Previously head of customer output at a Dutch retail bank. Sits on the Dutch Payments Association working group for secure customer correspondence.
We build one thing, carefully
DocShare has done exactly one job since 2016: move a confidential document from an organisation to a person, and be able to prove it afterwards.
Origin
It started with a misdirected mortgage file.
In 2015 two of our founders were working on the output platform of a Dutch retail bank. A mortgage adviser sent a complete customer file — income statements, medical questionnaire, valuation — to the wrong address in the autocomplete list. The attachment was password-protected. The password was in the following message.
The bank did what banks do: a policy was written, training was mandated, and eight months later it happened again. The problem was never discipline. It was that the tool everyone had was a tool for sending letters, and it was being used to send vaults.
DocShare was incorporated in Amsterdam in February 2016. Our first customer was that same bank's successor department. We have stayed narrow on purpose: no e-signing, no collaboration suite, no AI summarisation of documents we have deliberately made ourselves unable to read.
At a glance
Principles
Four commitments we have turned down revenue over.
We will not be able to read your documents
Every feature request that would require plaintext access has been declined, including full-text search, content classification and automated redaction. The inability is the product.
Nothing leaves the Netherlands
We have lost tenders by refusing to run a US region. Ciphertext, keys, logs, backups and support access all stay inside Dutch borders, and we would rather say no than qualify that sentence.
The recipient is a person, not a lead
No tracking pixels, no analytics before consent, no marketing to people who merely received a document. A recipient's address is used to deliver one link and is then the sender's data, not ours.
We publish our limits
Our security page lists what DocShare deliberately cannot do alongside what it can. A vendor who claims to prevent screenshots is a vendor who has stopped telling you the truth.
Leadership
Who is accountable.
Security incidents, regulatory correspondence and customer escalations reach named people, not a queue.
Cryptographic engineering, formerly at a European HSM manufacturer. Responsible for the algorithm suite, key ceremonies and the audit chain design.
Owns certification, penetration testing, the bug bounty and incident response. Reachable directly at security@doc-share.online.
Partners
Designed with the institutions that use it.
Eight organisations sit on our customer architecture council and review every change to the recipient experience before it ships.