Professional firms handle documents that should never sit in an inbox: identity records, financial statements, signed agreements, government forms. A secure client portal replaces email attachments and consumer file-sharing links with permissioned access, encryption in transit and at rest, and an audit trail you can produce when someone asks for it. SafeVault is built by AmitaSoft, LLC, which completed a SOC 2 Type 2 examination covering Security, Availability, Processing Integrity and Confidentiality.
Why email is the wrong place for client documents
Email was never designed to carry sensitive records. Attachments persist in sent folders, forwarded threads and backups long after the work is finished, in systems nobody is auditing. A document sent to the wrong recipient cannot be recalled. And when a client asks what they have already sent you, the answer is buried in a thread.
Consumer file-sharing links solve the transport problem and create a new one. A link that anyone can open is a permission model with no permissions. There is no record of who accessed the file, no way to revoke access after the fact, and no connection between the document and the piece of work it belongs to.
A firm portal fixes both. Access is granted to a named person, revoked when the work closes, and logged throughout.
What a secure firm portal does
- Permissioned access
- Each client sees only their own documents. Access is granted to named people and can be revoked at any time. Role-based permissions control what your own team can see.
- Encrypted exchange
- Documents are encrypted in transit using TLS and at rest using AES-256, applied to both stored databases and stored documents.
- Document requests with status
- Ask for what you need as a tracked request rather than an email. See at a glance what has arrived, what is outstanding, and who is holding up the work.
- Audit history
- Every upload, view, share and version change is recorded. When someone asks who accessed a document and when, the answer is a lookup rather than an investigation.
- Multi-factor authentication
- Required for access to critical systems, under a documented access control policy.
- Automatic organisation
- Uploaded documents are classified and key fields extracted, so files arrive sorted rather than as a folder of scans named IMG_4417.
Who uses it
SafeVault's portal is used by professional firms that exchange sensitive documents as part of routine work: financial advisors, attorneys, lenders, consultants, and tax and accounting practices.
If you work in tax or accounting specifically, there is a dedicated workspace built around client engagements, document requests and guided questionnaires.
Security
Security is the same on every SafeVault plan. It is not an upgrade.
AmitaSoft, LLC completed a SOC 2 Type 2 examination of the platform behind SafeVault, performed by an independent licensed CPA firm, covering Security, Availability, Processing Integrity and Confidentiality across an observation period from 15 May to 28 August 2026. The full report is available under a non-disclosure agreement.
Access runs through role-based permissions with multi-factor authentication on critical systems. Documents are encrypted in transit and at rest. Every action is logged.
Questions
Do my clients need to create an account?
Clients access the documents you share with them through a permissioned invitation. You control what each person can see and can revoke access when the work is finished.
Can I see whether a client has uploaded what I asked for?
Yes. Document requests carry a status, so you can see what has arrived and what is outstanding without emailing to ask.
What happens to documents when an engagement ends?
Documents remain in the vault under your retention settings, and access permissions can be revoked independently of storage. Nothing is deleted automatically.
Is there a limit on file types?
SafeVault supports the document types professional firms handle routinely, including financial records, legal agreements, government forms, identity documents and compliance certificates.
How is this different from a shared drive?
A shared drive stores files. A portal governs them. The difference is permissioned access per client, tracked requests, revocable sharing and a complete audit history, none of which a folder provides.
Is there a version built for a specific profession?
Yes. Firms doing recurring client engagement work have a dedicated workspace with engagement tracking, document requests and guided questionnaires. See the provider portal.
Get started
The free plan includes permissioned sharing, encryption, multi-factor authentication and audit history. Firms with recurring client work can arrange provider access directly.