Built for the documents that matter most

The mechanism is the same everywhere. What differs is the document, the regulator asking about it, and how the passphrase reaches the recipient.

Retail & private banking

Mortgage offers, credit decisions, KYC packs, account closure statements and arrears correspondence. The passphrase is usually a value the customer already holds — the last four digits of their IBAN, or a reference from a previous letter.

Typical trigger: AFM duty-of-care questions about whether a customer actually received a decision.

Insurance

Medical acceptance files, claim determinations, policy schedules and survey reports. Health data raises the stakes: a misdirected acceptance letter is a reportable breach, not an embarrassment.

Typical trigger: NEN 7510 obligations on the exchange of medical information.

Pensions

Value transfers, UPO statements, divorce settlements and early-retirement calculations. High volume, long retention, and recipients who may not have logged into a portal for a decade.

Typical trigger: portal abandonment — members who will open a link but never create an account.

Notarial & legal practice

Deeds of transfer, estate files, due diligence rooms and privileged correspondence. Professional privilege makes provable confidentiality a duty rather than a preference.

Typical trigger: a file that must demonstrably not have been read by the opposing party.

Healthcare & occupational health

Referral letters, diagnostic reports, and fitness-for-work assessments sent to employers who may see only the conclusion, never the file. Release policies differ per recipient class.

Typical trigger: splitting what the employee sees from what the employer sees.

Public sector

Benefit decisions, tax assessments, permit correspondence and inspection reports. Citizens cannot be required to install anything, and accessibility obligations are not optional.

Typical trigger: WCAG 2.2 AA and the obligation to reach every citizen, not just the digitally confident.

Getting it into your stack

Three ways in, none of them a migration.

Most customers are live in a fortnight. Nobody replaces a core system to start sending documents differently.

Fastest

SMTP relay

Point an existing output stream at our relay. Attachments on matching messages are stripped, sealed and replaced with a share link. No code changes in the sending application at all.

Most common

REST API

Create a share, attach a document, set the policy and let us dispatch — or take the link back and send it yourself. OpenAPI description, idempotency keys, webhooks for every lifecycle event.

For teams

Sender console & Outlook add-in

For correspondence that is composed by hand: a browser console with templates and approval workflow, plus an add-in that seals attachments as the message is sent.

Identity
SAML 2.0 and OIDC single sign-on, SCIM provisioning, group-to-role mapping
Passphrase dispatch
Known-value lookup, SMS one-time code, telephone script, or your own channel via API
Branding
Reserved subdomain, logo, palette and sender footer per business unit
Events
Webhooks for created, dispatched, opened, verified, released, refused, expired, revoked
Archiving
Push release records to your SIEM or archive; native connectors for common Dutch DMS platforms
Languages
Recipient viewer in Dutch, English, German, French and Frisian

Rollout

From first call to first live share.

1

Scoping — week one

Which document streams, which regulator is asking, how the passphrase will reach each recipient class, and who signs off. Usually two workshops of ninety minutes.

2

Tenant provisioning — week one

Your subdomain is reserved, certificates issued, HSM partition created under a witnessed key ceremony, and SSO connected. You receive the ceremony minutes.

3

Pilot — week two

One stream, one team, real documents to internal recipients. We tune the verification copy and the branding until the experience reads as yours rather than ours.

4

Production — week three onward

Phased by volume, with a rollback that is simply "stop routing through the relay". Your security team gets read access to the audit chain from day one.