Your team sends an encrypted link that expires when you decide, asks for a password when it has to and logs every download. You can revoke it in one click. And the file does not end up in someone else's cloud: it stays in the case record and, if you want, triggers the process.
Every transfer records who opened it, when and from where. And it stops the moment you want it to.
When the official channel is no use, people improvise. And what they improvise, you never see.
Public links circulating through email and chats, with no way of knowing who opens them or when they are deleted, on a personal account that has no contract with you.
A server set up by someone who left years ago, with shared accounts, passwords that never change and no useful log on the day it has to be audited.
It goes to whoever autocompleted in the "To" field, gets forwarded without control and sits in the recipient's mailbox forever. Sending to the wrong person is one of the most frequently notified breaches.
An employee's private account or a memory stick in a pocket. When that person leaves, your company's documents leave with them.
For the sender it is as easy as the service they were using. For you, it stops being invisible.
From the browser, from your phone or from the case record itself. The file is encrypted on upload and scanned by antivirus before the link even exists.
Expiry, maximum number of downloads, a password or code for the recipient, view-only, watermarking. Company policy applies itself; it does not depend on everyone remembering.
The recipient downloads without registering. You see who opened it, when and from where, you revoke the link in one click, and the file stays in the case record with its retention period.
As a default for the whole company, or transfer by transfer when the case calls for it.
TLS 1.3 in transit and AES-256 at rest, with keys in an HSM. The data stays in the EU. The technical detail is on the security page.
Hours, days or a single download. Once the deadline passes the link stops existing; it does not keep circulating through forwarded emails.
Recipient verification by email or SMS so the link is worthless if it ends up in the wrong hands. It fits with your SSO and two-factor for internal users.
Every file is scanned before the link is published, in both directions. What comes in through the intake inbox is scanned too.
Block extensions, set size caps, require a mandatory password for certain document types and get a warning when sensitive patterns appear. Every block is logged.
For sensitive documentation: it is viewed in the browser without downloading, with a watermark identifying whoever is looking at it.
Who sent what, to whom, when it was opened and from which IP address. Exportable for an audit, an inspection or an incident.
Sent to the wrong person? One click and the link stops working, even though the email is already in the recipient's inbox.
For the exchanges an FTP server handles between systems today: same controls, same log, without maintaining a server of your own. See integrations.
Half the problem is not sending, it is receiving. Today the paperwork for a new supplier, an insurance claim or a grant application lands in three different mailboxes, in emails with attachments somebody has to download by hand.
With the intake inbox you give them a page with your branding, the third party uploads their files without having an account, and what they upload arrives classified in the right case record. From there it is just another process: it is reviewed, approved, signed and filed.
See an inbox built for your caseWhat changes is not convenience, it is what you can prove afterwards.
| Criterion | Dokuflex secure transfer | Consumer service | In-house FTP | Email attachment |
|---|---|---|---|---|
| Size | Free of the email limit | Capped by plan | High | 25–35 MB |
| Link expiry | You set it, per transfer | Fixed on the free plan | Not applicable | Never: it stays in the mailbox |
| Recipient verification | Password or one-time code | Paid plans only | An account, often shared | None |
| Revoking what you sent | Yes, in one click | Limited | By deleting from the server | No |
| Log of who downloads | Complete and exportable | Partial | Technical logs, barely usable | No |
| Antivirus and content rules | Yes, in both directions | No | Only if you bolt it on | Whatever the mail server does |
| Where the file ends up | In your case record, with retention | In the provider's cloud | In a loose folder | In mailboxes you do not control |
| Triggers a process | Yes, it is a step in the workflow | No | With custom scripts | No |
A transfer tool leaves the file in its own cloud. Here the file is already where it will be needed.
What lands in the inbox creates the case record and launches the Dokuflex BPM workflow: review, approval and next step, with deadlines and owners.
The report, the contract or the payroll batch is generated and sent as a secure link when a condition is met. Nobody prepares transfers by hand.
If you have to prove the sending, certified email adds the evidence certificate; if you need agreement, eIDAS electronic signature runs in the same workflow.
Dokuflex AI reads the document that arrives, classifies it, extracts its data and creates a validation task when confidence falls below the threshold.
An auditor does not ask whether you have a tool. They ask how information leaves the company, who has downloaded it and with what measures in place. An encrypted channel with access control and an exportable log answers all three questions with data.
Every reference is linked to its official source. This page is not legal advice: compliance also depends on your policies and on how you use the tool.
Requires technical and organisational measures appropriate to the risk, and expressly names encryption and the ability to ensure ongoing confidentiality and integrity. Sending documentation containing personal data through a consumer service is hard to defend against that yardstick. And if things go wrong, the 72-hour breach workflow is the next step.
Its risk-management measures include policies on cryptography and encryption, security in acquisition and the use of secure communications. For entities in scope, the channel files leave through is part of the perimeter. See also NIS2 and DORA incident notification.
In Spain, for anyone working with the public sector, the measures protecting communications and information require encryption, access control and traceability. Dokuflex is certified at MEDIUM category; the ENS document management system sets out the detail.
For financial entities, it requires protecting data in transit and at rest and governing ICT third-party providers. A corporate channel with a contract, a DPA and an audit log is the exact opposite of every team picking its own service.
Dokuflex secure file transfer covers what is expected of a managed file transfer solution: TLS 1.3 and AES-256 encryption, recipient authentication, expiry and a download limit, antivirus, content rules, an exportable audit log and hosting in the European Union. It replaces consumer services, legacy FTP servers and email attachments in companies that need to prove how their information leaves the building.
Against a consumer service it brings control and traceability: immediate revocation, recipient verification, retention defined by document type and a data processing agreement. Against an in-house FTP it removes the server you have to patch, the shared accounts and the logs nobody knows how to read, while keeping system-to-system exchange over SFTP and an API. We set it out in detail in the guide to dropping WeTransfer at work.
The intake inbox lets third parties upload documentation without having an account, with antivirus and content rules applied on the way in. What arrives is classified with AI, filed in the case record and can start a supplier onboarding, KYC, claims or invoice approval process inside the same BPM platform.
It is a corporate channel for sending and receiving files with encryption, access control and traceability. The difference from a consumer service such as WeTransfer is control: you decide how long the link lasts, how many downloads it allows, whether it asks for a password or a code, who can open it and from where; you can revoke it at any time and every access is logged. On top of that the file stays in your case record, not in the cloud of a third party you have no contract with.
No. They get a link and download it from the browser. If you switch verification on, they are asked for a password or a one-time code sent to their email or mobile, but there is no registration and nothing to install.
The transfer does not go through email, so it is not affected by attachment limits (25 MB in Gmail, 35 MB by default in Exchange Online). The maximum size per transfer and the total storage are set by your plan; for high volumes or system-to-system transfers you use SFTP or the API instead of the browser.
Yes. The audit log records every opening and download with date, time and IP address, and you can be notified when it happens. If you also need to prove to a third party that you sent something and what it contained, combine it with certified email, which adds the evidence certificate.
Yes, with content rules. You can block file extensions, cap the size, require certain document types to always go out with a password and a short expiry, and warn or block when a file contains sensitive patterns. Every blocked attempt is logged so you can review it.
Yes. The intake inbox is a page with your branding where a third party uploads documents without having an account. What they upload is classified, filed in the right case record and can start a process: supplier onboarding, a KYC file, an insurance claim, an application or a complaint.
It helps with the part it covers. Article 32 of the GDPR requires appropriate technical measures such as encryption and the ability to ensure confidentiality; the NIS2 Directive asks for policies on cryptography and the use of secure communications among its risk-management measures; in Spain, the ENS requires protecting communications and leaving traceability for public-sector work. An encrypted channel with access control and an audit log is direct evidence of those measures. Overall compliance also depends on your policies and on how you use it.
On Dokuflex infrastructure in the European Union (Frankfurt, Madrid and Ireland), with TLS 1.3 encryption in transit and AES-256 at rest. For regulated sectors there is a dedicated private cloud or on-premise option. The detail is on the security page.
Create your account and send your first link with expiry and an audit log today. Or book 20 minutes and we build the channel and the intake inbox for your real case with you.