Skip to content

Stop emailing
Start requesting them safely.

Magic-link client intake for therapists, counsellors and allied-health practitioners. Clients upload intake forms, consent, insurance and prior records through one secure link - encrypted, virus-scanned, and audit-logged. Built with HIPAA expectations in mind.

14-day free trial · No charge until day 15 · Cancel anytime

Hosted in Canada by a Canadian company - outside the direct reach of US CLOUD Act orders.

receivevault.com/dashboard
Active requests
3 open
+ New request
Smith · Residential Purchase
4 of 5 files received
In progress
Jones · Refinance
5 of 5 files · scanned clean
Complete
Patel · Pre-approval
1 of 4 files received
Awaiting

Built for therapists · counsellors · psychologists · physiotherapists · dietitians

Built for the way you actually work

I'm a…

“New clients email me their intake form and a photo of their insurance card - I cringe every time.”
  • One secure link replaces the email attachment for intake forms, consent, and prior records.
  • Files are encrypted at rest and audit-logged; end-to-end encryption is available on Business+ for the most sensitive records.
  • Reusable intake template so every new client starts the same checklist in under a minute.
  • No client account or app - just a link they click once.
How it works

Three steps. No software for your client.

1

Create a request

List the files you need. Start from a ready-made template or build your own checklist - it adapts to whatever you collect.

2

Your client gets a magic link

One email, one click, no account. They see a tidy checklist on a page branded as your firm, not ours.

3

Files land in your dashboard

Each one is scanned for viruses, encrypted at rest, and added to the audit log so you know who sent what when.

Why pay for this

Email wasn't built for client documents.

You already know the alternatives have problems. Here's how this stacks up against what you're probably doing today.

CapabilityEmailDropbox / WeTransferReceiveVault
Client needs an accountNoOften yesNo
Virus-scanned on arrivalNoNoYes (ClamAV)
Audit log of who-sent-what-whenNoLimitedEvery action
Branded as your firmNoNoYes
Files encrypted at restProvider-dependentYesYes
Optional end-to-end encryptionNoNoYes (Business+)
Send files securely outboundAttachment-onlyYes (separate flow)Yes (same portal)
Canadian-owned hostingUsually noNoYes, in Canada - outside US CLOUD Act jurisdiction
Data sovereignty

Who can be ordered to hand over your clients’ files?

The US CLOUD Act lets US authorities compel any US-based provider to produce data it controls, wherever that data physically sits. Most secure-file tools are US companies, so which datacentre they picked never really answers the question.

A US tool with a Canadian region

  1. Provider
    US company
  2. Servers
    Canadian datacentre
  3. Who can compel it
    US authorities, directly

Data residency. The files are in Canada, but the company holding them answers to a US court.

ReceiveVault

  1. Provider
    Canadian company
  2. Servers
    Canadian-owned, in Canada
  3. Who can compel it
    Canadian courts

Data sovereignty. There is no US-owned company in the custody chain of your clients' files.

ReceiveVault runs on servers owned and operated by a Canadian hosting company, for a Canadian company. Your clients’ files sit outside the direct reach of a US CLOUD Act order and are handled under Canadian privacy law.

To be precise

No provider is beyond all legal process. Canadian courts can compel production, and governments cooperate through treaty channels. What changes is whose law and whose courts, and that no US-owned company holds your clients' files. Email notifications currently relay through a provider outside Canada, protected by TLS in transit; file contents never leave Canadian infrastructure.

Read the full explainer: does the US CLOUD Act reach your clients' files?

Also in this series: PIPEDA and US-owned tools, Quebec's Law 25, law society guidance, and the twelve questions to put to a vendor. See all guides.

Security

The boring parts, done properly.

Virus scanning

Every upload goes through ClamAV before it lands in your dashboard. Infected files are quarantined and you get an alert.

Encrypted in transit and at rest

TLS everywhere, and files stored in S3-compatible object storage with server-side encryption. Optional client-side end-to-end encryption on Business+.

Full audit log

Every action gets a timestamped record with the actor: request created, link sent, file uploaded, file downloaded. Exportable.

Canadian-owned hosting

The app, the database, and your files run on servers owned and operated by a Canadian hosting company, on Canadian soil. No US-owned provider in the custody chain.

No third-party trackers

The pages your clients see carry no advertising or analytics trackers. Their upload page reports to you, and to nobody else.

MFA on every account

TOTP, hardware passkeys (YubiKey / iCloud / Windows Hello), and recovery codes. Sudo gate on destructive actions.

What you can do

Built for the people who send the scary stuff.

Stop chasing files over email

Send one link instead of a back-and-forth email thread. Your contact uploads everything in one place, and you get a clean, timestamped record of what arrived and when.

Addressed to one person, not the world

A request is for a single named recipient - not a public share anyone can open. Turn on one-time-code email verification and a forwarded link will not open for anyone else.

Every contact sends the same set

Build a checklist once and each person returns exactly the files you asked for. No more piecing together a dozen loose attachments per applicant or client.

No account for your contacts

The people you collect from never sign up or set a password. One link, upload, done - which means far fewer “how do I use this” replies landing in your inbox.

A defensible audit trail

Every request, upload, and download is timestamped with the actor. On a regulated file you can show exactly what was collected and when, without reconstructing it from an email thread.

Built for the sensitive stuff

Virus scanning, encryption at rest, automatic link expiry, and download limits are there from the start - so the documents your clients are nervous about sending are handled carefully.

FAQ

Common questions

Does this support my HIPAA obligations?+

It is built with HIPAA expectations in mind: minimum-necessary collection, encryption in transit and at rest, optional end-to-end encryption, audit logging, and configurable expiry. The technical controls are here, but compliance ultimately remains your responsibility.

Where are the files stored?+

On S3-compatible object storage with server-side encryption, running on servers owned and operated by a Canadian hosting company on Canadian soil. Files are never copied to third-party clouds, and no US-owned provider sits in the custody chain.

Does the US CLOUD Act reach my clients’ files?+

A CLOUD Act order is served on a provider subject to US jurisdiction. The application, the database, and your clients’ files all run on infrastructure owned and operated by a Canadian company, so there is no US provider in that chain to serve. Files are subject to Canadian legal process instead. No provider is beyond all legal process - courts on either side of the border can compel production through their own channels - but the direct route does not exist here.

What happens to files after the request expires?+

Every link expires, and you choose when. Each request link carries an expiry you set when you create it (30 days by default, up to 90), and outbound deliveries carry one you set per send. Once a link expires the magic link stops working. Files remain in your dashboard until you delete them or your retention policy removes them.

Is this HIPAA / GLBA / CCPA compliant?+

The product is built with privacy-by-design expectations in mind: minimum-necessary collection, audit logging, encryption, expiry. We are not HIPAA-certified and do not sign BAAs at this tier; for HIPAA-adjacent workflows we provide the technical building blocks (encryption, access logs, MFA) but compliance certification is your responsibility. GLBA and CCPA obligations are similarly supported but ultimately yours to attest.

Can I cancel during the trial?+

Yes. The 14-day trial is free and we don’t charge your card until day 15. Cancel any time from the billing page in your dashboard.

Can my clients reply to the magic-link email?+

Yes. Invite emails go out with your email address as the reply-to, so your client can ask a question and it lands in your inbox like a normal reply.

Try it on your next intake.

14 days free, every feature included. Cancel before day 15 and your card is never charged.

Further reading