Use Case

Secure KYC & Identity Document Collection

Collect passports, IDs, proof of address, and tax forms from clients through an end-to-end encrypted intake — not email attachments or a public upload link. GDPR-compliant identity document collection with a full audit trail.

Collect Identity Documents Securely

Clients email photos of their passport

A picture of a driver's license or passport lands in your inbox as an attachment and stays there, and in your sent folder, indefinitely.

Public upload links expose one client to the next

A shared Drive folder or open form leaves sensitive identity documents visible or guessable, with no record of who accessed them.

You're holding regulated PII with no audit trail

IDs, proof of address, and tax forms are exactly the data regulators expect you to protect — collected through channels you can't prove were secure.

Chasing and re-collecting blurry or missing documents

You never know who submitted what, or whether the file is legible, until you open it. Manual follow-up slows every onboarding.

1

Build a reusable identity intake

Create one request for exactly the documents your checks require (government ID, proof of address, tax form) with clear labels so clients submit the right thing the first time.

2

Send the branded link

The client opens a page with your company name and logo. No account to create, no app to install, no public folder.

3

They submit — encrypted in their browser

Every document is encrypted on the client's device before it reaches our servers. We store ciphertext; you're notified the moment it's complete.

4

You decrypt and run your checks

Open the submission in your workspace, hand the documents to whatever verification process you already use, and keep a timestamped record of the whole exchange.

  • Passports, IDs, and tax forms never transit through email or chat
  • Each client's documents isolated — never exposed to the next
  • End-to-end encrypted, GDPR-aligned collection with an audit trail
  • Clear field labels reduce blurry, wrong, or missing uploads
  • No account required — the client just opens the link
  • A timestamped record of what was collected, when, and by whom

Collecting someone's identity documents is the moment you take on the most regulated data you'll ever handle. Email is the wrong place for it.

Onboarding a customer, a borrower, a tenant, or a contractor means asking for their passport, their proof of address, sometimes a tax form or source-of-funds document. The default, "email a photo of your ID," turns your inbox into a store of the most sensitive personal data there is: government identifiers, home addresses, dates of birth.

That passport photo is now searchable in your mail, sitting in your sent folder, backed up on servers you don't control, with no expiration and no record of who opened it. A shared upload folder is no better. It exposes one applicant's documents to the next. This is exactly the data breach-notification laws are written about, and it's easy to stop.

Where doconvoy fits (and where it doesn't)

doconvoy is the secure collection layer: it gets identity documents from your client to you encrypted end-to-end, GDPR-aligned, with a full audit trail. It is not a verification engine. No liveness checks, database lookups, or sanctions screening. It hands you clean, legible documents to feed into whatever KYC, AML, or verification process you already run. Think of it as the encrypted front door to your checks, not a replacement for them.

What you'll collect

One reusable identity intake replaces the email attachments. Everything the client submits is encrypted end-to-end in their browser and kept isolated from every other submission:

  • Full name, date of birth, and nationality
  • Residential address
  • Government-issued ID (passport, driver's license, or national ID)
  • Proof of address (utility bill or bank statement)
  • A photo of the applicant for document matching, where your process needs it
  • Tax form (W-9 / W-8BEN) or source-of-funds document, where relevant

How the intake flow works

When you onboard a client: Send your standard identity request — the same reusable intake for every applicant. It opens as a branded page carrying your name, not a generic tool or a public folder.

They submit their documents: Clear labels tell them exactly which document goes where, so you get legible files the first time. Everything is encrypted on their device before it's sent. We store ciphertext.

You decrypt and verify: Open the submission in your workspace, pull the documents into whatever verification process you run, and keep a timestamped record of the exchange.

What your client experiences

A link, a form, a few uploads, submit. No account, no app, no public link that makes them nervous about who else can see their passport. Handing over identity documents is the most sensitive step in any onboarding. A form that visibly encrypts their ID on their own device is often what convinces them to finish.

The audit trail regulators expect

Collecting regulated identity data means being able to show how you collected it. Every submission is logged: when the request was sent, when it was opened, when documents were submitted, and the verification method used. If a client exercises a data-subject request, or an auditor asks how identity documents are handled, the record is already there. Retention or deletion is one deliberate action, not a hunt through inboxes and backups.

Built for the way your field collects identity documents

The same encrypted intake fits any identity-document collection, but the checklist and the journey differ by field. If you handle visas or relocation, see the immigration document collection view, built around passports, financial proof, and the reminders and GDPR handling that cross-border cases demand.

For the underlying practices, see our guides on securely receiving files from clients and maintaining audit trails for sensitive data sharing, or explore Secure Requests and the Audit Trail.

Handle sensitive client information securely — from onboarding to handoff. Try any workspace free for 3 days — no credit card required.

Collect Identity Documents Securely