RequestFlow

Security

How RequestFlow handles client file uploads.

Clients upload documents through private request links without creating accounts.

Your firm can require PINs for sensitive requests, use multi-factor authentication for staff accounts, review upload activity, and download files after scanning.

This page describes product controls available in RequestFlow. It does not make third-party certification claims.

Security controls

ControlWhat it does
Private upload linksEach request has its own client upload link.
Optional PINsSensitive requests can require a PIN before upload.
No client accountsClients do not need RequestFlow logins to send files.
Staff multi-factor authenticationFirm users can protect staff access with multi-factor authentication.
Server-side access checksRequest, file, export, and download actions are checked on the server.
Malware scan before downloadUploads must pass malware scanning before staff can download them.
Short-lived downloadsDownload links are temporary and expire automatically.
Audit historyRequest sends, opens, uploads, downloads, approvals, and reminders are recorded.
Export and delete accessFirms can export files and remove data when needed.

Frequently asked questions

Security documents

Additional pages for firms, clients, and vendor reviews.

Client document collection security | RequestFlow