ISO 27001 & NEN 7510 certified Data resident in Amsterdam & Eindhoven eIDAS-aligned audit trail
Trusted by 340+ regulated institutions in the Benelux

Documents that open for one person only.

DocShare replaces password-protected attachments with a single-use encrypted link. The document is sealed with its own AES-256-GCM key, the key lives in a hardware security module, and it is released only after the recipient passes verification.

No recipient account required Zero-knowledge key custody Evidential audit trail

In production at

The problem

Email was never built to carry a mortgage file.

A password-protected PDF sent over email is protected by two things: a 40-bit-equivalent cipher from 1999, and a password that was almost certainly sent in the next message. Once delivered, the file is out of your control — forwarded, archived on a mail server in an unknown jurisdiction, and readable by anyone who reaches the mailbox.

Uncontrolled distribution

Attachments are copied the moment they land. You cannot revoke them, expire them, or find out who opened them.

No evidence of delivery

Supervisors ask who received a document and when. A sent-items folder is not an answer a regulator accepts.

Passwords in the same channel

The second email with the password defeats the encryption entirely. Everyone knows it; everyone still does it.

Residency you cannot prove

Mail transits providers you did not choose. Under GDPR, "probably in Europe" is not a lawful basis.

How it works

Five steps from sender to sealed document.

The sender uploads once. Everything after that is automatic — and every step is written to a tamper-evident log.

1

The document is sealed at upload

Before the file leaves the sender's browser it is encrypted with a freshly generated 256-bit data key. That key is itself wrapped by a customer-specific master key held in our HSM cluster — envelope encryption, so the plaintext document and the unwrapped key never exist on the same machine at the same time.

AES-256-GCM SHA-256 manifest

2

The recipient receives a link — never the document

An email arrives containing nothing confidential: no attachment, no password, no description of the contents. Just an address on a subdomain reserved for the sending organisation, carrying a single-use reference to the encryption record.

Single-use Expires in 14 days

3

The document loads, blurred

Opening the link shows the document's shape but none of its content — the page count, the layout, the fact that it is genuinely waiting. Nothing readable has been transmitted to the browser yet; the blur is a placeholder rendered from the encrypted manifest, not a filter over readable text.

4

Verification runs before a password is accepted

Pressing Unlock PDF starts a sequence of checks: the transport channel, the integrity of the encryption record, the reputation of the device, and the availability of the key custodian. The password field stays disabled until every check returns green. If one fails, the session ends there — there is nothing to brute-force.

5

The passphrase releases the key, once

The passphrase — agreed out of band, by telephone, in branch, or from a document the recipient already holds — is stretched with Argon2id and used to unwrap the data key inside the HSM. The plaintext key is returned to the recipient's browser for the length of the session and never written to disk on either side.

Argon2id FIPS 140-2 Level 3 HSM

Anatomy of a DocShare link

https://rijnbank.doc-share.online/?encryptionId=6f1a9c84-2e57-4d0b-9c33-af51d7e0b2a9

rijnbank
The sending organisation's reserved subdomain. Certificate-pinned and branded, so the recipient can tell a genuine link from a lookalike.
doc-share.online
Our delivery domain. It serves the viewer application only — never document content, which is fetched separately after verification.
encryptionId
A random version-4 GUID pointing to the encryption record. It is not the key, not a token, and carries no information about the document or the recipient.

What the recipient sees

A short, deliberate wait — and then the file.

The verification sequence is shown to the recipient in full. Nothing happens silently: each check names itself, resolves, and leaves a mark. It takes a few seconds, and those seconds are the difference between "a PDF turned up" and "a document was released to me, and someone can prove it".

Pre-release verification

Shown live in the unlock dialog.

  • Secure channel establishedTLS 1.3, certificate chain pinned to the tenant subdomain
  • Encryption record resolvedThe encryptionId is matched to a live, unexpired share
  • Document integrity verifiedSHA-256 digest compared against the sealed manifest
  • Key custodian reachableHSM partition responds and holds the wrapped data key
Open a demonstration link

Cryptography

Standard primitives, conservatively applied.

We do not invent ciphers. Every algorithm below is published, peer-reviewed and on the approved lists of NIST and the Dutch NCSC. The engineering is in how they are combined, and in who is able to reach the keys.

At rest

AES-256-GCM

Every document is encrypted with its own 256-bit key and a unique 96-bit nonce. GCM gives authenticated encryption, so a modified ciphertext fails to decrypt rather than decrypting to garbage.

In transit

TLS 1.3, HSTS preloaded

Modern cipher suites only, forward secrecy mandatory, TLS 1.0–1.2 and all RSA key-exchange suites disabled. Certificates are issued per tenant subdomain and monitored in Certificate Transparency logs.

Key exchange

RSA-4096 / ECDH P-384

Data keys are wrapped for transport using hybrid key encapsulation. Tenant master keys never leave the HSM boundary in plaintext form, under any operational circumstance.

Passphrase

Argon2id

Recipient passphrases are stretched with Argon2id (m=64 MiB, t=3, p=4) and a per-share salt. The derived value unwraps the key; the passphrase itself is never stored, logged or transmitted in clear.

Key custody

FIPS 140-2 Level 3 HSM

Master keys are generated inside, and never exported from, a tamper-responsive hardware security module cluster operated in two Dutch data centres under dual control.

Integrity

SHA-256 + Ed25519

Each share carries a signed manifest: document digest, page count, sender identity and policy. Any divergence between manifest and ciphertext aborts the release.

Full specification

Symmetric cipher
AES-256-GCM — 256-bit data key, 96-bit nonce, 128-bit authentication tag, unique per document version.
Key wrapping
AES-KW (RFC 3394) against a tenant master key resident in the HSM partition.
Passphrase derivation
Argon2id, 64 MiB memory cost, 3 iterations, 4 lanes, 128-bit random salt stored with the encryption record.
Transport
TLS 1.3 with X25519 key agreement; HSTS max-age=63072000; includeSubDomains; preload.
Manifest signature
Ed25519 over a canonical JSON manifest; public keys published in our trust centre.
Random generation
Hardware entropy from the HSM, mixed into the kernel CSPRNG; no userspace PRNG is used for key material.
Key rotation
Tenant master keys rotate every 90 days; data keys are never reused across documents or versions.
Post-quantum posture
Hybrid X25519 + ML-KEM-768 in limited release for key encapsulation; general availability targeted for 2027.
Read the full security architecture
4.1M
Documents released through DocShare in the past 12 months
340+
Regulated institutions across the Benelux and DACH
99.98%
Viewer availability, measured over rolling 90 days
0
Confirmed disclosures of customer document content since 2016

Our partners

Built alongside the institutions that depend on it.

DocShare is deployed inside banks, insurers, pension administrators and notarial practices. Several of them helped design the verification sequence their own customers now see.

Rijnbank N.V.

Retail & private banking. Mortgage offers, KYC packs and account closure statements.

Partner since 2018

Vondel Verzekeringen

Life and disability insurance. Medical acceptance files and claim determinations.

Partner since 2019

Batavia Bank

Corporate and institutional banking. Syndicated loan documentation and term sheets.

Partner since 2020

Nederlandse Handelsbank

Trade finance. Letters of credit, bills of lading and sanctions screening reports.

Partner since 2017

Zuiderzee Assurantiën

Non-life and marine. Policy schedules, survey reports and settlement offers.

Partner since 2021

Maasstad Pensioenen

Pension administration. Value transfers, UPO statements and divorce settlements.

Partner since 2019

Hollandsche Waarborg

Mortgage guarantee fund. Guarantee certificates and arrears correspondence.

Partner since 2022

De Waal & Partners

Notarial and corporate law. Deeds of transfer, estate files and due diligence rooms.

Partner since 2020

In their words

What changes when documents stop being attachments.

Our complaints about "I never received the mortgage offer" dropped to almost nothing. We can now show exactly when a document was released, and to which verified session.
SM Sanne MeijerHead of Retail Operations, Rijnbank N.V.
The verification sequence is the part customers actually comment on. They see the checks run, and they believe the document is genuinely theirs. That trust is worth more than the cryptography we bought it with.
TV Thijs van DijkCISO, Vondel Verzekeringen
DNB asked us to evidence the confidentiality of outbound client correspondence. We exported eleven months of DocShare audit records and the question was closed in a week.
AB Anneke BosmanCompliance Director, Batavia Bank

Compliance

Evidence, not assurances.

Certification reports, penetration test summaries and our sub-processor register are available under NDA through the trust centre. Every share produces an immutable audit record: who sent it, which checks ran, when the key was released and from which network.

ISO/IEC 27001:2022Certified, annual surveillance audit
NEN 7510Dutch healthcare information security
SOC 2 Type IISecurity, availability, confidentiality
GDPR / AVGEU-only processing, DPA on request
eIDASQualified timestamps on audit records
DORA-readyICT third-party register & exit plan

Questions

The ones security teams ask first.

Can DocShare read our customers' documents?
No. Data keys are wrapped under a tenant master key that lives in an HSM partition your organisation controls, and unwrapping requires a recipient passphrase we never see. Our staff have no operational path to plaintext document content — this is enforced by key custody, not by policy.
What happens if the link is forwarded to someone else?
The link on its own is worthless. Without the out-of-band passphrase the verification sequence completes but the key is never released. Shares can additionally be bound to a single successful release, so a second attempt — even with the correct passphrase — is refused and raises an alert to the sender.
How is the passphrase communicated to the recipient?
Out of band, and never by us in the same channel as the link. Most customers use something the recipient already holds: a customer number, the last four digits of an IBAN, a reference from a previous letter, or a code given by telephone. DocShare can also dispatch a one-time code by SMS to a verified mobile number.
Where is our data stored?
Encrypted documents, metadata, audit records and key material all remain within the Netherlands, in two ISO 27001-certified facilities in Amsterdam and Eindhoven. There is no replication outside the EEA, and no sub-processor with access to ciphertext is established outside the EEA.
What if a verification check fails?
The passphrase field stays disabled and the release is aborted. The recipient is shown which check failed and given a reference number for support. A failed check is logged with full context and, depending on the failure class, notifies the sending organisation's security contact within minutes.
Does the recipient need an account or software?
Neither. The viewer is a standard web application that runs in any current browser on desktop or mobile. There is nothing to install, no registration, and no cookie is set before the recipient acts.
How long does a share stay available?
Fourteen days by default, configurable per template between one hour and ninety days. Expiry destroys the wrapped data key, after which the ciphertext is mathematically unrecoverable — including by us.

Next step

See it from the recipient's side.

Twenty minutes, your own document, your own subdomain. We will send you a real link and walk through the verification sequence together.