Feature · Secure Inbox

Receive filessecurely.No account required.

Every employee gets a personal upload link. Clients, patients, applicants, and suppliers send files encrypted, no account, no software, no email size limits. GDPR-compliant, hosted in the EU.

Incoming files are the unsolved problem

Sending is easy. Receiving is the drama. Four reasons why nobody is satisfied today.

Email attachments get rejected

Your inbox caps at 25 MB. The client sends the contract three times, each time it lands in the bounce report.

WeTransfer is GDPR-risky

Your customer sends via WeTransfer, the file caches in the US. You receive it, but legally you're in a grey zone.

OneDrive shares fail on accounts

The applicant has no Microsoft account. The permission check fails. You call back and forth, or ask for another email resend.

FTP servers are a maintenance nightmare

IT doesn't want to maintain more FTP credentials. Patches, upgrades, access protocols, too much overhead for a file upload.

ihrefirma.de/sendto/max-mueller
MM
Send files to Max Müller
Your Company Ltd · encrypted transfer
Datei hier ablegen
or click to choose
gutachten-2026.pdf14 MB
videokonferenz.mp41,8 GB62%
Hosted in the EU · end-to-end encryptedDSGVO-konform
Highlight · Secure Inbox

The personal upload link your externals actually complete

Every employee gets their own upload link. Clients, patients and applicants upload files right in the browser, no account, no software. Encrypted, logged, hosted in the EU.

No account required for externals, no Microsoft login, no WeTransfer detour.

Encrypted from the browser to storage, virus scanning before the file reaches your inbox.

Own subdomain and branding possible, the link feels like part of your company.

Full audit log: uploader, IP hash, timestamp, automatic retention.

Three steps to secure receipt

The SecureFiles Secure Inbox makes uploads as simple as a WeTransfer share, but GDPR-compliant and without US cloud.

1. Share the link

Copy your personal upload link from SecureFiles and put it in your email signature, website, or a client letter.

2. External uploads

The client opens the link in a browser. No account needed. Select file, optionally set a password, upload. Encrypted in transit, malware-scanned.

3. You receive

You get a signed email notification. File is ready to pick up in SecureFiles. Audit log shows origin, IP hash, timestamp.

Everything a secure inbox needs

No form builder, no branching workflow. A personal link, the rest is security craftsmanship.

Personal upload link

Every employee has their own link, bindable to role, team, or department. No central collection inbox, clear attribution from the first upload.

Encrypted in transit and at rest

Upload stream secured by TLS, data at rest AES-256, optionally stored in your own S3 bucket in Germany.

Malware scan before release

Every uploaded file is scanned before delivery. Infected uploads go to quarantine, not your inbox.

Audit log per GDPR Art. 30

Who uploaded what when, including IP hash, user agent, and file size. Origin verifiable any time.

No account for externals

The client needs no Microsoft account, no Dropbox login, no Tresorit registration. Open link, upload, done.

Branded from a single source

Upload page in your logo, your colors, with your imprint. The client sees your brand, not ours.

Secure Inbox in comparison

What the usual workarounds don't deliver, and we do, in the standard.

 
SecureFiles
Typical workarounds
Account required for externals
No
Usually yes (OneDrive, Dropbox, Tresorit)
Encryption in transit and at rest
Yes, optional client-side
TLS only
Virus scan before delivery
Malware scan by default
Rarely, often post-hoc
GDPR European hosting
Yes
Often US cloud
Audit log with IP hash
Standard
Limited or unavailable
Own branding
Included
Upcharge or unavailable

Statements about the usual route follow the publicly documented prerequisites of common signature services that source people data from Entra ID.

FAQ: Secure Inbox

What is a secure inbox?
A secure inbox is the counterpart of secure sending: instead of you sending files to externals, externals get a way to deliver files to you encrypted. With SecureFiles, every employee gets a personal upload link. The external opens the link, uploads the file, you get a notification. Encrypted, malware-scanned, GDPR-compliant.
Do externals need an account with you?
No. That's exactly the point. The client, patient, or applicant opens the link in a browser and uploads the file. No registration, no software install, no OAuth chain with Microsoft or Google. Optionally, the employee can set a password the external enters before upload, for sensitive contexts.
How large can uploaded files be?
No hard per-file size cap. CAD drawings, DICOM imaging, video recordings, and database exports are receivable without the external needing a split workflow.
Is the Secure Inbox GDPR-compliant?
Yes. Upload infrastructure is in the EU, TLS in-transit and AES-256 at-rest are standard. Every file is auditable via the audit log (GDPR Art. 30), IP addresses are hashed, retention is configurable per tenant. A DPA template is available on request.
Are uploaded files scanned for malware?
Yes. Every upload goes through a malware scan before the file is released to the receiving employee. Infected files go to quarantine automatically, you get a notification, the original file never reaches you.
How long are received files kept?
Retention is configured per tenant, default is 10 days, selectable between 7, 10, and 30 days. After expiry the file is deleted automatically. For longer retention needs, move the file to your records during the retention window.
Which industries benefit most from the Secure Inbox?
Any industry where externals submit confidential documents: law firms (client contracts), medical practices (MRI results, patient documents), HR (applicant references, health certificates), procurement (CAD drawings from suppliers), tax advisors (receipts from clients), insurers (damage photos). Industries handling GDPR Art. 9 categories gain the most.
How does this differ from a client portal?
A classic client portal is a persistent dashboard with login, folder structure, and ongoing relationship. The Secure Inbox is lighter: a one-time upload flow without the external registering or managing files. Perfect for ad-hoc receipt; for ongoing collaboration we recommend our data room solution (in planning).

Related solutions

Launch your Secure Inbox.

30-minute demo. Free pilot phase. Your clients will love it.