Security
Last updated 30 August 2026
You are asking clients to hand over bank statements and tax records. This page sets out plainly how that material is protected, and is deliberately honest about what we do not yet have.
How documents are stored
- Uploads go to a private storage bucket. There is no public URL for any document.
- Files are reached only through signed links that expire after one hour, generated fresh each time you open a document.
- Access is enforced at the database level, not just in the interface. A request for a file is checked against the workspace that owns the client it belongs to.
- One firm cannot see another firm's documents, even with a valid account.
In transit
Everything is served over HTTPS. Uploads go directly from your client's browser to encrypted storage. Data is encrypted at rest by our infrastructure providers.
Client portals
Clients upload without creating an account, using a unique unguessable link. That link is the credential, so treat it like one: send it to the client, not to a shared mailbox or group chat. If a link is exposed, delete the client record and create a new one to invalidate it.
Your account
- Passwords are stored hashed. Nobody at ClientVault can read yours.
- Password reset links expire after one hour.
- Scheduled jobs that send email are authenticated and cannot be triggered by anyone else.
What we do not have yet
We would rather tell you than let you assume:
- No SOC 2 or ISO 27001 certification. If your firm requires a certified vendor, we are not the right fit today.
- No two-factor authentication on accounts yet. It is on the roadmap.
- No customer-managed encryption keys.
Reporting a vulnerability
If you find a security issue, email support@theclientvault.net with the subject "Security". We will acknowledge within two working days. Please give us a reasonable window to fix it before disclosing it publicly. We will not pursue anyone who reports a genuine issue in good faith.
Keep your own copies
ClientVault is a collection tool, not a system of record. Once you have what you need, file it in whatever you already use for long-term storage.