Skip to main content
VaultFerry

Law firms & professional-services practices

Client files that never leave your firm's control

VaultFerry is the secure front desk in front of the cloud storage your firm already owns. Share matter files and collect documents from clients with expiring links — password-protected on paid plans — while the files themselves stay in your own bucket, never in ours.

By Lorenzo Piovesan · Updated

The problem

  • Consumer file-transfer tools take custody of privileged material, putting a third party inside your data-custody chain.
  • You can't evidence where a client's documents physically live, which complicates data-residency and engagement-letter commitments.
  • Forwarding matter files over email leaves copies scattered across inboxes you can't expire or revoke.
  • Confirming whether opposing counsel or a client actually retrieved a document usually means a follow-up phone call.

How VaultFerry helps

  • Files stay in your own bucket

    Bytes travel directly from your firm's S3, Google Cloud, or Azure bucket to the recipient. Nothing passes through, or is stored on, our servers — so VaultFerry supports the "reasonable efforts" standard of ABA Model Rule 1.6(c) and Formal Opinion 477R for your file contents. The limited metadata we process is documented in our Data Processing Agreement.

  • Data residency you can name

    Because the storage is yours, you decide where it's kept. Your files stay under your control — we hold only limited operational metadata — which supports SEC Regulation S-P safeguarding and GDPR cross-border transfer programs.

  • Links you can password-protect, expire, and revoke

    On paid plans, every share link can carry a password and an expiry; the Business plan adds a per-link download cap. Revoke a link from the dashboard and no new download URL is minted for it.

  • A delivery and access record

    Paid plans record when each link was downloaded; the Business plan adds the approximate region of the access (derived from the IP, which is never itself stored), supporting your own incident-response and oversight program.

Frequently asked questions

Do our client files ever pass through VaultFerry's servers?
No. Bytes travel directly from your own cloud bucket to the recipient. We mint short-lived signed links from your credentials, but the file itself is never routed through, or stored on, our infrastructure.
How does this map to ABA Model Rule 1.6(c)?
Rule 1.6(c) and Formal Opinion 477R require reasonable efforts to protect client information, including metadata. Keeping file contents inside infrastructure you already control, with encrypted credentials and expiring links, is a concrete reasonable-efforts measure. We document the limited metadata we process in our Data Processing Agreement.
Where are our client documents physically stored?
Wherever you configure your own bucket. You choose the cloud provider and where your data physically lives, so you can evidence data residency on your own terms — which supports SEC Reg S-P and GDPR transfer obligations.
What happens if we need to cut off access to a document?
Revoke the link in the dashboard. No new download URL is minted after that. A signed URL already issued remains valid only until it expires — at most five minutes.
Can we see whether a client actually received a file?
On paid plans you can see when each link was downloaded. The Business plan also records the approximate, country-level region of the access; the raw IP address is never stored — only a coarse region.