Security
How ReceiveVault keeps files safe
Last updated June 20, 2026
The technical building blocks behind secure file collection. Security is a shared responsibility - these are the controls we provide.
Uploads are virus-scanned
Every file we can read is streamed through ClamAV before it lands in your dashboard. Malicious files are quarantined and removed, and you are notified. End-to-end encrypted uploads are the deliberate exception: their contents are unreadable to us by design, so they cannot be scanned.
Encrypted in transit and at rest
All traffic runs over TLS. Files are stored in S3-compatible object storage with server-side encryption - never copied to third-party clouds.
Optional end-to-end encryption
On Business and Enterprise plans, files can be encrypted in the contact's browser with your account's public key, so their contents are unreadable by anyone but you - including us.
Full audit log
Every meaningful action - request created, link sent, file uploaded, file downloaded - is timestamped with the actor, giving you a defensible record of who did what, when.
No account for your clients
Contacts upload through a magic link addressed to them, with optional one-time-code email verification you can require. There is no password for them to reuse or leak, and no extra account to manage.
Expiry and retention controls
Every link expires. A request link carries an expiry you choose when you create it (30 days by default, 90 at most), and outbound deliveries carry one you set per send along with an optional download limit. Once a link expires it stops working. Files remain under your control until you delete them or your retention policy removes them.
Strong account security
Argon2id password hashing, TOTP and hardware-key (WebAuthn) multi-factor authentication, per-action re-verification, and new-device login alerts.
Built for Canadian privacy obligations
Minimum-necessary collection, audit logging, encryption, and automatic expiry are designed against PIPEDA, PHIPA, and Quebec Law 25 expectations. Compliance is ultimately yours to attest, but the technical controls a privacy officer asks about are here and documented.
Canadian-owned and Canadian-hosted
The application, the database, and uploaded files run on servers owned and operated by a Canadian hosting company, on Canadian soil. This is the distinction that matters legally: a US-owned provider with a Canadian datacentre is still a US provider, and a US CLOUD Act order is served on the provider, not the building. There is no US-owned company in the custody chain of your files, so they are handled under Canadian legal process. That is not immunity from legal process - Canadian courts can compel production, and governments cooperate through treaty channels - but it does decide whose law applies. Email notifications are sent through an SMTP provider that may route messages outside Canada in transit (protected by TLS); see our Privacy Policy.
Have a security question or want to report a concern? Email support@receivevault.com.