Tax documents are identity-theft kits. Treat them accordingly.
Returns, payroll, bank statements and identity documents pass through accounting firms every season, mostly as email attachments that live forever.
“Client tax files that no provider, and no old mailbox, can read.”
For accountants, bookkeepers, tax advisers and payroll bureaux handling seasonal volumes of sensitive client documents.
Built for confidentiality
Encrypted intake
Clients upload documents through a protected link, encrypted in their own browser, straight into your client space.
One space per client
Per-client keys keep separation cryptographic across hundreds of clients.
Short-lived deliveries
Returning a completed return uses a link that expires within 24 hours at most and can be revoked.
Access record
Who received what and when, exportable, without exposing document contents.
Seasonal staff control
Temporary staff get keys only for the clients they work on, and removal rotates the rest.
Versioning
Draft and final versions retained with a 30-day trash for mistakes.
The seasonal risk pattern
Volume spikes, temporary staff arrive, and clients send scans of everything to whichever address they remember. That combination produces mailboxes full of identity documents that persist for years. Moving intake to encrypted upload links removes the mailbox copy entirely.
Client experience matters
Accounting clients are not technical and will not install anything. A link, a passphrase given by phone, and a browser upload is about the limit of what will be adopted — which is exactly what protected links provide.
Retention discipline
Keep what you must for statutory periods in encrypted client spaces, and let the transient exchanges expire on their own. Deliberate retention beats an accidental archive in a shared inbox.
Frequently asked questions
Can clients send us documents without an account?
+
Yes, through a protected upload link; encryption happens in their browser before anything is transmitted.
Can we keep records for statutory retention?
+
Yes — store them in the client's encrypted space with versioning, and delete deliberately when the period ends.
Can DRIVUNO read the files I transfer?
+
No. Files are encrypted on your device with XChaCha20-Poly1305 before the upload starts, using keys derived locally with Argon2id. Our servers hold ciphertext only, so there is no preview, no scanning and no staff view of your transfer.
Does the recipient need an account?
+
No. They open the link in any browser, type the passphrase you shared separately, and the file is decrypted locally on their machine. Nothing to install, nothing to sign up for.
How long do share links last?
+
Public share links always expire within 24 hours at most, and you can make them shorter, limit the number of views, or revoke them instantly. Expiry is enforced by the system, not by a reminder.
How big can a transfer be?
+
Uploads are chunked, resumable and verified after upload, so multi-gigabyte transfers survive a dropped connection, a closed laptop or a hotel network. You resume instead of starting again.
Is there a free plan?
+
Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can test a real client hand-off before paying anything.
What happens if I lose my password?
+
Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to store offline. That is the same property that keeps anyone else, including us, out of your account.