Secure Alternatives to Email Attachments for Sensitive Documents
Email was never designed to carry confidential files. Five alternatives, ranked by how much control they give you after you press send.
Email attachments have one property that makes them wrong for sensitive documents: the moment they are sent, control is gone. You cannot recall them, you cannot see who opened them, and you do not know where they were forwarded. Here are the alternatives, ranked by the control they leave you with.
5. Password-protected files
Encrypt the PDF or ZIP, send the password by another channel (a text message, a phone call). Better than nothing: an interception of the email alone yields nothing. But still not recallable, still not logged, and in practice the password goes in the next email.
4. Expiring cloud links
Share from a cloud drive with a link that expires and, ideally, a password. Recallable — you can kill the link. Not identity-verified: anyone with the link and password is "the client". Logging is usually coarse.
3. Encrypted email (S/MIME, PGP, provider-level)
Genuinely confidential in transit and at rest — when both sides have it set up, which for clients is rare. Solves interception, not the after-delivery problems.
2. A secure message with verified access
The recipient gets an email saying "you have a message"; they prove who they are (a one-time code to their address) and read it on your system. Withdrawable, logged, verified. Suitable for one-off exchanges.
1. A client portal tied to the matter
The recipient signs in with a one-time code or a password you shared separately, and sees their matter: the documents you chose to share, updates you posted, a place to reply and upload. Every view and download logged. Revocable at any time. Nothing copied anywhere unless they download it. And — the part that matters day to day — new documents appear without another email, and their replies arrive on the matter rather than in an inbox. See the portal model vs the attachment model.
The reverse problem: receiving documents
Clients emailing you their passport, bank statements and medical letters is the same risk in the other direction, and it is usually the larger volume. A file request — a link that lets them upload directly into their matter, encrypted on arrival, with no attachment in anyone's inbox — solves it, and gives you a record of what was received when.
When an attachment is still right
A finished document the recipient needs to keep — the signed contract, the final report. Send it, once, from the matter so the sending is logged, and understand that you have released a copy. The rule of thumb: working documents through the portal; final documents as attachments, deliberately. We cover the privacy-law angle in privacy-compliant file sharing.
The habit that makes it stick
Alternatives fail when they are extra effort. If sharing from the matter is one click and emailing is three, people will share from the matter. Choose the tool where the secure path is the easy path.