The structural conflict in consulting
Agencies and consultancies routinely hold material from clients who compete with each other, under NDAs that promise separation. In most firms that separation is implemented as folders and good intentions inside one suite where every account and the provider itself can technically read everything.
Cryptographic separation instead
Give each engagement its own encrypted space with its own key, sealed individually to the people staffed on it. Separation then survives a misconfigured permission, an over-broad admin action and a curious colleague, because the underlying capability to decrypt simply does not exist outside the team.
Freelancers, the recurring gap
External collaborators are normal and are the most common source of lingering access. The pattern that works:
- Invite them into exactly one engagement space.
- Use protected links, not attachments, for anything they need outside it.
- Remove them the day the statement of work ends, so remaining keys rotate.
- Keep the audit entry; it is what you show the client later.
Deliverables without permanent copies
A final report sent as an attachment lives forever in a dozen mailboxes. A protected link with a passphrase, an expiry and an optional watermark keeps distribution deliberate, and lets you revoke access if a relationship ends badly.
Large creative files
Video, 3D and design files break most secure-sharing workflows, and broken workflows push people to consumer transfer services. Chunked, resumable uploads with verification after upload are what keep the sanctioned path faster than the shortcut.
Turning it into a sales advantage
Legal, healthcare, public-sector and enterprise buyers increasingly send security questionnaires. Being able to answer that your provider cannot read client material, that access is per-engagement, and that you can export an access trail turns a procurement obstacle into a differentiator.
What to have ready
- A one-page description of the architecture in plain language.
- Your vendor's published subprocessors and storage regions.
- An exportable audit trail per engagement.
- A written offboarding procedure with key rotation in it.
A caution about recovery
Zero-knowledge means no vendor can reset a lost password. Store the Recovery Kit for each account offline and verify annually that it still works. In a small agency this is a five-minute annual ritual that prevents the only irreversible failure mode in the whole model.
Try it in one click.
Three private surfaces. Same zero-knowledge architecture.