Anyone working as a broker or trustee knows the scenario well: a client simply sends their salary statement, a copy of their ID, or a completed health questionnaire as an email attachment. Quick, convenient – and often problematic from a security standpoint. Exchanging client data securely is no longer optional; it is part of the duty of care you owe your clients. This article looks at where the risks of email attachments lie, what email encryption can and cannot do – and where a client portal is the more practical solution.
Why Email Attachments Are Risky for Sensitive Documents
On their way from sender to recipient, emails pass through several servers. The connection between these servers is nowadays usually encrypted via TLS – but this is not true end-to-end encryption: once a message reaches a mail server or an inbox, it is typically stored there in plain, readable form. On top of that come some very practical problems. Attachments often remain in the inbox, the sent folder, and in backups indefinitely, without anyone knowing exactly how long or where. A single typo in the address is enough for documents to end up with the wrong person. And once sent, the sender no longer has any control over whether an attachment is forwarded, downloaded, or saved elsewhere.
For the occasional, non-critical message, that may be an acceptable trade-off. Salary statements, ID copies, health data, or contract documents are a different matter – and these are exactly the kinds of documents brokers and trustees exchange on a daily basis.
Email Encryption: What It Can and Cannot Do
There are technical methods for genuinely encrypting emails end-to-end, such as PGP or S/MIME. Both require sender and recipient to exchange keys in advance and configure their email programs accordingly. Among professionals, this is manageable. For the average private client who renews a policy once a year, the effort involved is usually too high in practice – hardly anyone sets up a PGP key just to send a single document.
A common workaround is the password-protected ZIP archive. The problem: if the password is shared by email, SMS, or phone over the same unsecured channel, the security gain is minimal. Anyone able to intercept one message can usually intercept the other. Email encryption is therefore technically possible, but for the recurring exchange of documents with many clients it becomes cumbersome and error-prone – and it does nothing to solve the problem of unlimited storage in the inbox.
The Alternative: A Client Portal with Login and Access Log
Instead of sending documents through various inboxes, the client uploads them directly to a protected portal. Access is tied to a personal login, and the data is stored encrypted and strictly separated by client on servers located in Switzerland. An access log makes it possible to trace who accessed which document and when – something neither a regular email nor an open cloud link can offer.
For the client, the process is simpler than it sounds: a document request checklist shows exactly which items are still missing, a live status replaces the usual follow-up emails, and wherever a confirmation is required, the client can approve it digitally, right there in the portal. For the broker or trustee, the tedious back-and-forth by phone or email falls away – documents are kept organized by dossier in one place, rather than scattered across years of email threads. For a detailed overview of what such a portal offers, see /funktionen.
What Matters in a Client Portal for Document Exchange
Not every portal offers the same level of protection. When it comes to exchanging sensitive client data securely, it is worth checking the following points:
- Access only via a personal login, not through a freely shareable link
- Encryption of the stored documents, not just of the transmission
- Clear separation between clients when several clients and advisors use the same system
- An access log that shows who viewed which document and when
- Hosting in Switzerland, with a provider that operates in compliance with the Swiss Data Protection Act (revDSG)
- An interface that feels familiar to the client and is tailored to your own office, rather than an anonymous third-party system
These points are usually easier to implement with a single tool built specifically for broker and trust offices than by cobbling together several separate solutions – an email program, cloud storage, and a password manager.
finra was built for exactly this day-to-day reality of Swiss broker and trust offices: a secure client portal with its own subdomain, where clients upload documents against a request checklist, track status live, and grant approvals directly in the portal – complete with access logging, encryption, and strict client separation, hosted exclusively in Switzerland. If you would like to try it out in your own office, you can test finra free for 30 days, with no credit card required, at /register.