← Blog
Finance8 min read

Secure file sharing for financial services and fintech

KYC packs, models, board material and deal documents are high-value targets. What changes when your storage provider holds no decryption key.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

The material and the adversaries Financial firms hold identity documents, account data, models, board papers and market-sensitive transaction material. The adversaries are correspondingly diverse: opportunistic fraudsters after KYC packs, targeted attackers after deal information, and insiders with legitimate credentials and no legitimate need.

Why provider key custody is the pivotal control Conventional cloud storage decrypts on demand to provide previews, search and administrative recovery. That means readable copies of client identity documents exist on systems your compliance team has never inspected. Client-side encryption removes the capability rather than restricting its use.

Insider risk is an access-control problem Per-participant key envelopes mean a colleague outside a deal has no cryptographic path to its documents, whatever an administrator clicks or a permission bug allows. Removing a person rotates the remaining envelopes for their spaces and writes the change to an append-only trail. That is a materially stronger control than a permissions review conducted quarterly.

KYC collection without loose attachments Identity documents arriving as email attachments sit in mailboxes for years. Collect them through a protected link that deposits directly into an encrypted space: the client uploads from a browser, the file is encrypted on their device, and no readable copy exists in any mailbox.

Deal rooms without a per-page invoice Diligence needs structured distribution, watermarking, expiry and access reporting. A zero-knowledge workspace provides those on storage-based pricing, with the added property that the operator cannot read the disclosure set. After closing, revoke external links, remove external members to rotate keys, export the trail for the file, and delete the room.

Internal discussion is part of the exposure Deal chatter in a readable chat product is, in aggregate, more sensitive than most individual documents: it contains timelines, valuations and counterparty names. Keeping it in encrypted channels bound to the same key hierarchy as the documents removes a separate readable archive.

Compliance posture, stated plainly We do not hold SOC 2 or ISO 27001 certification today and we publish that on our compliance page. Where your policy requires certification, that constraint is decisive. Where your assessment is about actual technical exposure, an architecture in which the provider holds no key is a stronger control than most certified stacks provide.

Operational checklist 1. Individual identities and passkeys; no shared logins to portals. 2. Deal- and client-scoped encrypted spaces, not one firm-wide drive. 3. Protected links with expiry for every external send. 4. Credentials in an encrypted vault, never in chat. 5. Offboarding as a single action that rotates keys and logs the change. 6. Monthly review of sessions, devices and live external links.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Encrypted on your device · upload in 1 click
Upload