At a Glance
Secure document delivery software is sold into a dozen regulated industries under a dozen different names, and underneath it is the same architecture every time. We built Sealwax, a prototype secure messaging system, to understand encrypted document delivery from the inside: a unique key per message, a link instead of an attachment, and a sender who can expire or destroy what they sent at any time. We built it with a healthcare use case in mind. But that architecture isn't specific to healthcare at all. It's the same pattern that already sits underneath products sold into law firms, accounting practices, title companies, wealth managers, and HR teams, each for reasons specific to their own regulator and their own worst-case failure.
| Industry | What has to stay off email | Who already sells into it |
|---|---|---|
| Legal | Privileged client communications, discovery documents | Kiteworks, Virtru Collaborate, Tresorit |
| Accounting & tax prep | Tax returns, SSNs, W-2s | SmartVault, TaxDome, Canopy |
| Real estate, title & escrow | Wire instructions, closing documents | CertifID |
| Financial advisory / wealth management | Statements, wills, estate plans | Box (Morgan Stanley's own build), RIA-focused portals |
| HR, recruiting & background screening | Offer letters, background checks, candidate PII | FileOrbis, Turn, HYPR Affirm |
Why the Same Pattern Keeps Reappearing
Every one of these industries is solving the identical underlying problem: a document that identifies a specific person alongside something sensitive about them has to move between two parties who don't share an internal system, and ordinary email is not an acceptable channel for it. The solution that keeps reappearing, independently, across all of them is the same four-part pattern:
- Encrypt the document once, with a key that belongs to it alone, so compromising one document never exposes another.
- Deliver a link, never the file itself, so a forwarded or misdirected email carries nothing usable.
- Let the sender revoke access after sending, through expiry or outright deletion, because in every one of these fields the sender remains accountable for the document long after it's sent.
- Log every access, because in a dispute, a breach, or a regulator's inquiry, "we don't know who opened it" is not an acceptable answer.
That's exactly what we built into Sealwax. Mechanically, it works like this regardless of which industry it sits inside: the sender's document gets a random encryption key belonging to it alone, that key is sealed separately to each recipient's public key so only they can open it, the notification email carries a link rather than the file or even a descriptive subject line, and deleting the document later destroys every sealed copy of its key rather than just the file, which is what actually makes deletion permanent. Swap "patient statement" for "closing disclosure" or "background check report" and nothing about that mechanism changes. What changes, industry to industry, is the regulator watching over your shoulder and the software the document has to arrive through. It's worth walking through where each vertical needs it, and what it would actually need to plug into.
- 01Unique key per document
Compromising one document never exposes another.
- 02Deliver a link, never the file
A forwarded or misdirected email carries nothing usable.
- 03Sender-controlled revocation
The sender stays accountable long after sending, in every one of these fields.
- 04Log every access
"We do not know who opened it" is not an acceptable answer to a regulator.
Legal: Attorney-Client Privilege
Lawyers carry a specific ethical exposure that other industries don't: ABA Formal Opinion 477R holds that attorneys have a duty to use "reasonable efforts" to prevent inadvertent disclosure of client confidences over electronic communication, and explicitly requires understanding who controls the encryption keys before trusting a cloud service with privileged material. ILTA's 2025 Security Benchmark sets AES-256 at rest and TLS 1.2+ in transit as the floor, not the ceiling, for legal document sharing.
Purpose-built platforms already compete on exactly the detail our architecture addresses: Virtru's Collaborate product lets a firm host its own encryption keys rather than trusting a vendor with them, and Kiteworks pitches a single audit trail across every channel a firm uses to move privileged data. For a law firm, the integration point is rarely the inbox at all. It's the practice management or document management system: Clio, NetDocuments, or iManage. A secure delivery layer that can't plug into where documents already live doesn't get adopted, no matter how strong the cryptography underneath it is.
Accounting & Tax Preparation: A Market With Published Pricing
Tax and accounting is the clearest evidence this is a real, budgeted software category, because the pricing is public. SmartVault starts around $30 per user per month and is the default choice for firms already running Lacerte, ProSeries, ProConnect, UltraTax, or CCH. TaxDome starts around $50 per user per month and bundles the same encrypted document exchange into a full practice-management operating system, workflow and billing included. Both are SOC 2 Type II certified, which tells you the buyer here (a firm handling client SSNs and tax returns) expects that certification as table stakes, not a differentiator.
The lesson for anyone building in this space: a standalone secure-delivery tool competes weakly against a bundled practice-management platform that already includes it. Where this pattern wins on its own is as the delivery layer underneath a workflow tool, not as a separate destination a client has to be taught to use.
Real Estate, Title & Escrow: The Highest-Stakes Version of This Problem
Wire fraud is the single most common form of payment fraud in real estate closings, and title companies and law firms carry the highest exposure because multiple parties exchange wiring instructions and closing documents by email in a compressed timeframe. CertifID has built an entire company around this exact failure mode: as of their own published figures, they've protected over 1.4 million real estate transactions, blocked $283 million in attempted fraud, and recovered $118 million in stolen funds, working with the US Secret Service. In February 2026, CertifID expanded from a fraud-detection tool into a full closing platform that includes encrypted document delivery, explicitly to remove email from how wire instructions get exchanged at all.
This is the vertical where "link, not attachment" matters most literally: an intercepted email with wire instructions in the body or an attached PDF is the actual fraud vector, not a hypothetical one. The scale of the individual loss makes the case on its own. The average loss per wire fraud complaint specifically tied to a real estate closing reached approximately $124,000 in Q1 2026, up from $112,000 a year earlier, according to industry reporting on FBI IC3 data, and the FBI recorded $275.1 million in total real estate fraud losses in 2025. Against numbers like that, a secure delivery layer that costs a fraction of a single averted incident is an easy budget conversation. Integration here means title production software (SoftPro, ResWare) and the digital closing platforms title companies already run their transactions through.
Financial Advisory & Wealth Management: Regulation-Driven, Not Just Best Practice
SEC-registered investment advisors operate under Regulation S-P (privacy of consumer financial information) and Regulation S-ID (identity theft prevention), and FINRA members carry additional obligations under Rules 3110 and 4370. That regulatory backdrop is why Morgan Stanley's wealth management division didn't buy an off-the-shelf tool for this; they partnered with Box to build a client-facing encrypted vault using Box KeySafe and Box Governance specifically for wills, deeds, estate plans, and tax filings.
Smaller advisory firms and RIAs face the identical requirement without Morgan Stanley's engineering budget, which is exactly why a lighter-weight, purpose-built delivery layer has real demand here. The integration surface is a firm's CRM or portfolio management platform (Salesforce Financial Services Cloud, eMoney, Envestnet) on one side, and custodial statement feeds on the other, often moving in bulk through managed file transfer rather than one document at a time.
HR, Recruiting & Background Screening
Every hire generates a paper trail of exactly the kind this pattern protects: offer letters, background check results, and onboarding paperwork containing Social Security numbers, all moving between a company, a candidate, and often a third-party screening vendor. FileOrbis addresses this by replacing email attachments with revocable, time-bound secure links for exactly this handoff. Turn and HYPR Affirm both lead with AES-256 encryption of PII specifically because candidate data protection has become a stated buying criterion, not an afterthought.
The integration point here is the ATS or HRIS a company already runs (Workday, BambooHR, Greenhouse) and the background screening vendor on the other side (Checkr, HireRight). A secure delivery layer that lives outside both of those systems, requiring a recruiter to manually move documents into it, doesn't survive contact with an actual hiring workflow.
A Quick Note on Insurance and Other Regulated Industries
Insurance claims processing carries the same shape of problem, medical records, financial details, and identifying information moving between an insurer, a claimant, and often a third-party adjuster, and the same drivers apply: a named regulator, a named worst case, and an existing software stack the solution has to sit inside rather than replace. We haven't built a dedicated example for insurance the way we have for the five verticals above, but the architecture doesn't change; only the system it needs to plug into does.
Where the Private-AI Layer Actually Costs Money
Every vertical below reaches the same conclusion about AI: whatever model reads these documents has to run on infrastructure you control, because the entire point of encrypting a tax return or a background check is that no third party reads it. Piping the same content through a public API defeats that guarantee regardless of what happens to the message afterwards.
The part usually left vague is what that costs. We maintain a directory of 24 openly licensed models with VRAM measured at 4-bit and 8-bit quantisation for each, plus named cloud instances and their memory bandwidth, because bandwidth rather than capacity is what sets generation speed. The relevant floors for this use case are lower than most teams expect: document classification and retrieval runs in about 0.5 GB of VRAM (BGE-M3), and a guardrail model filtering what reaches a recipient runs in about 2 GB (Shieldstral 3B).
On rented hardware that is a single 24 GB instance: roughly $0.71/hr on a Google Cloud g2-standard-4, $0.805/hr on an AWS g6.xlarge, or about EUR 214/month for a dedicated Hetzner GEX45 in EU datacentres. The wider comparison is covered in self-hosting AI: local LLMs vs cloud APIs, and the compliance boundary specifically in AI automation under UK GDPR and HIPAA.
The Common Integration Requirement
Across every vertical above, the technology that actually gets adopted is never the standalone tool. It's the one that disappears into whatever the practitioner already uses:
| Vertical | Existing system this must integrate with |
|---|---|
| Legal | Practice/document management (Clio, NetDocuments, iManage) |
| Accounting & tax | Tax prep software (Lacerte, Drake, UltraTax, CCH) |
| Real estate/title | Title production software (SoftPro, ResWare) |
| Wealth management | CRM/portfolio platforms, custodial MFT feeds |
| HR/recruiting | ATS/HRIS, background screening vendors |
| Healthcare | EHR and billing/practice management systems |
That's the practical takeaway from building Sealwax in the first place: the hard engineering problem was never really the cryptography. PyNaCl and libsodium make the encryption itself close to a solved problem. The genuinely hard part, in every one of these verticals, is building something that fits into a workflow someone else already owns.
What Sealwax Actually Proves, and What It Doesn't
Sealwax demonstrates that the core mechanism, unique per-message keys, sealed key delivery, link-only notification, and crypto-shredding on deletion, is buildable by a small team using well-audited, freely available cryptography rather than a proprietary black box. All 82 of its automated tests pass, including a scenario where two independent users complete a full send-receive-reply-delete cycle and a third, unrelated account is confirmed to have no way to decrypt a message it was never sent.
What it doesn't prove, on its own, is that the same code is ready to sit inside a law firm's document management system or a title company's closing platform tomorrow. Every vertical above layers its own requirements on top of the core mechanism: a signed BAA and audit trail for healthcare, key-sovereignty options for law firms operating under ABA guidance, SOC 2 certification for accounting platforms, insured fraud guarantees for title and escrow, and Regulation S-P alignment for wealth management. The architecture transfers cleanly. The compliance posture around it has to be rebuilt, deliberately, for each regulator.
Including a third account confirmed unable to decrypt a message it was never sent.
The same mechanism works regardless of which regulator is watching.
BAAs, SOC 2, key sovereignty and insurance are per-regulator, not reusable.
What We'd Build Next to Extend This
If we extended Sealwax toward any of these verticals specifically, the next steps are consistent regardless of which one: an API surface so it can be called from inside an existing practice-management or ATS system rather than used as a standalone destination, single sign-on so it inherits a firm's existing identity provider instead of managing its own passwords, and role-based, multi-recipient support for the cases (real estate closings, HR onboarding) where more than two parties need controlled access to the same document.
If You're Solving This Problem in Your Own Industry
If your organization moves documents that identify a specific person alongside something sensitive about them, whether that's a legal filing, a tax return, a closing package, a client statement, or a background check, the underlying engineering problem is one we've already worked through directly. We'd welcome a conversation about what building or adapting something like this would take for your specific workflow.
What This Would Cost to Build for Your Industry
A scoped delivery layer for a single document type, into a system that already exposes a documented API, runs $5,000 to $15,000. A multi-system build with identity resolution and integration into a practice management or ATS platform runs $15,000 to $50,000. Integration count and data quality drive the number rather than company size, which is broken down fully in our AI automation cost guide.
That work sits under our AI automation development service, with an AI consulting engagement where the first question is which of your existing systems the documents actually have to arrive through. Full tiers are on the pricing page.
Before any of that, the AI readiness score is ten questions on whether your systems and data are ready, and the automation quote generator returns an instant ballpark. Both are free with no email required.
The Vertical Guides
Each industry above has its own regulator, its own worst case, and its own set of incumbent vendors. We have written the build-versus-buy decision out in full for five of them:
- Secure document sharing for law firms, where key custody is the diligence question and a 2026 ruling held that a consumer AI tool destroyed privilege outright.
- Secure client portals for accounting and tax firms, the one vertical with fully public pricing, which makes it the clearest build-versus-buy comparison anywhere.
- Wire fraud prevention for title and escrow, where the average loss reached roughly $124,000 per incident in Q1 2026 and encryption alone does not address the actual fraud vector.
- Secure client portals for financial advisors, covering Regulation S-P, why Morgan Stanley built rather than bought, and the ad hoc email gap most firms miss.
- Secure document sharing for HR and recruiting, where the recipient has no account with your systems yet and that, not the encryption, is the hard part.
The healthcare version, including the full cost breakdown and the gap list, is in HIPAA secure messaging: build vs buy.
Frequently Asked Questions
Is this architecture specific to healthcare, or genuinely reusable?
Genuinely reusable. Per-message encryption keys, link-only delivery, sender-controlled expiry, and access logging aren't healthcare-specific techniques; they're a general answer to "how do I send someone a sensitive document without email being the weak point," which is why the same pattern shows up independently across law, accounting, real estate, wealth management, and HR.
Why do these industries need a different tool instead of just using encrypted email?
Standard email encryption (like S/MIME or PGP) still requires both parties to manage keys and typically still delivers the file itself. This pattern instead sends a link and requires no key management from the recipient, which is why regulated industries with non-technical recipients (patients, clients, candidates) have converged on it.
What's the single biggest integration challenge across these industries?
Fitting into a workflow tool the practitioner already uses. A secure delivery product that requires someone to leave their tax software, practice management system, or ATS to use it separately faces adoption resistance regardless of how strong its security is.
Which of these verticals has the clearest, most public pricing model?
Accounting and tax preparation. SmartVault and TaxDome both publish per-user monthly pricing ($30 and $50 respectively) and both carry SOC 2 Type II certification, which makes it the easiest vertical to benchmark a build-vs-buy decision against directly.
Does the same regulatory logic apply everywhere, or does each industry have its own rules?
Each has its own specific regulator and standard: ABA opinions and ILTA benchmarks for law, SEC/FINRA rules for financial advisors, and industry-specific breach liability for title and escrow. The technical solution is shared; the compliance framing around it has to be written for each regulator specifically.
How would you approach building this for an industry not listed here?
The same way we approached healthcare: understand the specific document type, the specific regulator, and the specific system of record the target user already lives in, then adapt the same four-part pattern (unique keys, link delivery, sender control, audit logging) to fit that workflow rather than starting from scratch.
Muhammad Kashif is co-founder of ValueStreamAI, leading technical delivery and AI strategy. He designs and ships custom agentic AI and healthcare automation systems for clients across the US and UK. More about Muhammad Kashif →
