Privacy & compliance

How to send case bundles securely

By Hein de Wilde·Updated ·3 min read

Key takeaways

  • Send bundles as a link you control: a password sent by another channel, an expiry date and a download receipt.
  • Ordinary encryption means the service holds the keys; use an end-to-end encrypted transfer where even it must not read the file.
  • The professional assessment of any tool stays yours to make.
Contents
  1. Why bundles and email do not mix
  2. A link you can control
  3. Ordinary encryption versus end-to-end
  4. Getting documents from the client
  5. What stays your responsibility
  6. A delivery routine for bundles

To send a case bundle securely, send a link instead of attachments, put a password on it and send the password through a different channel, give the link an expiry date, and keep the download receipt. For the handful of documents that nobody but the recipient should ever be able to open — including the service in the middle — use an end-to-end encrypted transfer instead of an ordinary one.

I run Yungle, so I am not neutral. What follows is a method, and the professional judgement about what your matter requires stays yours.

Why bundles and email do not mix

A hearing bundle is a big PDF, an exhibits folder, witness statements and often video — CCTV, a recorded interview. Together that is far beyond the 25 MB most mail servers accept, and splitting it across emails is how exhibits go missing.

Email has a second problem that matters more in legal work: once sent, it is out of your hands. You cannot take an attachment back, it lives in every inbox it passed through, and it forwards with a click. A link, by contrast, is something you control after sending.

Four properties turn a link into a controlled delivery:

A password, sent separately — by phone or text, not in the same email. Someone who gets the email alone gets nothing.

An expiry date. The link stops working when the bundle stops being needed, so a forwarded copy dies on schedule instead of living forever.

Revocation. If a link goes to the wrong person, you switch it off. That is not possible with an attachment.

A download receipt, per recipient. When the other side says they never received the bundle, you have the date and time they downloaded it.

Ordinary encryption versus end-to-end

This distinction is worth getting right, because "encrypted" gets used loosely.

On Yungle every file is always encrypted at rest with its own key, on servers in Germany. Those keys are held by Yungle — that is what allows virus scanning and previews, and it means the service could technically decrypt an ordinary file. Nobody browses uploads, but "could" is the honest word.

An end-to-end encrypted transfer is different: the key is created in your browser and travels in the link itself, after the #, which browsers never send to a server. Yungle stores a file it cannot read.

End-to-end encryption: the key travels in the part of the link after the #, which browsers never send to a server.

The trade-off is practical. Because the key is the link, an end-to-end transfer cannot be emailed to recipients by Yungle or put behind a password — you send the link yourself, through a channel you trust. It is the right tool for the few documents that justify it, not a default for everything.

Getting documents from the client

Clients send documents too, usually badly: phone photos, forwarded chains, a scan that bounced. A single upload link per matter fixes the direction — the client uploads without an account, every file is checked for viruses before it reaches you, and it lands in that matter's folder. Collecting documents from clients covers the method in detail; it applies just as well to disclosure as to year-end accounts.

What stays your responsibility

Tools do not carry professional obligations. Before you rely on any service for client material, the questions are yours to answer:

  • Whether it meets your professional secrecy and data-protection obligations for this kind of material.
  • How long the material should be kept, and when it should be deleted.
  • Which documents need end-to-end encryption rather than ordinary encryption.

Yungle publishes a data processing agreement and holds no certification of its own — its hosting provider's data centres are ISO 27001 certified. It runs on one server with no service level agreement. The page for law firms sets all of this out plainly.

A delivery routine for bundles

  1. One link per bundle, never attachments.
  2. Password on, sent by another channel.
  3. An expiry date that matches the stage of the matter.
  4. End-to-end encryption for the documents that justify it.
  5. Keep the receipt with the file note.

For the wider picture — privileged material, medical records, anything where a leak is not recoverable — read how to send confidential documents and what "end-to-end encrypted" really means.

Hein de Wilde

I build and run Yungle, and I write everything here. Comparisons name competitors and credit them, every claim about another company comes from that company’s own documentation, and where we fall short it says so. More about who is behind this.

Read next