Secure document sharing

How to Send Sensitive Documents Securely in 2026, Step by Step

Seven steps for accountants, auditors and advisers who send confidential files to clients every week, with a quick triage test, a side-by-side of attachments against encrypted links, a sample cover email, and the mistakes that undo the whole effort.

Last updated September 20269 min readBy the Pidgy team
Request access More about the product Trusted by 8,000+ professionals. ISO 27001, GDPR, EU-hosted.

The short version

To send sensitive documents securely in 2026, stop attaching them. Upload the file to a service that encrypts it at rest and in transit, share a link on your own domain instead of the file itself, give the link an expiry date and a password where the content warrants it, send that password through a different channel, and keep the access log so you can show later who opened what. Alkmist Share Space, the secure file sharing product from the team behind Pidgy, does all of that in one flow with AES-256 encryption, links up to 5 GB, EU hosting and ISO 27001 certification. The steps below work whatever tool you use.

First, decide whether the document needs more than email

Three questions sort the everyday PDF from the file that should never travel as an attachment. Answer yes to any one of them and go to the steps.

Would the client be harmed if a stranger read it?

Financial statements before publication, payroll, shareholder agreements, anything with personal data. An attachment sits unencrypted at rest in every mailbox it touches, and IBM's 2025 Cost of a Data Breach report puts phishing through the inbox as the most frequent way in.

Might you need to prove later who opened it?

Regulated work, disputes and anything an auditor could ask about. Email records that a message was sent and nothing else. You cannot show whether the file was viewed, downloaded or forwarded.

Is it larger than 20 MB?

Gmail rejects attachments above 25 MB and Outlook stops around 20 MB. Files that bounce end up on consumer transfer sites and personal drives, which is where most of the accidental exposure happens.

What a mistake costs

The same IBM report puts the average breach at 4.44 million dollars worldwide and 6.24 million in the Benelux. A single misdirected attachment is enough to start that clock.

Seven steps to send sensitive documents securely

The steps take under two minutes once the tool is set up. Most of the time goes into step one, deciding what the document is.

1

Sort the file by how much damage it could do

Three buckets are enough. Public or harmless, confidential, and confidential with personal or price-sensitive data. The first can go by email. The other two get a link, and the third also gets a password.

2

Upload it somewhere that encrypts at rest, not only in transit

Transport encryption protects the file on the way. It does nothing once the file is stored. Look for AES-256 at rest and in transit, and for hosting in a jurisdiction your engagement letter allows. Alkmist stores files in the EU.

3

Share a link on your own domain instead of the file

A link means the document stays in one controlled place rather than being copied into every inbox. A link that carries your firm's branding is also one the client will recognise and open, where a random consumer URL makes them hesitate or, worse, forward it around asking whether it is legitimate.

4

Set an expiry that matches the job

A signed set of accounts the client needs to download once can expire in 7 days. A working folder for an engagement might need 30. Alkmist Share Space offers 7 days, 30 days or indefinite, and indefinite should be a deliberate choice, not the default you forgot to change.

5

Add a password for the top bucket, and send it another way

A password in the same email as the link protects nothing. Text it, say it on the phone, or put it in the client's portal. The extra thirty seconds is the difference between a locked door and an open one.

6

Watch for the read receipt, then revoke when the job is done

A read receipt tells you the document was opened, which ends the "did you get it?" email. When the engagement closes, revoke the link. There is no reason for last year's payroll file to stay reachable in perpetuity.

7

Keep the log, and know how to export it

The value of the audit trail arrives months later when someone asks who saw a document and when. Alkmist logs every create, view, download and revoke with timestamps and IP addresses, and exports a compliance-ready report in one click.

Email attachment against encrypted link, side by side

The same six questions from the triage and the steps, answered for each way of sending.

QuestionEncrypted link (Alkmist Share Space)Email attachment
Is the file protected once it has been delivered?
Yes, AES-256 at rest and in transit
No, it sits in plain form in each mailbox
Can you take it back after sending?
Yes, expire or revoke at any time
No
How large can the file be?
Up to 5 GB per file
25 MB in Gmail, around 20 MB in Outlook
Can you prove who opened it?
Yes, read receipts and a full activity log
No record beyond "sent"
What does the client see?
A download page on your domain, no account needed
A familiar attachment, until it bounces
Where does the data live?
EU-hosted, ISO 27001, GDPR-aligned, never used to train AI
Wherever each recipient's mail is stored
CoveredPartly, or depends on the recipientNot covered

A worked example, the cover email that goes with a secure link

The link does the security. The email around it decides whether the client opens it without a phone call.

What not to send

Attachment plus password, same message

"Hi Marc, attached is the zip with the signed FY25 statements. The password is Statements2025. Let me know if it does not open. Anna"

The file and its password now sit together in Marc's inbox, in his sent folder when he forwards it to the board, and in whatever backup his provider keeps. There is no expiry and no log.

What to send instead

Branded link, password by text, expiry stated

"Hi Marc, the signed FY25 statements are ready. I have put them on our secure link rather than attaching them, so you will see a page on our domain asking for a password. I will text you that now. The link closes in 7 days, so tell me if you need it reopened. Anna"

Marc knows what to expect, why there is a password, where it will come from and how long he has. Anna gets a read receipt when he opens it and a log entry she can export later.

Mistakes that undo a secure send

Each of these shows up regularly in firms that already own a secure sharing tool. The tool is fine. The habit is the problem.

Password in the same email as the link

Anyone who can read the email can open the file. Send the password by text or phone every time, even when it feels like overkill.

Leaving expiry on indefinite

A link that never closes is an attachment with extra steps. Pick 7 or 30 days unless there is a stated reason not to.

Falling back to a personal transfer account

The moment a file bounces, someone reaches for the consumer tool they use at home. With a 5 GB ceiling on Alkmist links there is no size that needs the workaround.

Relying on a password-protected zip

It scrambles the contents, and that is all. No expiry, no revoke, no record of who opened it, and the password usually travels in the same email.

Where Alkmist Share Space fits

Alkmist is the secure file sharing product from the same team as Pidgy. It covers all seven steps in one drag-and-drop flow.

You drop a file in, it is encrypted with AES-256, and the client receives a link to a download page on your own domain, with no account to create. Expiry, password, read receipts, revoke and the exportable activity log are all settings on that one link, and files go up to 5 GB. If your team likes WeTransfer for its simplicity, the sending experience is the same, only on your brand, EU-hosted, ISO 27001 certified, and never used to train AI.

Alkmist secure sharing in numbers

5 GB
per file, against Gmail's 25 MB limit
AES-256
encryption in transit and at rest
0
client accounts required to download or upload
ISO
27001 certified, GDPR-aligned, EU-hosted

Questions people ask about sending confidential files

What is the safest way to send a confidential document to a client?
Upload it to a service that encrypts it at rest and in transit, share a link on your own domain instead of an attachment, set an expiry, add a password for the most sensitive files and send that password by a separate channel. Alkmist Share Space does this with AES-256 encryption, EU hosting and a full access log.
Should I put a password on a PDF before emailing it?
It is better than nothing and much worse than a link. A password-protected PDF cannot be expired, revoked or tracked, and the password usually ends up in the same thread. Use it only for the lowest-risk files, and use an encrypted link for anything you would not want forwarded.
How long should a secure file link stay open?
As long as the job needs and no longer. Seven days suits a document the client downloads once, thirty days suits a live engagement, and indefinite should be a conscious exception. Alkmist offers exactly those three settings and lets you revoke early at any time.
Can I stop someone opening a document after I have already sent it?
With an email attachment, no. With a shared link, yes, because the file lives in one place you control. In Alkmist you revoke the link and any further attempt to open it fails, whether or not the client had already viewed it.
Is WeTransfer safe enough for client documents?
For casual transfers it is convenient, but for regulated client work you want the link on your own domain, encryption at rest, EU data residency and an audit trail. Alkmist keeps the drag-and-drop simplicity and adds those four things.
How do I show an auditor who accessed a file?
Use a tool that logs each action rather than relying on email. Alkmist records every create, view, download and revoke with a timestamp and IP address, and exports the history as a compliance-ready report in one click.

Send the next confidential file as a link, not an attachment

Alkmist Share Space encrypts the file, puts the link on your domain, adds expiry, passwords and a full access log, and handles files up to 5 GB. Request access to try it.