Can DocShare read our customers' documents?
No. Data keys are wrapped under a tenant master key that lives in an HSM partition your organisation controls, and unwrapping requires a recipient passphrase we never see. Our staff have no operational path to plaintext document content — this is enforced by key custody, not by policy.
What happens if the link is forwarded to someone else?
The link on its own is worthless. Without the out-of-band passphrase the verification sequence completes but the key is never released. Shares can additionally be bound to a single successful release, so a second attempt — even with the correct passphrase — is refused and raises an alert to the sender.
How is the passphrase communicated to the recipient?
Out of band, and never by us in the same channel as the link. Most customers use something the recipient already holds: a customer number, the last four digits of an IBAN, a reference from a previous letter, or a code given by telephone. DocShare can also dispatch a one-time code by SMS to a verified mobile number.
Where is our data stored?
Encrypted documents, metadata, audit records and key material all remain within the Netherlands, in two ISO 27001-certified facilities in Amsterdam and Eindhoven. There is no replication outside the EEA, and no sub-processor with access to ciphertext is established outside the EEA.
What if a verification check fails?
The passphrase field stays disabled and the release is aborted. The recipient is shown which check failed and given a reference number for support. A failed check is logged with full context and, depending on the failure class, notifies the sending organisation's security contact within minutes.
Does the recipient need an account or software?
Neither. The viewer is a standard web application that runs in any current browser on desktop or mobile. There is nothing to install, no registration, and no cookie is set before the recipient acts.
How long does a share stay available?
Fourteen days by default, configurable per template between one hour and ninety days. Expiry destroys the wrapped data key, after which the ciphertext is mathematically unrecoverable — including by us.