Stop emailing
Start requesting them safely.
Magic-link document collection for notaries and estate planners. Clients upload wills, ID, asset documents and beneficiary details through one secure link - virus-scanned, encrypted, and audit-logged. Easy enough for any client to use.
14-day free trial · No charge until day 15 · Cancel anytime
Hosted in Canada by a Canadian company - outside the direct reach of US CLOUD Act orders.
Built for notaries · estate planners · wills & estates practitioners
I'm a…
“My clients are often older and not technical - emailing me a scanned will is a real struggle for them.”
- A single link with a tidy checklist - no account, no app, nothing for the client to install.
- Files virus-scanned, encrypted at rest, and audit-logged for your file.
- Send executed documents back to the client through the same secure link.
Three steps. No software for your client.
Create a request
List the files you need. Start from a ready-made template or build your own checklist - it adapts to whatever you collect.
Your client gets a magic link
One email, one click, no account. They see a tidy checklist on a page branded as your firm, not ours.
Files land in your dashboard
Each one is scanned for viruses, encrypted at rest, and added to the audit log so you know who sent what when.
Email wasn't built for client documents.
You already know the alternatives have problems. Here's how this stacks up against what you're probably doing today.
| Capability | Dropbox / WeTransfer | ReceiveVault | |
|---|---|---|---|
| Client needs an account | No | Often yes | No |
| Virus-scanned on arrival | No | No | Yes (ClamAV) |
| Audit log of who-sent-what-when | No | Limited | Every action |
| Branded as your firm | No | No | Yes |
| Files encrypted at rest | Provider-dependent | Yes | Yes |
| Optional end-to-end encryption | No | No | Yes (Business+) |
| Send files securely outbound | Attachment-only | Yes (separate flow) | Yes (same portal) |
| Canadian-owned hosting | Usually no | No | Yes, in Canada - outside US CLOUD Act jurisdiction |
Who can be ordered to hand over your clients’ files?
The US CLOUD Act lets US authorities compel any US-based provider to produce data it controls, wherever that data physically sits. Most secure-file tools are US companies, so which datacentre they picked never really answers the question.
A US tool with a Canadian region
- ProviderUS company
- ServersCanadian datacentre
- Who can compel itUS authorities, directly
Data residency. The files are in Canada, but the company holding them answers to a US court.
ReceiveVault
- ProviderCanadian company
- ServersCanadian-owned, in Canada
- Who can compel itCanadian courts
Data sovereignty. There is no US-owned company in the custody chain of your clients' files.
ReceiveVault runs on servers owned and operated by a Canadian hosting company, for a Canadian company. Your clients’ files sit outside the direct reach of a US CLOUD Act order and are handled under Canadian privacy law.
No provider is beyond all legal process. Canadian courts can compel production, and governments cooperate through treaty channels. What changes is whose law and whose courts, and that no US-owned company holds your clients' files. Email notifications currently relay through a provider outside Canada, protected by TLS in transit; file contents never leave Canadian infrastructure.
Read the full explainer: does the US CLOUD Act reach your clients' files?
Also in this series: PIPEDA and US-owned tools, Quebec's Law 25, law society guidance, and the twelve questions to put to a vendor. See all guides.
The boring parts, done properly.
Virus scanning
Every upload goes through ClamAV before it lands in your dashboard. Infected files are quarantined and you get an alert.
Encrypted in transit and at rest
TLS everywhere, and files stored in S3-compatible object storage with server-side encryption. Optional client-side end-to-end encryption on Business+.
Full audit log
Every action gets a timestamped record with the actor: request created, link sent, file uploaded, file downloaded. Exportable.
Canadian-owned hosting
The app, the database, and your files run on servers owned and operated by a Canadian hosting company, on Canadian soil. No US-owned provider in the custody chain.
No third-party trackers
The pages your clients see carry no advertising or analytics trackers. Their upload page reports to you, and to nobody else.
MFA on every account
TOTP, hardware passkeys (YubiKey / iCloud / Windows Hello), and recovery codes. Sudo gate on destructive actions.
Built for the people who send the scary stuff.
Stop chasing files over email
Send one link instead of a back-and-forth email thread. Your contact uploads everything in one place, and you get a clean, timestamped record of what arrived and when.
Addressed to one person, not the world
A request is for a single named recipient - not a public share anyone can open. Turn on one-time-code email verification and a forwarded link will not open for anyone else.
Every contact sends the same set
Build a checklist once and each person returns exactly the files you asked for. No more piecing together a dozen loose attachments per applicant or client.
No account for your contacts
The people you collect from never sign up or set a password. One link, upload, done - which means far fewer “how do I use this” replies landing in your inbox.
A defensible audit trail
Every request, upload, and download is timestamped with the actor. On a regulated file you can show exactly what was collected and when, without reconstructing it from an email thread.
Built for the sensitive stuff
Virus scanning, encryption at rest, automatic link expiry, and download limits are there from the start - so the documents your clients are nervous about sending are handled carefully.
Common questions
Where are the files stored?+
On S3-compatible object storage with server-side encryption, running on servers owned and operated by a Canadian hosting company on Canadian soil. Files are never copied to third-party clouds, and no US-owned provider sits in the custody chain.
Does the US CLOUD Act reach my clients’ files?+
A CLOUD Act order is served on a provider subject to US jurisdiction. The application, the database, and your clients’ files all run on infrastructure owned and operated by a Canadian company, so there is no US provider in that chain to serve. Files are subject to Canadian legal process instead. No provider is beyond all legal process - courts on either side of the border can compel production through their own channels - but the direct route does not exist here.
What happens to files after the request expires?+
Every link expires, and you choose when. Each request link carries an expiry you set when you create it (30 days by default, up to 90), and outbound deliveries carry one you set per send. Once a link expires the magic link stops working. Files remain in your dashboard until you delete them or your retention policy removes them.
Is this HIPAA / GLBA / CCPA compliant?+
The product is built with privacy-by-design expectations in mind: minimum-necessary collection, audit logging, encryption, expiry. We are not HIPAA-certified and do not sign BAAs at this tier; for HIPAA-adjacent workflows we provide the technical building blocks (encryption, access logs, MFA) but compliance certification is your responsibility. GLBA and CCPA obligations are similarly supported but ultimately yours to attest.
Can I cancel during the trial?+
Yes. The 14-day trial is free and we don’t charge your card until day 15. Cancel any time from the billing page in your dashboard.
Can my clients reply to the magic-link email?+
Yes. Invite emails go out with your email address as the reply-to, so your client can ask a question and it lands in your inbox like a normal reply.
Try it on your next intake.
14 days free, every feature included. Cancel before day 15 and your card is never charged.