Security
How RequestFlow handles client file uploads.
Clients upload documents through private request links without creating accounts.
Your firm can require PINs for sensitive requests, use multi-factor authentication for staff accounts, review upload activity, and download files after scanning.
This page describes product controls available in RequestFlow. It does not make third-party certification claims.Security controls
Frequently asked questions
No. Clients use the private upload link from your request and can send files without creating a RequestFlow account.
Yes. Sensitive requests can require a PIN before the client can open the upload page.
Yes. Uploads must pass malware scanning before firm users can download or review the file.
Yes. Firm users can protect staff access with multi-factor authentication.
No. This page describes product controls available in RequestFlow and does not make third-party certification claims.
Request sends, opens, uploads, downloads, approvals, reminders, and replacement activity are recorded in audit history.
Security documents
Additional pages for firms, clients, and vendor reviews.
Processing roles and safeguards.
SubprocessorsHosting, storage, email, billing, monitoring, and support providers.
Data retentionHow files, exports, logs, billing records, support grants, and deleted organizations are handled.
Support accessHow customer-approved support access works.
Acceptable useProduct boundaries and abuse reporting.
Security contactResponsible disclosure and urgent security questions.
RequestFlow