Menu
Guides

How to share files securely with clients

Updated 25 September 2026, 7 minute read

To share files securely with clients, stop sending sensitive documents as email attachments or open links. Use one place per client where files are encrypted, access is limited to named people, downloads use links that expire, and every view and download is recorded. Then agree a short policy with your team and follow it for every client.

Most small firms share files with clients the same way they did ten years ago: attachments in email, a link to a shared folder, occasionally a file transfer service for anything too big. It mostly works. The trouble is that “mostly” includes the passport scan sitting in a former employee’s inbox, the folder link that’s been forwarded to someone at a supplier, and the signed contract nobody can find because it was sent to a personal address.

This guide explains where common methods fall short, what to look for in a secure alternative, and how to set a simple file-sharing policy for your firm. It’s practical rather than technical; you don’t need to be an IT specialist to act on any of it.

What makes file sharing insecure?

Security problems in small-firm file sharing rarely come from sophisticated attacks. They come from ordinary habits that leave files in the wrong places.

Files that never leave inboxes. An attachment exists in the sender’s sent folder, the recipient’s inbox, any backup of either, and the inbox of anyone it’s forwarded to. You can’t delete it later, and you often can’t tell where it’s gone.

Links that anyone can open. “Anyone with the link” sharing is convenient, and it means exactly what it says. A link pasted into the wrong chat, or left in an old email, stays open until someone remembers to close it.

Access that nobody removes. When a client’s employee leaves, or a project ends, shared folder access usually stays as it was. Over a few years, a firm’s shared drive quietly accumulates access for dozens of people it no longer works with.

Reused and shared passwords. When a portal or shared drive requires a password, clients reuse one from elsewhere, write it down, or share one login between colleagues. Any of those turns a secure system into a weak one.

No record of who saw what. If you can’t answer “who downloaded this file, and when?”, you can’t tell whether a document went where it shouldn’t, and you can’t reassure a client who asks.

How do common methods compare?

Email attachments are simple and universal, but files persist in inboxes indefinitely, can be forwarded freely, and leave no record of who opened them. Size limits also push people to other tools for anything large. Reasonable for low-sensitivity files; poor for identity documents, financial records or contracts.

Shared folders (Google Drive, Dropbox, OneDrive) are good for storing and organising files, with some access control. The risks are permission drift, “anyone with the link” sharing, and clients who need an account with that provider. Workable if someone owns the permissions and reviews them regularly. See Google Drive vs a client portal for more.

File transfer services handle large files well, and links usually expire. They’re designed for one-off sending, not an ongoing relationship: nothing ties the file to the client, and there’s rarely a record you control.

Client portals give each client their own private space, with files, access and history in one place. A well-built one encrypts files, separates each client’s data, uses expiring download links and keeps an audit log. The trade-off is one more tool for your team to adopt, and choosing one clients will actually sign in to.

What to look for in a secure way to share files

Whichever tool you use, these are the properties that matter. They also make a useful set of questions for any vendor.

  1. Encryption in transit and at rest. Files should travel over HTTPS and be stored encrypted. This is standard now; any tool that can’t say yes clearly should be ruled out.
  2. Access for named people only. Each client’s files should be visible to that client’s named contacts and your team, not to anyone holding a link.
  3. Sign-in without shared passwords. One-time sign-in links sent to the person’s own email address avoid reused and shared passwords entirely. If a tool uses passwords, it should support two-step sign-in for your team at least.
  4. Download links that expire. Links that stop working after minutes, not days, mean an old link found in an email can’t be used later.
  5. An audit log. Who uploaded, viewed or downloaded each file, and when, from where. You should be able to export it.
  6. Malware checks on uploads. Files from clients should be checked before your team opens them, with anything suspicious quarantined.
  7. Easy removal of access. Removing a person, or closing a client’s space, should end access immediately and completely.
  8. Deletion you control. You should be able to permanently delete a client’s files when your retention period ends, and export them first.

Denby’s file sharing is built around these properties; our security page says how each works and what we don’t do.

A file-sharing policy for a small firm

A policy doesn’t need to be long to be useful. The one below fits on a page. Adapt it, share it with your team, and mention the relevant parts to clients in your welcome message.

  1. Sensitive documents never travel by email. Identity documents, financial statements, contracts and anything covered by confidentiality go through the client’s portal space in both directions. If a client emails one, upload it to their space, reply with a link to it, and delete the email.
  2. Every client has one place. All files for a client live in their space, not in personal drives or desktops.
  3. Access is to named people. No “anyone with the link” sharing for client files. Add each person at the client individually.
  4. Access ends when work ends. When a project finishes, archive the client or remove their access. When someone at a client leaves, remove them that day.
  5. Staff use two-step sign-in. Everyone on your team enables it on every tool that holds client files.
  6. Files are deleted on schedule. Decide how long you keep each kind of file, and delete on that schedule. Export first if you need an archive.
  7. Incidents are reported the same day. If a file goes to the wrong person, tell the firm’s lead immediately, then the client. Speed matters more than blame.

Explaining it to clients

Clients sometimes see a portal as an extra hurdle. A sentence of explanation usually settles it: “We don’t send documents like this by email, to keep them safe. You’ll get a link that signs you in; there’s no password to remember.” Most clients are reassured, especially those who’ve had an email account compromised.

Be ready for the occasional client who insists on email. Explain once why you don’t use it for sensitive files, offer to walk them through the first upload by phone, and if they still prefer email, upload what they send to their space and delete the original. The policy protects them as much as you, and most clients understand that once it’s put plainly.

Make the secure route the easy route. If uploading to the portal takes longer than attaching a file to an email, clients will choose email. Test it yourself, on your phone, from the invitation email.

What rules might apply to you?

Depending on where you work and what you handle, several kinds of rule may cover how you share client files. This isn’t legal advice, but it’s worth knowing which apply to you.

Data protection law. If you hold personal data about people in the UK or European Union, UK GDPR or the GDPR require you to keep it secure, limit who can access it, keep it no longer than necessary and report certain breaches. Similar laws exist in many other countries and US states. When you use a software provider to hold that data, you’ll usually need a data processing agreement with them; reputable providers publish one, like Denby’s data processing agreement.

Professional body rules. Accountants, lawyers, financial advisers, immigration advisers and others often have rules about client confidentiality and record keeping. Check your professional body’s guidance on how long to keep files and how to share them.

Contracts with your clients. Larger clients may set their own requirements in their contract: where data is stored, how quickly you must report incidents, and whether you can use sub-processors. Read those clauses before choosing a tool.

When a file goes to the wrong person

It happens to careful firms too. What matters is acting quickly and in the right order.

  1. Contain it. Remove the recipient’s access, or ask them to delete the file and confirm they have.
  2. Work out what was exposed. Which file, whose data, and for how long. An audit log that shows downloads is what lets you answer this precisely.
  3. Tell the right people. Your firm’s lead first, then the client whose data it was. If personal data was involved, check whether you must notify a regulator; under the GDPR, some breaches must be reported within 72 hours.
  4. Fix the cause. A mistyped address, a wrongly shared folder, a missing step in your process. Change the process, not just the person.

Two special cases

Identity documents. Passports, driving licences and right-to-work evidence are among the most valuable documents to a fraudster. Collect them only through your secure space, never by email, and delete them when you no longer need them. See how recruiters collect candidate documents with a checklist and a clear retention step.

Very large files. Video, photography, drawings and datasets push people towards whatever tool can handle the size, which is often the least controlled option. Choose a secure tool that accepts large uploads and resumes interrupted ones, so size never becomes the reason to bypass your policy.

Common mistakes

Securing the storage, not the sharing. An encrypted drive doesn’t help if the files leave it as email attachments.

Treating the portal as optional. If some documents come by portal and some by email, you’ve got two systems to secure, and neither is complete.

Forgetting your own side. Most incidents involve the firm, not the client: a laptop without a password, a shared login, a colleague’s personal email. Your policy should cover your team first.

Keeping everything forever. Every old file is a liability if something goes wrong. Keep what you need, for as long as you need it.

Overcomplicating it. A seven-point policy followed by everyone is worth more than a 40-page one nobody reads.

Where to go from here

If you’re choosing a tool, start with the client portal checklist; its security section turns this guide into questions for a trial. If your firm handles identity documents, see how immigration consultants use Denby to collect evidence securely. For large files, see how photographers deliver full-resolution work without a separate transfer service.

Set up your first client portal in 20 minutes.

14 days free. No card. Unlimited team members on every plan.