Emailing sensitive documents as attachments is risky, and shared links leak. But forcing clients to create yet another account creates support tickets and drop-offs. Passwordless portals solve both.
How it works
- The client enters their email address on the portal.
- If that email is approved for the portal, a short code is sent to it.
- The client types the code and gets a session for a limited time.
- Every file they see or upload passes through a permission check on the server.
What makes it safe
- Short-lived, single-use codes, typically valid for a few minutes.
- Rate limits on requests and attempts.
- An allow-list: only emails you have approved can ever receive a code.
- No direct file links. Files are streamed through the app after a permission check, so forwarding a link gives nobody access.
- An audit log of every sign-in, view, upload and signature.
Where it fits
We built five portals this way for one firm: client, broker, investor, document upload and e-signing. Each audience sees only its own files, with visibility set per file for client, broker, staff and investor, and admin approval before anything is released.
When you still want passwords or SSO
For your own staff, use your company sign-in (Google or Microsoft) with multi-factor authentication. One-time codes are ideal for outside people who visit occasionally.
Need a portal for your clients or investors? See custom portals.