Stop emailing
Start requesting them safely.
Magic-link file collection for Canadian professionals who handle sensitive client documents. Virus-scanned, encrypted, audit-logged, and your clients don’t need an account.
14-day free trial · No charge until day 15 · Cancel anytime
Canadian company. Canadian-owned servers. Your clients’ files never touch US-controlled infrastructure.
Built for Canadian mortgage brokers · lawyers · accountants · bookkeepers · financial planners · immigration consultants
I'm a…
“My client just emailed me their SIN, their T4, and a photo of their passport. In one email.”
- Send one magic link, collect SINs / T4s / pay stubs / ID in a single intake. No app, no account, no friction for the client.
- Files virus-scanned, encrypted at rest, audit-logged with who-sent-what-when.
- Pre-built request template for residential mortgage purchase and refinance. Start in under a minute.
- Send commitment letters and closing packages back through the same portal - no second tool, same audit trail.
Three steps. No software for your client.
Create a request
List the files you need. Start from a ready-made template or build your own checklist - it adapts to whatever you collect.
Your client gets a magic link
One email, one click, no account. They see a tidy checklist on a page branded as your firm, not ours.
Files land in your dashboard
Each one is scanned for viruses, encrypted at rest, and added to the audit log so you know who sent what when.
Email wasn't built for client documents.
You already know the alternatives have problems. Here's how this stacks up against what you're probably doing today.
| Capability | Dropbox / WeTransfer | ReceiveVault | |
|---|---|---|---|
| Client needs an account | No | Often yes | No |
| Virus-scanned on arrival | No | No | Yes (ClamAV) |
| Audit log of who-sent-what-when | No | Limited | Every action |
| Branded as your firm | No | No | Yes |
| Files encrypted at rest | Provider-dependent | Yes | Yes |
| Optional end-to-end encryption | No | No | Yes (Business+) |
| Send files securely outbound | Attachment-only | Yes (separate flow) | Yes (same portal) |
| Canadian-owned hosting | Usually no | No | Yes - Canadian provider, outside US CLOUD Act jurisdiction |
A Canadian datacentre is not the same as a Canadian company.
The US CLOUD Act lets US authorities compel a US-based provider to produce data it controls - including data sitting on servers in Toronto. Picking a tool with a Canadian region does not settle the question. Who owns the provider does.
A US tool with a Canadian region
- ProviderUS company
- ServersCanadian datacentre
- Who can compel itUS authorities, directly
Data residency. The files are in Canada, but the company holding them answers to a US court.
ReceiveVault
- ProviderCanadian company
- ServersCanadian-owned, in Canada
- Who can compel itCanadian courts
Data sovereignty. There is no US-owned company in the custody chain of your clients' files.
ReceiveVault runs on servers owned and operated by a Canadian hosting company, for a Canadian company. Your clients’ files are handled under Canadian legal process - PIPEDA, provincial privacy law, and Quebec Law 25.
No provider is beyond all legal process. Canadian courts can compel production, and governments cooperate through treaty channels. What changes is whose law and whose courts, and that no US-owned company holds your clients' files. Email notifications currently relay through a provider outside Canada, protected by TLS in transit; file contents never leave Canadian infrastructure.
Read the full explainer: does the US CLOUD Act reach your clients' files?
Also in this series: PIPEDA and US-owned tools, Quebec's Law 25, law society guidance, and the twelve questions to put to a vendor. See all guides.
The boring parts, done properly.
Virus scanning
Every upload goes through ClamAV before it lands in your dashboard. Infected files are quarantined and you get an alert.
Encrypted in transit and at rest
TLS everywhere, and files stored in S3-compatible object storage with server-side encryption. Optional client-side end-to-end encryption on Business+.
Full audit log
Every action gets a timestamped record with the actor: request created, link sent, file uploaded, file downloaded. Exportable.
Canadian-owned hosting
The app, the database, and your files run on servers owned and operated by a Canadian hosting company, on Canadian soil. No US-owned provider in the custody chain.
No third-party trackers
The pages your clients see carry no advertising or analytics trackers. Their upload page reports to you, and to nobody else.
MFA on every account
TOTP, hardware passkeys (YubiKey / iCloud / Windows Hello), and recovery codes. Sudo gate on destructive actions.
Built for the people who send the scary stuff.
Stop chasing files over email
Send one link instead of a back-and-forth email thread. Your contact uploads everything in one place, and you get a clean, timestamped record of what arrived and when.
Addressed to one person, not the world
A request is for a single named recipient - not a public share anyone can open. Turn on one-time-code email verification and a forwarded link will not open for anyone else.
Every contact sends the same set
Build a checklist once and each person returns exactly the files you asked for. No more piecing together a dozen loose attachments per applicant or client.
No account for your contacts
The people you collect from never sign up or set a password. One link, upload, done - which means far fewer “how do I use this” replies landing in your inbox.
A defensible audit trail
Every request, upload, and download is timestamped with the actor. On a regulated file you can show exactly what was collected and when, without reconstructing it from an email thread.
Built for the sensitive stuff
Virus scanning, encryption at rest, automatic link expiry, and download limits are there from the start - so the documents your clients are nervous about sending are handled carefully.
Common questions
Where are the files stored?+
On S3-compatible object storage with server-side encryption, running on servers owned and operated by a Canadian hosting company on Canadian soil. Files are never copied to third-party clouds, and no US-owned provider sits in the custody chain.
Does the US CLOUD Act reach my clients’ files?+
A CLOUD Act order is served on a provider subject to US jurisdiction. The application, the database, and your clients’ files all run on infrastructure owned and operated by a Canadian company, so there is no US provider in that chain to serve. Files are subject to Canadian legal process instead. No provider is beyond all legal process - Canadian courts can still compel production - but whose law applies is the part you get to choose.
What happens to files after the request expires?+
Every link expires, and you choose when. Each request link carries an expiry you set when you create it (30 days by default, up to 90), and outbound deliveries carry one you set per send. Once a link expires the magic link stops working. Files remain in your dashboard until you delete them or your retention policy removes them.
Is this PIPEDA / Quebec Law 25 compliant?+
The product is built with PIPEDA, PHIPA, and Quebec Law 25 expectations in mind: minimum-necessary collection, audit logging, encryption, expiry, and hosting with a Canadian-owned provider on Canadian soil. Compliance is ultimately your responsibility, but the technical building blocks are here.
Can I cancel during the trial?+
Yes. The 14-day trial is free and we don’t charge your card until day 15. Cancel any time from the billing page in your dashboard.
Can my clients reply to the magic-link email?+
Yes. Invite emails go out with your email address as the reply-to, so your client can ask a question and it lands in your inbox like a normal reply.
Try it on your next intake.
14 days free, every feature included. Cancel before day 15 and your card is never charged.