Seven steps for accountants, auditors and advisers who send confidential files to clients every week, with a quick triage test, a side-by-side of attachments against encrypted links, a sample cover email, and the mistakes that undo the whole effort.
To send sensitive documents securely in 2026, stop attaching them. Upload the file to a service that encrypts it at rest and in transit, share a link on your own domain instead of the file itself, give the link an expiry date and a password where the content warrants it, send that password through a different channel, and keep the access log so you can show later who opened what. Alkmist Share Space, the secure file sharing product from the team behind Pidgy, does all of that in one flow with AES-256 encryption, links up to 5 GB, EU hosting and ISO 27001 certification. The steps below work whatever tool you use.
Three questions sort the everyday PDF from the file that should never travel as an attachment. Answer yes to any one of them and go to the steps.
Financial statements before publication, payroll, shareholder agreements, anything with personal data. An attachment sits unencrypted at rest in every mailbox it touches, and IBM's 2025 Cost of a Data Breach report puts phishing through the inbox as the most frequent way in.
Regulated work, disputes and anything an auditor could ask about. Email records that a message was sent and nothing else. You cannot show whether the file was viewed, downloaded or forwarded.
Gmail rejects attachments above 25 MB and Outlook stops around 20 MB. Files that bounce end up on consumer transfer sites and personal drives, which is where most of the accidental exposure happens.
The same IBM report puts the average breach at 4.44 million dollars worldwide and 6.24 million in the Benelux. A single misdirected attachment is enough to start that clock.
The steps take under two minutes once the tool is set up. Most of the time goes into step one, deciding what the document is.
Three buckets are enough. Public or harmless, confidential, and confidential with personal or price-sensitive data. The first can go by email. The other two get a link, and the third also gets a password.
Transport encryption protects the file on the way. It does nothing once the file is stored. Look for AES-256 at rest and in transit, and for hosting in a jurisdiction your engagement letter allows. Alkmist stores files in the EU.
A link means the document stays in one controlled place rather than being copied into every inbox. A link that carries your firm's branding is also one the client will recognise and open, where a random consumer URL makes them hesitate or, worse, forward it around asking whether it is legitimate.
A signed set of accounts the client needs to download once can expire in 7 days. A working folder for an engagement might need 30. Alkmist Share Space offers 7 days, 30 days or indefinite, and indefinite should be a deliberate choice, not the default you forgot to change.
A password in the same email as the link protects nothing. Text it, say it on the phone, or put it in the client's portal. The extra thirty seconds is the difference between a locked door and an open one.
A read receipt tells you the document was opened, which ends the "did you get it?" email. When the engagement closes, revoke the link. There is no reason for last year's payroll file to stay reachable in perpetuity.
The value of the audit trail arrives months later when someone asks who saw a document and when. Alkmist logs every create, view, download and revoke with timestamps and IP addresses, and exports a compliance-ready report in one click.
The same six questions from the triage and the steps, answered for each way of sending.
| Question | Encrypted link (Alkmist Share Space) | Email attachment |
|---|---|---|
| Is the file protected once it has been delivered? | Yes, AES-256 at rest and in transit | No, it sits in plain form in each mailbox |
| Can you take it back after sending? | Yes, expire or revoke at any time | No |
| How large can the file be? | Up to 5 GB per file | 25 MB in Gmail, around 20 MB in Outlook |
| Can you prove who opened it? | Yes, read receipts and a full activity log | No record beyond "sent" |
| What does the client see? | A download page on your domain, no account needed | A familiar attachment, until it bounces |
| Where does the data live? | EU-hosted, ISO 27001, GDPR-aligned, never used to train AI | Wherever each recipient's mail is stored |
The link does the security. The email around it decides whether the client opens it without a phone call.
"Hi Marc, attached is the zip with the signed FY25 statements. The password is Statements2025. Let me know if it does not open. Anna"
The file and its password now sit together in Marc's inbox, in his sent folder when he forwards it to the board, and in whatever backup his provider keeps. There is no expiry and no log.
"Hi Marc, the signed FY25 statements are ready. I have put them on our secure link rather than attaching them, so you will see a page on our domain asking for a password. I will text you that now. The link closes in 7 days, so tell me if you need it reopened. Anna"
Marc knows what to expect, why there is a password, where it will come from and how long he has. Anna gets a read receipt when he opens it and a log entry she can export later.
Each of these shows up regularly in firms that already own a secure sharing tool. The tool is fine. The habit is the problem.
Anyone who can read the email can open the file. Send the password by text or phone every time, even when it feels like overkill.
A link that never closes is an attachment with extra steps. Pick 7 or 30 days unless there is a stated reason not to.
The moment a file bounces, someone reaches for the consumer tool they use at home. With a 5 GB ceiling on Alkmist links there is no size that needs the workaround.
It scrambles the contents, and that is all. No expiry, no revoke, no record of who opened it, and the password usually travels in the same email.
Alkmist is the secure file sharing product from the same team as Pidgy. It covers all seven steps in one drag-and-drop flow.
You drop a file in, it is encrypted with AES-256, and the client receives a link to a download page on your own domain, with no account to create. Expiry, password, read receipts, revoke and the exportable activity log are all settings on that one link, and files go up to 5 GB. If your team likes WeTransfer for its simplicity, the sending experience is the same, only on your brand, EU-hosted, ISO 27001 certified, and never used to train AI.
More guides on moving confidential client work out of the inbox.
Alkmist Share Space encrypts the file, puts the link on your domain, adds expiry, passwords and a full access log, and handles files up to 5 GB. Request access to try it.