Help centre | Article
Secure document sharing
Send chosen documents to an organisation behind three checks: a unique link, the email it was sent to, and a time-bound access code you give over the phone. Available on Plus.
What it is
Secure document sharing is a stronger version of the compliance passport for sensitive files. Instead of the link alone granting access, the person who opens it must also enter the email address you sent it to and a short access code you give them separately, over the phone. Three things are needed to see the documents, not one, so a forwarded or intercepted link is useless on its own.
Sending a secure share
- Go to Share documents in your dashboard and choose the locked link, protected by an access code. (A quick link with no code is the compliance passport.)
- Tick the documents you want to include. You choose exactly what to share, document by document.
- Enter the recipient email address and, optionally, a name and an organisation label.
- Create the share. Sessional emails the recipient a link, and shows you a six-digit access code once.
- Call the organisation and read them the code. The code is never included in the email.
The access code
The code is six digits and lasts 15 minutes, long enough for a phone call. It is shown to you only once when you create the share, and it is never sent in the email, so seeing the email is not enough to open the documents. If the code expires before the organisation uses it, open the share in your dashboard and generate a fresh code, then read the new one out.
How the organisation opens it
They open the link, enter the email address the link was sent to, and enter the access code you gave them. Once both match, the documents appear and stay available until the link expires or you revoke it. No account is needed on their side.
Control and revocation
You stay in control of every share. Each link expires after seven days, and you can revoke any of them at any time from the same page, which stops access immediately. For safety, a link locks itself after five incorrect attempts, so a fresh code cannot be guessed, and each share records when it was opened.
Important: Sessional does not verify documents
Note