How to evaluate a secure document upload portal: 15 questions
A 15-question buyer checklist for evaluating document intake, access, deletion, providers and security claims.
A secure document upload portal should give you credible answers about the whole document lifecycle: what the sender sees, how files are checked, who can review them, where copies exist and how deletion works. Encryption matters, but a padlock icon and a claim of "bank-level security" do not answer those questions.
Use the 15 questions below in a vendor call, security review or trial. Write down the answer and the evidence provided. A public security page, contract term or technical document is more useful than an unsupported "yes" from a salesperson.
The NCSC guidance on choosing a cloud provider makes the same distinction: confidence comes from evidence about how controls are implemented and what an assurance review actually covers, not from a certification name on its own.
First decide what the portal may receive
List the documents, people and countries in the proposed workflow before comparing products. A service suitable for ordinary business forms may not be approved for health records, children's information, criminal-conviction data, payment-card data or government material.
Also decide whether the portal is temporary intake or the official record. Those are different jobs. A temporary portal should help a team receive, review and delete files. A permanent archive needs record classification, long retention, legal holds, export, preservation and recovery controls that an intake product may not provide.
The 15-question evaluation sheet
1. Which data categories are allowed?
Ask for an explicit permitted-use statement and prohibited-data list. Compare it with the documents in your process. "Personal data supported" is too broad to be useful.
Look for separate treatment of special-category data, criminal records, children's data, biometric identifiers, credentials, payment-card data and regulated sector records. If a provider requires a written agreement or different plan for a category, complete that step before sending the data.
2. What does the sender see before uploading?
The page should identify the collecting organisation, explain the purpose, state who can review the files and show the expected deletion timing. It should link to the collector's privacy information rather than suggesting that the software provider decides the collector's lawful basis.
The portal cannot repair a missing notice after collection. Check whether you can present the right information at the point where a sender chooses a file.
3. Does the sender need an account?
An account can strengthen authentication, but it also adds friction and more personal data. Account-free intake may be appropriate when the sender is already known through another process.
Do not confuse possession of an upload link or access to an email address with identity verification. Ask how your own process will verify identity when that is required.
4. How are upload links and email addresses protected?
Ask whether links are guessable, whether pages can be indexed, how abuse is rate limited and whether an address can be changed after exposure. If the service offers email intake, ask how it validates the intended workspace and deals with spoofing, unsolicited mail and oversized attachments.
Email is useful as a fallback, but the portal cannot remove copies from a sender's Sent folder, mail provider or backups.
5. Which files are accepted, and what happens before review?
Ask about file type, size and quantity limits. Then ask how the service checks the actual content rather than trusting the filename extension.
Useful controls include quarantine, format validation, malware scanning and safe preview generation. None detects every malicious or deceptive file. The provider should state that limitation plainly and explain what happens when a file fails.
The NIST bulletin on exchanging files over the internet recommends evaluating the protection offered by the exchange method and the risks of storing files with a third party. It is a useful baseline for this part of the review.
6. Is data encrypted in transit and at rest?
Ask which connections use transport encryption and which stored objects are encrypted. Find out whether backups, previews and temporary processing files receive equivalent protection.
Encryption does not answer who holds the keys or which application and provider personnel can access plaintext during normal processing. Ask those questions separately.
7. Where is each kind of data stored and processed?
Request countries for document content, account records, logs, backups, email processing and support access. A product may advertise one storage region while authentication or operational metadata is processed elsewhere.
Ask which legal entity provides the service and which transfer mechanism applies when personal data crosses relevant borders. Your privacy or legal adviser should assess whether the answer fits your use case.
8. Which subprocessors receive customer data?
The provider should publish the companies involved, their purpose, relevant data, processing location and change process. Check the data processing agreement for notice of new subprocessors and the available response if you object.
Do not assume every supplier sees document contents. Ask the provider to distinguish content storage, transactional email, billing, monitoring and other operational roles.
9. Can access follow the work people actually do?
Check whether each person has a named account and whether administrative actions are separated from ordinary review. Ask who can invite members, read documents, print, download originals, change deletion dates and delete submissions.
If every member has every permission, the team will need a smaller member list and stronger operating rules. Use the least-privilege checklist to test the available model.
10. What authentication and session controls are available?
Ask about password storage, two-step verification, session expiry, device or login alerts and account recovery. Two-step verification should be available to the people who can reach documents or administer the workspace.
Also ask what an attacker needs to reset an account. Strong sign-in controls lose value if support can bypass them through a weak recovery process.
11. Can reviewers work without downloading originals?
A browser viewer may reduce working copies on laptops and shared drives. Confirm whether it sends the original file to the browser or renders a separate preview.
No viewer can guarantee that a visible document will not be copied. Screenshots, photographs, printing and transcription remain possible. The provider should describe view-only access as copy reduction, not copy prevention.
12. What does the audit trail record?
Look for sign-in, viewing, printing, original download, permission change, retention change and deletion events. Ask who can see the log, how long it remains and whether timestamps can be exported when needed.
The log should avoid exposing more document content than necessary. A filename, subject line or preview can itself reveal sensitive information. Ask whether the audit trail records the action without repeating document contents.
13. How does deletion work?
Ask whether every submission gets a deletion date at intake, who can change it and whether the customer can delete earlier. Get separate answers for active originals, generated previews, temporary files, logs and backups.
"Deleted immediately" often describes only the active copy. A candid answer identifies protected backup residuals and their expiry cycle. It should also explain what happens after cancellation, failed payment or account deletion.
14. Can you retrieve records before deletion or switching?
Temporary intake still needs a controlled handoff. Ask how an authorised person retrieves an original that must enter the official record, what the export contains and what becomes unavailable after expiry.
Downloading everything by default defeats temporary intake. The useful feature is a deliberate, authorised exception before the deadline, followed by deletion of the intake copy.
15. What happens during an incident or service failure?
Ask how the provider detects incidents, contacts customers, supplies available facts and restores service. Review the contract and DPA rather than relying on a generic status-page promise.
Ask for the vulnerability-reporting route too. The NCSC lightweight cloud assessment includes vulnerability disclosure, authentication, data location and transparent security information among its practical checks.
Score evidence, not confidence words
Copy the questions into a sheet and add four columns:
| Field | What to record |
|---|---|
| Answer | The provider's specific response |
| Evidence | Public page, contract clause, DPA, test result or audit scope |
| Gap | What remains unknown or unsupported |
| Decision | Accept, mitigate, contractually clarify or reject |
Mark a question unresolved when the provider gives only a broad adjective such as "military-grade", "fully compliant" or "zero risk". Those phrases do not identify a control, boundary or piece of evidence.
Sunset Docs publishes its current measures and limitations on its Security page, identifies providers on its Subprocessors page and provides a Data Processing Addendum. It is designed for temporary document intake. It is not an identity-verification service, electronic-signature service, backup or permanent legal archive. Its default prohibited-data categories still apply even when a workspace has strict access settings.
For a direct comparison with attachment-based intake, read secure file upload portal vs email attachments.
Frequently asked questions
Does ISO 27001 or SOC 2 prove that a portal is secure?
No single certification proves that a service is suitable for your documents. Check the scope, date, system, locations and controls covered. Ask what was independently tested and whether the report covers the product configuration you will use.
Is encryption enough?
No. Encryption protects particular paths and stored data, but the service still needs authentication, access control, secure processing, monitoring, retention and incident procedures. Your team also needs a lawful and narrow collection process.
Should a portal offer email intake?
It can be a practical fallback. Keep notifications and subjects free of sensitive detail, and tell senders that email may leave external copies beyond the portal's control.
Must the provider store data in our country?
That depends on your contracts, applicable law, customer commitments and risk assessment. Ask for every processing location and transfer mechanism, then assess the complete answer rather than one advertised region.
Can a portal verify that a document is genuine?
Not unless it provides a separate, clearly defined verification service. Malware scanning and format validation do not establish the sender's identity, the document's accuracy or whether it has been altered before upload.
What should stop the purchase?
Stop when the provider will not identify where data goes, cannot explain deletion, hides prohibited-data boundaries, lacks an acceptable contract for processor duties or cannot support the access model your workflow needs. A missing feature can sometimes be mitigated. An unknown data flow cannot be assessed.