Offline Secure Share
Sensitive records should not leave your control as email attachments. Offline Secure Share sends a time-boxed, password-protected link to a document held in your vault, and lets you withdraw it the moment the exchange is done.
- Time-boxed links
- Password protected
- Revoke instantly
- Every share logged
- Record or folder per link
- 1Record or folder per link
- Expiry window you choose
- SetExpiry window you choose
- Revocation, before expiry
- Any timeRevocation, before expiry
- Shares written to the audit log
- 100%Shares written to the audit log
Most confidentiality failures are a sharing decision
Data rarely leaks from the vault. It leaks from the copy someone emailed, forwarded and forgot. Offline Secure Share keeps the record where it belongs and gives access a deadline.
Stop sending copies you cannot recall
An email attachment leaves your control the moment it is sent. A share link stays owned by the vault, so access can be withdrawn at any point.
Access that expires on purpose
Every link is time-boxed. Once the window passes, the link is dead and the recipient sees nothing, even if the message is forwarded on.
Evidence you shared it properly
Each link carries a record of who created it, who opened it and when. That record is what a regulator, insurer or client asks for after the event.
Six controls on every link
Each control answers a question you will be asked after an incident: who could open it, for how long, and how do you know.
Expiry window
Set how long the link should live, from a few hours to a defined number of days. Expiry is enforced by the vault, not by the recipient's good behaviour.
Password protection
Protect the link with a password shared through a separate channel, so a forwarded email alone is not enough to open the file.
Instant revocation
Withdraw a link at any time. Access ends immediately, which matters when a deal falls away or a recipient leaves their firm.
Access visibility
See whether a link has been opened, how many times and when, so you know a bundle actually reached the other side.
One record, one link
Share a specific document or folder rather than granting a route into the wider vault. Nothing outside the share is reachable.
Logged against an identity
The person who created the share is recorded in the audit trail alongside every other action in that access window.
Four steps from vault to recipient
Sharing sits inside the access window, so there is never a standing service exposed between sessions.
Open an access window
Authenticate and connect your vault. Sharing happens from inside the File Manager, never from a standing service left running between sessions.
Choose the record and the rules
Select the document or folder, set the expiry window, add a password where the material is sensitive.
Send the link, share the password apart
Send the link by whichever channel suits the relationship, and pass the password separately so the two never travel together.
Watch it, then withdraw it
Check whether it was opened, and revoke the link when the exchange is finished rather than waiting for expiry.
The exchanges that carry the most risk
Regulated firms share the most sensitive material they hold at the least convenient moments. These are the cases we see most.
Legal
Send closed matter files, deeds, wills or evidence bundles to counsel, clients or a new firm without emailing privileged material as an attachment.
See the sector pageAccountancy and audit
Release statutory records and audit evidence to an auditor or regulator for the period they need it, then withdraw access.
See the sector pageBoards and transactions
Share board papers and transaction documents with advisers on a time-boxed basis rather than opening a permanent data room.
See the sector pageFamilies and personal records
Pass identity documents, policies or estate paperwork to a solicitor or family member without leaving them sitting in an inbox.
See the sector pageAttachment against time-boxed link
An attachment is a permanent copy in someone else's estate. A link is access you still own.
Can you withdraw access after sending
- Email attachment
- No
- Offline Secure Share
- Yes, revoke at any time
Does access expire automatically
- Email attachment
- No
- Offline Secure Share
- Yes, on the window you set
Extra credential to open the file
- Email attachment
- Rarely
- Offline Secure Share
- Optional password on every link
Do you know whether it was opened
- Email attachment
- No
- Offline Secure Share
- Yes, access is visible
Copies left on mail servers
- Email attachment
- Yes, on every hop
- Offline Secure Share
- The record stays in the vault
Audit evidence of the disclosure
- Email attachment
- Sent items only
- Offline Secure Share
- Logged against a verified identity
| Question | Email attachment | Offline Secure Share |
|---|---|---|
| Can you withdraw access after sending | No | Yes, revoke at any time |
| Does access expire automatically | No | Yes, on the window you set |
| Extra credential to open the file | Rarely | Optional password on every link |
| Do you know whether it was opened | No | Yes, access is visible |
| Copies left on mail servers | Yes, on every hop | The record stays in the vault |
| Audit evidence of the disclosure | Sent items only | Logged against a verified identity |
Questions about sharing from a vault
What is Offline Secure Share?
It is the sharing capability inside Offline Secure Storage®. You create a time-boxed, password-protected link to a record held in your vault instead of sending a copy as an email attachment.
Does the file leave the vault?
The record stays in the vault as your copy of record. The recipient receives access through the link for as long as you allow it, and that access can be withdrawn.
Can a link be opened after the vault disconnects?
No. Access depends on the vault being reachable, so sharing is used for defined exchanges rather than as a permanent publishing service. Plan the exchange into your access window.
How long can a link last?
You set the window. Short windows are the sensible default for privileged and personal data, and links can be revoked before expiry at any time.
Is the password sent with the link?
No, and it should not be. Share the password through a separate channel, such as a phone call, so a forwarded message alone cannot open the record.
Can I see who opened a shared record?
Yes. Link activity is visible to you, and creation of the share is recorded in the vault audit trail against the identity that made it.
Does this replace a data room?
For most exchanges, yes. A data room is a permanently reachable service. Offline Secure Share gives a defined party a defined window against a record that otherwise sits physically disconnected.
Which products include it?
Sharing is part of the Vault, Storage and Enterprise experience. LUV is a deep cold personal vault with one nominated access day each week, so sharing is planned into that window.
Give your most sensitive exchanges a deadline
We will show you how sharing works against your own filing, and which product fits the volume and access pattern you need.