you actually need is a full practice-management suite, the last section says so and points you at one.

What "document collection" means for an immigration firm

The job is narrow to describe and hard to do well. You need a specific set of documents from a specific client, you need them before a filing deadline, and you need to know at a glance what is still missing. The failure modes are familiar to anyone who has run an immigration caseload: the client emails four of the six documents and forgets the rest; the passport photo arrives as a blurry WhatsApp image; the RFE response is due in a week and the tax transcripts still are not in. Underneath the logistics sits a confidentiality problem that is sharper here than in accounting or general legal work. These are the documents that decide whether a person can stay in the country. A leaked passport plus an I-797 is a near-complete identity kit, and the client rarely has the option to shrug off the exposure.

Two constraints follow from that, and they shape which tool fits:

  • The client is the hardest kind of portal user. Often filing in a second language, frequently mobile-only, and reasonably reluctant to create an account and remember a password for a one-time upload. Any tool that gates the upload behind a signup loses documents.
  • The data is cross-border by nature. Immigration files move between countries as a matter of course, which turns "where does this data physically live, and who has jurisdiction over it" from a compliance checkbox into a real question a client may ask.

Two kinds of tool solve this

The market splits cleanly, and confusing the two halves is the most common mistake in tool selection here.

Immigration case-management suites — Docketwise, eImmigration (Cerenade), INSZoom (Mitratech), LollyLaw — bundle document collection into a much larger system: auto-filled USCIS forms, e-filing, questionnaires, priority-date and case-status tracking, invoicing. The client portal is one feature of many. If your practice needs the whole workflow in one login, this is the category to shop, and document collection comes along for the ride.

Dedicated collection and encryption tools — Content Snare, FileInvite, and ShieldFive — do the collection channel and little else. Content Snare and FileInvite specialize in the chase: templates, reminder automation, dashboards. ShieldFive offers client-side encrypted document requests, subject to the client-code trust boundary explained below. None of these three is a case-management system, and none pretends to file a form.

The honest framing is that the suites do dramatically more than ShieldFive does. The reason to consider a dedicated tool at all is that the suite's portal, like nearly every portal in this space, uses provider-managed encryption — the vendor's own infrastructure holds the keys and can decrypt what a client uploads.

The comparison

CapabilityShieldFiveContent SnareDocketwiseeImmigrationINSZoomLollyLawClioFileInvite
Primary roleClient-side encrypted document requestsDocument collection + onboardingImmigration case managementImmigration case managementImmigration case managementImmigration case managementGeneral legal practice + portalGeneral document collection
Encryption / key custodyClient-side encryption with client-code trustProvider-managed AES at restProvider-managed AES-256 at rest, TLS in transitProvider-managedProvider-managedProvider-managedProvider-managed ("256-bit SSL/TLS")Provider-managed AES-256, TLS 1.2+
Zero-knowledge / client-side encryption claimed?Client-side encryption; no absolute provider-inaccessible guaranteeNoNoNoNoNoNoNo
Post-quantum encryptionHybrid default on web and Android, AES-GCM fallbackNot documentedNot documentedNot documentedNot documentedNot documentedNot documentedNot documented
Client upload without an accountYes — PIN-gated link, no signupYes — PIN-gated portalPortal loginPortal loginPortal loginPortal loginPortal login (biometric on mobile)Yes — client portal
USCIS forms / e-filingNoNoYes — 300+ forms, Smart FormsYes — 300+ forms, e-filingYesYesNoNo
Reminder automationLimited — Firm seats: at most two client reminders (day ~3 and ~7); none on freeYes — rules-based engineYesYesYesYesMessaging/notificationsYes
Named certification / auditNone yet — open crypto core + published internal reviewISO 27001 (parent Aktura Technology)SOC 2 Type 2 (at parent 8am level)Not publishedNot publishedNot publishedProvider-managed; no ZK claimSOC 2 Type II
Data residency / DPAEU — DB Frankfurt, files Amsterdam, DPA published + per seatAWS; Australian company; region not publishedAWS (US)Not publishedNot published (enterprise skew)Not publishedUS / global (AWS)US / general
Indicative price14 days with everything unlocked, then free (5 GB, 1 open request at a time, links up to 7 days, no card); seats €29/seat/mo or €290/seat/yr for unlimited~$35/mo Basic (annual) → $215+/mo Custom~$69–$109/user/mo$55 / $70 / $85 per user/moQuote-based~$120/user/mo (unofficial)~$39–$139/user/moPro from $49/mo

Pricing and security wording for every competitor above change frequently and several vendors do not publish rates at all; confirm current terms on each vendor's own page before a buying decision. ShieldFive's own figures are drawn from constants/plans.ts in its open repository.

The documents that raise the bar

Immigration collection is not generic file transfer, and the reason is the specific document set. A typical family or employment case asks the client for some combination of:

  • Identity documents — passport biographic pages, national ID cards, prior visas and I-94 records.
  • USCIS correspondence — I-797 receipt and approval notices, the RFE or NOID letter itself.
  • Petition evidence — the supporting exhibits behind an I-130, I-140, or I-485: relationship evidence, employment letters, qualifying documents.
  • Financial evidence — for the I-864 Affidavit of Support: federal tax transcripts, W-2s, recent pay stubs, and bank statements, often for both the petitioner and a joint sponsor.
  • Civil documents — birth, marriage, and divorce certificates, police clearances, sometimes with certified translations.

Two things about this set change the confidentiality calculus. First, the combination is an identity dossier: passport, financials, and an approval notice together are more than enough to impersonate someone or reconstruct their immigration file. Second, an RFE response runs on a fixed USCIS deadline, so the collection channel has to be one the client will actually use on the first try — a portal they cannot log into is not a minor annoyance, it is a missed filing. That is the same "clients will not create an account" problem every collection tool has solved, but the cost of getting it wrong is higher here.

Where the case-management suites lead, honestly

If document collection is one part of a high-volume immigration practice, a suite almost certainly beats a dedicated channel, and it would be dishonest to suggest otherwise. Docketwise, eImmigration, INSZoom, and LollyLaw auto-fill the USCIS forms from the questionnaire data, track priority dates and case status, e-file where supported, and handle invoicing — the collected documents flow straight into the rest of the matter instead of sitting in a separate tool. Docketwise publishes a SOC 2 Type 2 attestation at its parent-company (8am) level; several of the suites integrate directly with cloud storage the firm already uses. Content Snare, on the dedicated side, leads on the actual chase: a rules-based reminder engine so no one manually follows up, 110-plus templates so a standard engagement does not start from a blank checklist, and a completed ISO 27001 certification under its parent Aktura Technology. FileInvite carries a completed SOC 2 Type II and adds virus scanning and MFA.

ShieldFive has none of this. No USCIS forms, no e-filing, no case tracking, no invoicing, no configurable reminder engine, no template library, no integrations, and no completed third-party audit. Measured as a practice-management system, it is not one and does not compete.

Where ShieldFive leads, honestly

ShieldFive's document requests inherit the architecture of the storage product underneath them: every file the client uploads is encrypted in their browser before it reaches ShieldFive's servers, so the server holds only ciphertext — a property of how the system is built, not a policy that could be changed or compelled away later. Since 17 May 2026, that encryption defaults to a hybrid post-quantum suite: ML-KEM-1024 (FIPS 203, NIST security level 5) combined with XChaCha20-Poly1305, so a break in either component alone does not expose the file. The request's title, the client label, and the item checklist are themselves encrypted, not just the files. Data sits in the EU — database in Frankfurt, files in Amsterdam — with the Article 28 DPA published and included on every seat, and outbound return links (when the firm sends documents back) carry an expiry, a download cap, and an allowed-countries restriction. The client uploads through a PIN-gated link with no account to create. A new firm gets 14 days with everything unlocked. After that, the free plan allows 1 open request at a time with 5 GB of storage and no card; links last up to 7 days and client reminders stop. Firm seats (€29 per seat per month or €290 per year, up to 500 seats) add unlimited open requests, automatic client reminders, your logo, links that stay open up to 90 days or with no expiry, and 100 GB of fair-use storage per seat that is not metered against the firm. Clients never pay or sign up.

The limits belong in the same paragraph as the claims. There are no USCIS forms and no e-filing. Reminder automation is minimal. The firm is notified when a client uploads. On Firm seats (and during the trial), if you add the client's email, ShieldFive reminds them at most twice, around day 3 and day 7; there is no configurable schedule, and the free plan sends no client reminders. There is no template library; a request's checklist is a free-text list the firm fills in each time. There are no integrations with case-management software. And ShieldFive has not completed a SOC 2, ISO 27001, or any third-party audit — its evidence today is an open-source crypto core anyone can read and a published internal security review, which is a different kind of assurance from a completed certification, not a substitute for one.

Client-code trust matters for sensitive documents

ShieldFive encrypts files on the device before upload and stores encrypted file data in the EU. Your password never reaches our servers: the browser turns it into a separate login value with Argon2id and sends only that, and the key that opens the vault is derived separately and stays on the device. That service remains part of the trust boundary, so ShieldFive cannot promise that provider decryption is technically impossible. An encrypted storage format alone does not establish that files are inaccessible to the provider. ShieldFive has no completed external security audit, and its crypto core is open source while its apps are not fully open source. Review these limits before considering it for client documents.

Do you need a portal, or a channel?

This is the decision most immigration firms are actually making, and the search term "client portal for immigration attorneys" hides it. A portal in the case-management sense is a client-facing front end to your whole practice: questionnaires, forms, case status, messaging, billing, all behind one login. If that is what you want, buy a suite — Docketwise, eImmigration, INSZoom, and LollyLaw exist to sell you exactly that, and ShieldFive is not a competitor for it.

A channel handles a specific document-transfer step. ShieldFive offers encrypted document collection alongside an existing case-management system, with no integration between them today. Evaluate its client-code trust boundary and workflow limits; do not select it on the assumption that the provider can never decrypt the documents.

Which one fits your firm

Pick a case-management suite (Docketwise, eImmigration, INSZoom, LollyLaw) if you want the whole immigration workflow — auto-filled USCIS forms, e-filing, case tracking, invoicing — in one system, and you are comfortable with provider-managed encryption on the client portal. This is the right answer for most high-volume practices.

Pick Content Snare or FileInvite if your binding need is the collection chase itself — templated checklists, automated reminders, a completed audit (ISO 27001 for Content Snare, SOC 2 Type II for FileInvite) — and you do not require that the vendor be unable to read the files.

Consider ShieldFive only if its client-side encryption, EU ciphertext storage, client-code trust model and current workflow fit your requirements. Test with disposable documents and keep independent backups before moving client files. The document-collection page describes the request workflow.

For adjacent comparisons on the same axes, see Content Snare vs ShieldFive for the dedicated-collection head-to-head, secure file sharing for law firms for the general legal case, and the accountant file-sharing comparison for the portal-versus-channel argument in a different profession. For how ShieldFive compares with other encrypted-storage tools, see ten zero-knowledge providers rated honestly.

Frequently asked questions

Is Docketwise, Clio, or eImmigration zero-knowledge or end-to-end encrypted?

Not according to their public documentation. Docketwise describes AES-256 encryption at rest and TLS in transit with a SOC 2 Type 2 attestation at its parent-company (8am) level; Clio describes "bank-level 256-bit SSL/TLS"; eImmigration describes secure provider-managed storage. All three are provider-managed encryption, where the vendor's own infrastructure holds the keys and can decrypt uploaded files. None of them claims zero-knowledge or client-side (browser) encryption anywhere in its published materials as of August 2026. That is a legitimate, common security model — it is simply a different guarantee from zero-knowledge, where the provider is architecturally unable to read the content.

Can immigration clients upload documents without creating an account?

With ShieldFive, yes — the client opens a PIN-gated link and uploads with no signup and no password to remember, which matters when the client is mobile-only or filing in a second language. Content Snare and FileInvite also offer no-login client portals. The immigration case-management suites (Docketwise, eImmigration, INSZoom, LollyLaw) generally route clients through a portal login instead, which is more friction for a one-time upload but comes bundled with the rest of the case workflow.

Where does the data live, and is there a DPA?

ShieldFive stores its database in Frankfurt and files in Amsterdam — both in the EU — and publishes an Article 28 DPA that is included on every seat rather than gated behind an enterprise call, which is a concrete answer for a firm with clients under EU data-residency terms. Most of the case-management suites are US-hosted (Docketwise on AWS in the US) or do not publish a specific hosting region; Content Snare is an Australian company hosting on AWS without a published region. If EU residency is a hard requirement, treat any tool that does not publish its region as unconfirmed rather than assuming either way.

Does ShieldFive handle USCIS forms or e-filing?

No. ShieldFive collects documents; it does not auto-fill I-130, I-485, I-140, or any USCIS form, and it does not e-file. If you need forms and filing, you need a case-management suite such as Docketwise, eImmigration, INSZoom, or LollyLaw. ShieldFive is a collection channel that can run alongside one of those, subject to the client-code trust boundary described above.

What does ShieldFive cost compared with the case-management suites?

ShieldFive gives a new firm 14 days with everything unlocked, then is free with 1 open request at a time (links last up to 7 days), 5 GB of storage and no card; paid seats are €29 per seat per month (or €290 per seat per year) for unlimited open requests, automatic client reminders, your logo and longer links, up to 500 seats, with clients never paying or signing up. The immigration suites are priced per user per month for the whole workflow: eImmigration publishes $55/$70/$85 per user, Docketwise is commonly cited around $69–$109 per user, LollyLaw is unofficially around $120 per user, and INSZoom is quote-based. The comparison is not like-for-like — the suites include forms, e-filing, and case management that ShieldFive does not — so weigh cost against the whole feature set, not the seat price alone.

Can I use ShieldFive alongside my existing case-management software?

Yes. ShieldFive can provide a separate encrypted document-request workflow alongside existing case-management software, but there is no integration today. The web app code it delivers remains part of the trust boundary, so it must not be treated as a channel that the provider is technically unable to decrypt.

Ready to Protect What's Yours?

Encrypted on your device

5 GB free · No card required · Encrypted before upload