Every document visible only to whoever should see it
Confidentiality
Each document, only for those who should see it
Internal notes stay with your team. A confidential document is read only by your team and by the participants it names or mentions (subcontractor, bank, architect). The log shows who viewed what.
- Internal notes, invisible to the client
- Confidential: your team and the participants named
- Exportable access log
Replaces: Forwarded emails · Sensitive documents on WhatsApp
Asked “who saw this document?”, you have the answer
In a shared folder, everyone reads what concerns them
A subcontractor, a bank, an architect work on part of the folder. They have no business reading the rest: not your internal exchanges, not the client's identity document, not what concerns another participant. For a lawyer, a broker or a wealth adviser, this goes beyond comfort: professional secrecy is at stake.
The usual reflex is the forwarded email, document by document, outside the folder. That is what loses track of who holds what.
Who reads a publication, chosen as you write
Visibility is chosen in the composer, at the moment of writing, and applies to the whole publication.
-
Public
Every participant of the folder, clients and other participants alike. This is the default.
-
Internal note
Your team only. No participant reads it, and it never appears in a participant's export or in a reminder.
-
Confidential
A switch reserved for the team. The publication is read only by the team and by the participants it names or mentions itself. The group covering every participant is disabled in the selector, and the server refuses a confidential publication that would target it.
A mention in a comment never opens a confidential publication to someone who could not already read it. A participant with full access does not catch up on it afterwards either. The mode is chosen, never inferred: a publication does not become confidential by mistake, nor public by accident.
Others cannot guess what they cannot see
A document that does not concern a participant does not appear for them with a padlock: there is nothing to infer from the interface. A participant with limited access reads only the items that name or mention them, and the folder's milestones.
Who saw this document?
Each folder keeps an access log: who opened it, which document was viewed or downloaded, when, from which device. The folder's lead and supervisors can read it, and it exports as CSV. It is what lets you answer calmly the day someone claims never to have received a document.
In practice
- Construction and renovation. The client sends you their financing plan. You publish it as confidential, naming the client: the subcontractors and the architect in the folder do not read it, unless you name them.
- Brokerage, real estate, wealth management. The loan offer, the identity document or the tax assessment (avis d’imposition) are read only by the team and the named borrower, not by the notary (notaire) or the agent in the same folder, unless you name them.
What it does not do
- Confidentiality is set publication by publication. It does not restrict access within the team: members added to the folder read everything, internal notes included.
- You have to remember to flip the switch. The application does not guess that a document is sensitive.
- The access log is kept for a limited time, stated on the security page, and it records consultations, not what was made of them.
Related reading
The Security and confidentiality page describes hosting, access and traceability as the application enforces them. On the features side, see client access without an account and document requests. For the professions concerned: lawyers, mortgage brokers and wealth advisers.
Confidentiality, in other lines of work
The other features
Your next folder, with nothing lost along the way
Not the right time?
Get the link to this page by email and come back whenever you like.
By sending, you will receive one e-mail with this link — your address is not kept.