Accountants

How to Request Documents From Clients Securely

August 13, 2026

Almost every professional services firm collects sensitive client documents, and most of them do it by email, knowing it isn't the right answer. The reason isn't ignorance — it's that the secure alternatives usually ask something of the client, and a system clients won't use produces worse security than the insecure one they will.

What's actually wrong with email

  • Attachments persist indefinitely in both mailboxes, and in any backup either party keeps, long after the engagement ends.
  • Documents pass through mail servers you don't control and can't audit.
  • There's no access control — anyone who later gains access to either mailbox has everything.
  • A misaddressed email sends a client's Social Security number to a stranger, and there's no recall.
  • There's no record of what was requested versus what arrived, which matters in a dispute.

The options, honestly assessed

  • Encrypted email: better than plain email, but the encryption usually depends on the client doing something, and it inherits every retention problem of email.
  • Cloud storage links (Dropbox, Google Drive): fine for delivering documents to clients, poor for collecting from them — permissions get set wrong, and files sit in a shared drive indefinitely.
  • Client portals: strong on access control and auditability, weak on adoption. Every portal requires the client to create an account, which is where most drop-off occurs.
  • Dedicated collection tools: encrypted upload without a client account. Narrower in scope than a portal, and the least friction for the client.

The adoption problem is a security problem

This is the part firms underweight. A portal with excellent security that a third of clients won't use doesn't produce a third less risk — it produces a mixed environment where those clients email their documents anyway, and now you have sensitive material in two places instead of one. Measured across the whole client base, a slightly simpler system everyone uses often beats a stronger system with partial adoption.

That's the case for removing the account-creation step: not that logins are inherently bad, but that every step between the request and the upload is a point where a client falls back to email.

Retention is the other half

Secure transmission gets most of the attention and solves half the problem. The other half is how long the documents sit afterward. A firm that collects documents through an encrypted portal and then keeps every client's identity documents and bank statements there for six years has moved the risk rather than reduced it — the largest exposure in most firms is accumulated storage, not the moment of transfer.

  • Download what you need into your working file, then stop relying on the collection tool as storage.
  • Set a defined deletion window for raw client uploads, separate from your work-product retention policy.
  • Automate the deletion — a policy that depends on someone remembering will not hold across a busy season.

A practical standard

For most small firms, a workable bar is: documents are requested through a structured checklist rather than an open-ended email, uploads are encrypted in transit, clients don't need an account, and raw uploads are deleted automatically once the engagement closes. ClientBrief is built to that shape — checklist-based requests, no client login, and automatic deletion seven days after an engagement is marked complete — which is why firms use it for intake specifically rather than as a document store.

Try ClientBrief free for 14 days — no credit card required.