Secure File Transport gives you 10 powerful features—each designed to solve a real business problem. Whether you need to speed up approvals, reduce compliance risk, or cut manual work, these features deliver measurable results. This page explores each feature and shows how it helps your business. For a quick overview, see Overview.
Secure File Transfer & Encryption
Protect Files During Transfer and Storage
Secure File Transport uses encryption and security controls to help protect files from unauthorized access while they are being transferred and stored.
Files can be securely exchanged without relying on traditional email attachments or unsecured file-sharing methods.
How it works:
-
A user uploads or sends a file through SFT.
-
The file is transferred using secure communication protocols.
-
Files are stored using configured security controls.
-
Access is restricted based on the user's permissions and configuration.
Product Benefits:
-
Protect sensitive documents during transfer and storage.
-
Reduce reliance on email attachments for sensitive information.
-
Restrict access to authorized users and systems.
-
Provide a secure mechanism for exchanging documents with customers and internal teams.
Automation
Automate Collection of Documents
Secure File Transport can automate repetitive file-management activities using configurable rules and workflows. Business can configure automation to determine when files should be collected and processed after they are received or uploaded.
Example: Loan Processing
|
Before |
With SFT |
|---|---|
|
3-4 days (applicant emails → loan officer downloads → routes to underwriter → manual status updates) |
Same day (applicant uploads → auto-routes → auto-logs → underwriter notified instantly) |
Product Benefits:
-
Reduce manual file-handling activities.
-
Standardize document-processing workflows.
-
Route files based on configured business rules.
-
Improve processing consistency and turnaround time.
File Tagging & Organization
Organize and quickly locate documents
SFT provides mechanisms for organizing files using configurable tags, making it easier for users to locate documents when needed. Files are auto tagged as soon as they are uploaded by the end user.
Example:
A user needs to locate a client's tax return.
Instead of searching through multiple email conversations or shared folders, users can quickly find files associated with the relevant record using tags
Product Benefits:
-
Improve document organization.
-
Reduce time spent locating files.
-
Create a consistent document classification structure.
-
Make documents easier to retrieve and manage.
Reporting & Monitoring
Visibility Into File Activity and Processing
SFT provides reporting and monitoring capabilities that help administrators and users understand file activity and identify areas that may require attention.
Depending on the configured implementation, organizations can monitor information such as:
-
Files received and processed
-
File status
-
Processing activity
-
Transfer activity
-
Failed or pending transactions
-
User activity
Product Benefits:
-
Improve operational visibility.
-
Identify processing issues and bottlenecks.
-
Monitor file-transfer activity.
-
Support operational and management reporting.
Built-In Compliance
Support Your Organization's Security and Compliance Requirements
Instead of buying separate compliance tools for HIPAA, PCI, GDPR, FERPA, etc., SFT handles them all. Encryption, audit logs, access controls, retention policies—all automatically enforced.
-
All HIPAA controls auto-enforced
-
Access automatically logged (no manual work)
Regulations SFT Covers
|
Regulation |
What It Protects |
Business Benefit |
|---|---|---|
|
HIPAA |
Patient medical records |
Healthcare providers pass audits, protect patient privacy |
|
PCI DSS |
Payment card data |
Financial companies secure card data, reduce fraud |
|
GDPR |
EU resident personal data |
European companies comply with privacy laws, avoid fines |
|
FERPA |
Student education records |
Schools protect student data, comply with education law |
|
SOC2 |
Overall security controls |
Software companies prove security to customers |
Mobile & Remote Access
Work from Anywhere, Securely
What It Means for Your Business
Loan officers meeting clients can upload documents from their phone. Doctors on hospital rounds can access patient files. Remote employees can work from home with same security as office. No VPN needed, no special setup.
Real-World Example
Scenario 1: Loan Officer in Field
-
Client meeting: "I have my recent tax return with me"
-
Loan officer: Opens phone, takes picture, uploads to SFT
-
File instantly encrypted, routed to underwriter
-
Underwriter gets notification: "New doc ready"
-
Same day: File reviewed, decision made
-
Result: Faster decisions, better customer experience
Scenario 2: Healthcare Provider from Home
-
Doctor working from home during sick leave
-
Patient calls: "Can I see my test results?"
-
Doctor: Opens phone, views encrypted patient file
-
Doctor: Calls patient back with results
-
All access logged for HIPAA compliance
-
Result: Patients served, HIPAA logged, compliance maintained
Scenario 3: Compliance Officer Remote Work
-
Compliance officer works from Starbucks (WiFi)
-
Manager asks: "Are we audit-ready?"
-
Officer: Opens app, runs compliance report
-
Officer: See all files, access logs, security status
-
Officer: Email report to management
-
Result: Remote work enabled, compliance maintained
Business Benefit
📱 Work Anywhere, Anytime — Remote workers don't need special VPN or IT setup. Same security as office. Perfect for post-COVID flexible work, field teams, and distributed organizations.
11. Feature #9: Audit Trail
Compliance in a Click
What It Means for Your Business
Every file action is automatically logged: who accessed it, when, from where, for how long. No manual tracking needed. When auditors ask "Who accessed this patient file?", you have the answer in 1 second.
Real-World Example
Before SFT (manual audit):
-
Auditor asks: "Who accessed patient files in June?"
-
Compliance officer: Spends 3 days manually reviewing logs
-
Compliance officer: Creates spreadsheet of access
-
Compliance officer: Writes audit report
-
Time: 16+ hours
-
Risk: Missed access, incomplete report
After SFT (automatic audit):
-
Auditor asks: "Who accessed patient files in June?"
-
Compliance officer: Clicks "Generate HIPAA Audit Report"
-
System: Generates report in 10 seconds
-
Compliance officer: Reviews automated report
-
Time: 30 minutes
-
Result: Complete, accurate, professional report
What Gets Automatically Logged
|
Action |
Automatically Logged |
|---|---|
|
File uploaded |
User, date/time, file size, file type, upload method |
|
File downloaded |
User, date/time, device type, location |
|
File shared |
User, recipient, date/time, link expiration |
|
File accessed |
User, date/time, duration accessed, IP address |
|
File deleted |
User, date/time, reason, approval status |
|
Permission changed |
User, what changed, date/time, reason |
|
Policy violated |
Violation type, user, date/time, action taken |
Real-World Audit Scenario: Hospital
HIPAA Audit Log - June 2024
June 5, 10:15 AM - Patient John Smith's file accessed
- Accessed by: Dr. Jane Williams (Cardiologist)
- Device: Office desktop computer
- IP: 192.168.1.45
- Duration: 8 minutes
- Action: Viewed file
June 5, 10:23 AM - File shared with specialist
- Shared by: Dr. Jane Williams
- Recipient: Dr. Mark Jones (Cardiologist)
- Device: Office desktop
- Link expiration: June 12 (7 days)
June 5, 2:30 PM - File accessed by specialist
- Accessed by: Dr. Mark Jones
- Device: Mobile phone
- Location: Cardiology clinic
- Duration: 15 minutes
June 12 - Link expired (automatic)
- Dr. Mark Jones can no longer access file
- System automatically revoked access
- Logged in audit trail
Result: Complete transparency. Auditors can see every access.
All legitimate. No unauthorized access. HIPAA compliant. ✓
Business Benefit
📋 Audits Take Hours, Not Weeks — Auto-generated audit logs means compliance reviews go from 3-week projects to 1-hour reviews. Plus, you prove compliance happened—no guessing.
Role-Based Access Control
Only Authorized People See Sensitive Data
What It Means for Your Business
You decide exactly who can access which files: Finance staff see financial docs, HR staff see employee docs, executives see everything. If someone leaves the company, their access disappears instantly.
Real-World Example
Before SFT (manual access control):
-
New contractor hired: "They need to see client files"
-
Admin: Manually adds contractor to 15 file folders
-
Contractor finishes project: "OK, they're done"
-
Admin: Remembers to remove access (sometimes forgets)
-
Risk: Former contractor can still see confidential files
-
Cost: Data breach, compliance violation
After SFT (automatic access control):
-
New contractor hired: Admin sets role "Contractor_ABC"
-
Rule: Can access files tagged "Project_ABC" only
-
Contractor: Can see only their project files
-
Contractor finishes project: Admin changes role to "Contractor_Inactive"
-
System: Instantly revokes all access
-
Result: Clean access control, zero risk of "forgotten" access
Real-World Access Control Examples
Financial Services Company:
-
Loan Officer John Smith: Can see only his client files (50 clients)
-
Underwriter Jane Williams: Can see all loan files awaiting review (500+ files)
-
CEO: Can see all files across company
-
Compliance Officer: Can see all files + audit logs
-
Contractor: Can see only files tagged "Contract_XYZ"
-
Result: Least-privilege security, no one sees data they don't need
Healthcare Organization:
-
Front Desk Staff: Can see patient names/contact info only (no medical records)
-
Doctor: Can see patient's medical records (records they created/authorized)
-
Nurse: Can see medical records + medications
-
Billing Staff: Can see billing/insurance info only (no medical data)
-
Compliance Officer: Can see all patient files + audit logs
-
Patient: Can see own medical records only (via patient portal)
-
Result: Privacy maintained, patients trust healthcare organization
Law Firm:
-
Associate Attorney: Can see only files for cases they're assigned
-
Partner: Can see all cases (attorney oversight)
-
Paralegal: Can see only documents for their attorney's cases
-
Opposing Counsel: Cannot see any files (external access blocked)
-
Court: Can see discovery files (specifically approved by attorney)
-
Result: Attorney-client privilege maintained, court compliance
Business Benefit
🔐 Insider Threat Eliminated — Only authorized people access sensitive data. Employee leaves? Access gone instantly. Contractor finishes? Access gone instantly. No data exposure, zero compliance risk.
13. Comparing SFT to Other Approaches
|
Capability |
SFT |
|
Shared Drives |
Other Tools |
|---|---|---|---|---|
|
Files automatically encrypted? |
✅ Yes |
❌ No |
⚠️ Optional |
✅ Yes |
|
Workflows automate? |
✅ Fully |
❌ No |
❌ No |
⚠️ Limited |
|
Complete audit trail? |
✅ Yes |
❌ No |
⚠️ Limited |
✅ Basic |
|
Built-in compliance (HIPAA/PCI/GDPR)? |
✅ Yes |
❌ No |
❌ No |
⚠️ Partial |
|
Integrated with Salesforce? |
✅ Native |
❌ No |
❌ No |
⚠️ Requires setup |
|
Mobile app included? |
✅ Yes |
✅ Yes |
⚠️ Limited |
✅ Yes |
|
Easy to learn? |
✅ <5 min |
✅ None |
✅ Minimal |
⚠️ 1-2 hours |
|
Requires IT support? |
✅ Minimal |
✅ None |
⚠️ Moderate |
⚠️ Ongoing |
|
Cost per user/month? |
⚠️ Org-wide pricing |
✅ Included |
✅ Included |
⚠️ $20-100/person |
|
Reduces manual work 70%? |
✅ Yes |
❌ No |
❌ No |
⚠️ Partial |
14. Next Steps
Want to See These Features in Action?
-
🎥 Watch Video Demos — 5-minute feature walkthroughs
-
🧪 Try Free Trial — Use all features yourself (30 days)
-
📞 Schedule Demo — See features live for your specific business scenario
15. Contact
Have questions?
📧 Email: features@cloudmaveninc.com
📞 Phone: 1-800-XXX-XXXX (ext. Product)
🌐 Website:
http://www.cloudmaveninc.com
© 2026 Cloud Maven, Inc. All Rights Reserved.
4. Feature #2: Automation
Let the System Do the Heavy Lifting
What It Means for Your Business
Create "if-then" rules without writing code. "If client uploads ID, then auto-verify and route to compliance team." "If applicant uploads 3 required documents, then trigger loan underwriting approval." Rules run automatically 24/7—no humans involved.
Real-World Example #1: Loan Processing Automation
Traditional Process (4 days, lots of manual work):
-
Applicant calls: "Where do I send my documents?"
-
Admin sends email: "Email to loans@company.com"
-
Applicant emails tax return from personal email
-
Loan officer receives email, downloads file, creates folder
-
Loan officer manually checks: "Did we get all 3 required documents?"
-
Missing document! → Loan officer emails applicant: "Need pay stub"
-
Applicant emails pay stub (wrong format)
-
Loan officer calls applicant: "We need a recent pay stub"
-
Applicant re-sends correct pay stub
-
Loan officer organizes all docs, emails to underwriter: "Ready to review"
-
Underwriter receives email, downloads files, updates status
-
Total time: 4 days (because of email delays + back-and-forth)
-
Manual steps: 12, Error points: 10+
With SFT Automation (same day, zero manual work):
-
Applicant goes to secure portal (1 minute)
-
Applicant uploads documents (3 minutes)
-
System automatically:
-
✓ Receives all files
-
✓ Checks: Do we have all 3 required documents?
-
✓ If missing: Sends applicant email "Please upload pay stub"
-
✓ When complete: Tags all docs as "Complete Application"
-
✓ Routes to underwriter automatically
-
✓ Sends underwriter email: "New application ready to review"
-
✓ Logs everything for audit trail
-
-
Underwriter receives notification, starts review
-
Total time: 30 minutes
-
Manual steps: 0, Error points: 0
Business Impact:
-
✅ Reduce loan processing time from 4 days to 4 hours (90% faster)
-
✅ Eliminate back-and-forth emails (customer happier)
-
✅ Zero missing documents
-
✅ Loan officer has time for other work
-
✅ Underwriter reviews instantly (more loans funded, more revenue)
Real-World Example #2: Patient Records Automation (Healthcare)
Old Process (manual):
-
Doctor creates medical summary
-
Receptionist receives handwritten note
-
Receptionist scans to PDF
-
Receptionist manually files in patient folder
-
Receptionist manually logs access for compliance
-
Patient calls: "Can I see my results?"
-
Staff manually retrieves file
-
Staff manually emails to patient
-
Problems: Lost emails, missing records, compliance gaps, slow patient service
With SFT Automation (instant):
-
Doctor uploads medical summary to patient's file (1 click)
-
System automatically:
-
✓ Tags it: "Medical Record - Lab Results"
-
✓ Encrypts the file (HIPAA compliant)
-
✓ Logs access: who, when, where (audit trail ready)
-
✓ Creates patient portal access (patient can view instantly)
-
✓ Sends notification to patient: "New results available"
-
-
Patient opens app, sees results immediately
-
Patient can print/download
-
All actions logged for HIPAA compliance
-
Total time: Instant
-
Manual steps: 0
Business Impact:
-
✅ Patient satisfaction (instant access to records)
-
✅ Staff saves 30+ minutes per day (less manual filing)
-
✅ HIPAA compliance automatic (zero violations)
-
✅ Audit prep is 1 click (was 16 hours)
-
✅ No lost records or miscommunications
Real-World Example #3: Client Onboarding (Financial Services)
Traditional Process (5-7 days):
-
New client: Receives email "Send us KYC documents"
-
Client emails: ID, proof of address, bank statement
-
Compliance officer checks email manually: "Do we have everything?"
-
Missing one document! Officer emails client: "Please resend proof of address"
-
Client resends (but different format)
-
Officer: "This doesn't match our requirements"
-
Back-and-forth emails... 3 days later, correct documents received
-
Officer manually verifies each document
-
Officer creates compliance checklist (manually)
-
Officer updates account status in system (manually)
-
Account finally "ready to fund"
-
Total time: 5-7 days
-
Client experience: Frustrated (lots of back-and-forth)
With SFT Automation (1 day):
-
New client: Receives email with secure portal link
-
Client logs in (2 minutes)
-
Client uploads: ID, proof of address, bank statement (3 minutes)
-
System automatically:
-
✓ Checks: Do we have all 3 required documents?
-
✓ If missing: Sends client email "Please upload proof of address"
-
✓ Verifies documents (OCR technology reads ID, extracts info)
-
✓ Creates compliance checklist (auto-populated)
-
✓ Routes to compliance officer
-
✓ Logs everything for audit
-
-
Compliance officer reviews complete checklist in dashboard (5 minutes)
-
Officer approves
-
System automatically updates account: "KYC Complete - Ready to Fund"
-
Client gets notification: "Your account is ready!"
-
Total time: 1 day
-
Client experience: Fast, simple, professional
Business Impact:
-
✅ Onboarding 80% faster (5 days → 1 day)
-
✅ Customer satisfaction (simple, fast process)
-
✅ Compliance guaranteed (no missing docs, complete checklists)
-
✅ Compliance officer saves 4+ hours per client
-
✅ More clients funded, more revenue
Key Automation Scenarios
What Can Be Automated:
-
✅ Document routing (auto-send to right person)
-
✅ Required document checks (auto-verify all docs received)
-
✅ Compliance checklists (auto-populate, auto-route)
-
✅ Customer notifications (auto-email when docs received/reviewed)
-
✅ Approvals (auto-trigger approval workflows)
-
✅ Compliance logging (auto-log HIPAA/PCI/GDPR access)
-
✅ File cleanup (auto-delete after retention period)
-
✅ Escalations (auto-email if approval pending >2 days)
Rules You Can Create (No Code):
-
"If file type = tax return, auto-tag as 'Income Verification'"
-
"If all required docs uploaded, auto-route to underwriter"
-
"If file not approved within 2 days, send escalation email"
-
"If file is medical record, auto-log for HIPAA audit"
-
"If file expires in 30 days, send renewal reminder"
-
"If file is 5 years old, auto-delete per retention policy"
Business Benefit
🤖 Save 20+ Hours Per Week Per Employee — If your team spends 100 hours/week on file management, automation handles 70-90 hours of that. You just saved $80K-$120K/year in salary costs. Plus, processes run 24/7 (even nights/weekends).
5. Feature #3: Automatic File Tagging & Metadata
What It Is
Automatically organize and categorize files using searchable metadata tags. Users or admins can set rules to auto-tag files based on type, document content, or workflow stage.
Technical Details
-
Auto-Tagging: Rules-based tagging (if file type = "tax return", auto-tag "Financial Document")
-
Manual Tagging: Users can add custom tags (e.g., "Urgent", "Priority Client")
-
Metadata Fields: Document type, date received, source, compliance category, retention period, owner, status
-
Searchable: Full-text search across all metadata (find files in seconds)
-
Bulk Operations: Tag 100+ files at once
Tagging Examples
Healthcare:
Auto-tag rules:
-
PDF + mentions "lab results" → Tag: "Lab Results"
-
DOCX + mentions "discharge" → Tag: "Discharge Summary"
-
Any file + received from Insurance Co. → Tag: "Insurance Document"
Manual tags users add:
-
"Urgent - High Priority"
-
"Follow-up Required"
-
"Review for Authorization"
Financial Services:
Auto-tag rules:
-
"Form 1040" detected → Tag: "Tax Return"
-
Filename contains "W-2" → Tag: "Income Verification"
-
File from client upload portal → Tag: "KYC Submission"
Manual tags users add:
-
"Verified"
-
"Fraud Risk - Flag for Review"
-
"Pre-Approval"
Legal:
Auto-tag rules:
-
File marked "Privileged" → Tag: "Attorney-Client Privilege"
-
File from opposing counsel → Tag: "Discovery Document"
-
File type = "Email" → Tag: "Correspondence"
Search & Retrieval
Find files in seconds:
Search: "Tax Return" → 47 results across all clients
Search: "Tag: Lab Results AND Date: Last 30 Days" → 12 results
Search: "Status: Needs Review AND Compliance: HIPAA" → 8 results
Search: "Owner: John Smith AND Tag: Urgent" → 3 results
Reports using tags:
-
Show all "Unverified" documents (status check)
-
Show all "Expiring Soon" documents (compliance alert)
-
Show all "Fraud Risk" documents (security review)
Compliance Relevance
-
✅ HIPAA: Tag sensitive PHI, track document type for retention
-
✅ GDPR: Tag "Personal Data", track "Right to Deletion" documents
-
✅ E-Discovery: Tag "Relevant to Litigation", "Privilege"
Business Benefit
📊 Instant Document Retrieval — Instead of "Where's that client's tax return from 2024?" taking 30 minutes to search emails, one tagged search takes 5 seconds.
6. Feature #4: Advanced Reporting & Analytics
What It Is
Pre-built dashboards and custom reports showing file transfer patterns, compliance adherence, user activity, and process efficiency metrics.
Pre-Built Reports
Activity Reports
-
File Transfer Volume: Charts showing files transferred per day/week/month
-
Top Users: Who uploads/downloads most frequently
-
File Types: Distribution of PDF vs. DOCX vs. other types
-
Peak Hours: When most file transfers occur (identifies bottlenecks)
Compliance Reports
-
HIPAA Audit Report: All PHI access logged (who, when, from where)
-
PCI DSS Compliance: Payment card data access audit
-
GDPR Data Access Report: Track all access to EU resident data
-
Data Retention Report: Files approaching expiration, files deleted, archives
Performance Metrics
-
Average Time to Upload: How long files take (identifies slow connections)
-
Average Time to Download: User experience metric
-
Failed Transfers: Diagnosis and retry statistics
-
Processing Time: How long from upload → approval → completion
Security Reports
-
Unauthorized Access Attempts: Failed access logs
-
File Sharing Activity: Who shares with whom
-
Bulk Operations: Large batch uploads/downloads (fraud detection)
-
Anomalous Activity: User activity outside normal patterns
Custom Dashboards
Example 1: Finance Dashboard
-
Total loan applications submitted (count)
-
Average time from application → approval (days)
-
Percentage of applications with missing documents (quality metric)
-
Cost savings from automation (manual hours × hourly rate)
Example 2: Compliance Officer Dashboard
-
Files requiring retention review (count)
-
Compliance violations detected (count)
-
Days since last audit (timestamp)
-
Upcoming audit deadlines (calendar)
Example 3: Operations Manager Dashboard
-
Files processed today (count)
-
Average processing time (minutes)
-
Peak load hours (chart)
-
Team productivity (files processed per user)
Export & Sharing
-
Export reports as PDF, Excel, or CSV
-
Schedule reports (email daily/weekly/monthly summaries)
-
Share dashboards with stakeholders (read-only)
-
API access for custom BI integration
Compliance Relevance
-
✅ All Regulations: Audit trail export for compliance reviews
-
✅ SOC2: Report on access controls and compliance adherence
-
✅ Internal Audits: Prove compliance with corporate policies
Business Benefit
📈 Data-Driven Decision Making — See exactly where bottlenecks are (e.g., "approvals take 5 days") and measure impact of process improvements ("automation reduced approval time to 2 hours").
7. Feature #5: Multi-Compliance Support
What It Is
SFT is built with compliance controls baked into every feature—not an afterthought. Support for multiple regulatory frameworks means one solution covers all your compliance needs.
HIPAA (Healthcare)
Requirements SFT Addresses:
-
✅ Encryption: AES-256 encryption in transit & at rest
-
✅ Access Controls: Role-based permissions, audit of all access
-
✅ Audit Trail: Complete logging of who accessed PHI, when, from where
-
✅ Business Associate Agreement: Signed BAA available
-
✅ Data Integrity: Checksums prevent file tampering
-
✅ Breach Notification: Audit logs support breach investigation
-
✅ Encryption Key Management: Keys managed securely by Salesforce
Proof of Compliance:
-
HIPAA BAA (Business Associate Agreement) signed with Cloud Maven
-
SOC2 Type II audit certifies compliance
-
Annual penetration testing
Example Use Case: Patient portal → uploads insurance docs with SSN, medical history → auto-tagged "PHI" → encrypted AES-256 → logged in audit trail → shared only with authorized doctors → deleted after 6 years (HIPAA retention) → all actions logged for compliance audit
PCI DSS (Financial Services)
Requirements SFT Addresses:
-
✅ Encryption: AES-256 encryption of payment card data
-
✅ Access Controls: Restrict who can access card data
-
✅ Audit Trail: Log all access to card data
-
✅ Network Security: TLS 1.2+ for transmission
-
✅ Vulnerability Management: Regular security assessments
-
✅ Compliance Documentation: Reports proving compliance
Proof of Compliance:
-
PCI DSS Level 1 certified
-
Annual third-party audit
-
Penetration testing quarterly
Example Use Case: Client uploads scanned ID with card number → file tagged "PCI-DSS Data" → encrypted AES-256 → access restricted to compliance team only → 1-year retention → audit logs track every access → deleted after retention expires with cryptographic erasure
GDPR (Europe & EU Residents)
Requirements SFT Addresses:
-
✅ Data Portability: Export user data in standard format
-
✅ Right to Deletion: One-click data deletion with cryptographic erasure
-
✅ Consent Tracking: Log consent for data processing
-
✅ Data Residency: Option to store data in EU (not just US)
-
✅ Data Processing Agreement: DPA available with Cloud Maven
-
✅ Breach Notification: 72-hour breach notification process
-
✅ Privacy by Design: Encryption and access controls default-on
Proof of Compliance:
-
GDPR Data Processing Agreement (DPA)
-
Standard Contractual Clauses (SCCs) for US-EU transfers
-
Privacy Impact Assessment (PIA) available
Example Use Case: EU resident customer submits personal data → file tagged "EU Personal Data" → stored in EU data center → auto-logged for GDPR audit → right-to-deletion request → entire file deleted with cryptographic erasure within 30 days → deletion logged in audit trail
FERPA (Education)
Requirements SFT Addresses:
-
✅ Student Privacy: Protect education records
-
✅ Access Controls: Only authorized educators can access
-
✅ Audit Trail: Log all access to student records
-
✅ Data Retention: Configure retention periods (typically 7 years)
-
✅ Directory Information: Configure what can be publicly shared
-
✅ Parental Rights: Support parental access to student records
Proof of Compliance:
-
FERPA compliance documentation
-
Audit reports showing access controls
Example Use Case: Student uploads transcript, financial aid forms → tagged "FERPA Student Record" → access restricted to admissions staff → parent portal allows parent to view student's records → all access logged → deleted after student graduates + 7 years
SOC2 Type II (Data Security)
Requirements SFT Addresses:
-
✅ Security: Encryption, access controls, monitoring
-
✅ Availability: 99.9% uptime SLA, disaster recovery
-
✅ Processing Integrity: Accurate and complete processing
-
✅ Confidentiality: Data encryption and access controls
-
✅ Privacy: Data handling per privacy policies
Proof of Compliance:
-
Annual SOC2 Type II audit by Big 4 auditor
-
Audit report available under NDA
Additional Frameworks Supported
-
✅ GLBA (Gramm-Leach-Bliley Act) — Financial privacy
-
✅ CCPA (California Consumer Privacy Act) — Data privacy
-
✅ CASL (Canada's Anti-Spam Legislation) — Canadian compliance
-
✅ ISO 27001 — Information security management
Business Benefit
🌍 One Solution, All Regulations — Instead of buying separate tools for HIPAA compliance, PCI compliance, GDPR, etc., SFT handles all requirements in one platform.
8. Feature #6: User-Friendly Interface
What It Is
SFT is built for business users, not IT specialists. Intuitive UI, minimal buttons, clear workflows—most users are productive within 5 minutes.
Key UI/UX Features
Upload Files
One-click upload:
1. Click "Upload File" button
2. Select file from computer
3. File uploaded, encrypted, and logged in <1 second
4. Auto-tagged based on rules
5. Ready to share
No dropdowns, no configuration, no friction.
Share Files
Share securely:
1. Click file
2. Click "Share"
3. Enter recipient email or select from Contacts
4. Recipient gets encrypted link (no direct access)
5. Recipient downloads file
6. Done. All logged in audit trail.
No passwords, no separate logins, no friction.
Search Files
Find in seconds:
1. Click search box
2. Type "Tax Return" or "Jane Smith" or tag "Urgent"
3. Results appear instantly (indexed search)
4. Click file to preview
5. Done.
No digging through folders, no email scanning, no lost files.
View Audit Trail
See who accessed what:
1. Click file
2. Click "Audit Trail"
3. See: User, Action, Timestamp, IP Address, Device
4. Export to PDF for compliance audit
5. Done.
No manual logging, no spreadsheets, no guessing.
Mobile Experience
-
Full feature access on iOS & Android via Salesforce mobile app
-
Touch-optimized interface
-
Offline access to cached files
-
Same security/audit trail on mobile
Accessibility
-
WCAG 2.1 AAA compliant
-
Keyboard navigation
-
Screen reader support
-
High contrast mode
Business Benefit
👤 Minimal Training Required — Most users need <5 minutes to get started. IT doesn't need to provide extensive training, and users adopt quickly.
9. Feature #7: Configurable Policies & Governance
What It Is
Admins can define rules around file handling—who can upload, who can download, file size limits, retention policies, sharing rules—all without code.
Policy Types
Access Policies
Example: Loan documents can only be uploaded by "Loan Officers" role
- Who can upload? (by role, by user)
- Who can download? (by role, by record owner)
- Who can share? (anyone, only admin, only owner)
- Who can delete? (only admin, only uploader)
File Policies
Example: All financial documents must be encrypted
- Max file size: 2 GB
- Allowed file types: PDF, DOCX, XLS, ZIP (block .exe, .bat)
- Virus scanning: Enabled (scan all files)
- Encryption: Mandatory (AES-256)
Retention Policies
Example: Tax returns kept 7 years, then auto-deleted
- Retention period: 7 years
- Deletion method: Cryptographic erasure (completely unrecoverable)
- Notifications: Alert admin 30 days before expiration
- Compliance: Auto-log deletion for audit trail
Sharing Policies
Example: Healthcare providers can share records with patients only
- Internal sharing: Enable (within organization)
- External sharing: Enable/Disable
- Link expiration: 7 days (link auto-expires)
- Require MFA: Multi-factor auth for sensitive files
Compliance Policies
Example: All documents tagged "HIPAA" must be logged for audit
- Audit logging: Mandatory for HIPAA files
- Encryption: Mandatory for HIPAA files
- Retention: Locked to 6 years (cannot be changed)
- Sharing restrictions: Cannot share externally
Visual Policy Builder
Create policy without code:
IF file type = "Tax Return"
THEN apply retention policy = "7 years"
AND apply encryption = "AES-256"
AND auto-tag = "Financial Document"
AND require approval before sharing = Yes
AND notify compliance officer when accessed
Visual drag-and-drop, no coding required.
Policy Enforcement
-
Policies automatically enforced in real-time
-
Violations prevent action (e.g., "Can't upload .exe file, blocked by policy")
-
Audit trail logs policy violations for compliance review
-
Compliance officer alerts for policy violations
Compliance Relevance
-
✅ HIPAA: Enforce encryption and access controls per policy
-
✅ GDPR: Enforce deletion policies and consent requirements
-
✅ PCI DSS: Restrict access and require encryption
Business Benefit
⚙️ Governance Without Complexity — IT/Compliance can define strict rules (e.g., "all financial docs encrypted, kept 7 years, no external sharing") and Salesforce auto-enforces them. No workarounds, no human error.
10. Feature #8: Mobile & Desktop Access
What It Is
Access SFT on any device—desktop, tablet, or mobile—with full feature parity. Upload, download, share, and audit files from anywhere.
Desktop Access
-
Full Salesforce web interface
-
All SFT features available
-
Keyboard shortcuts for power users
-
Bulk upload (drag & drop)
-
Offline capabilities (Salesforce offline features)
Mobile App Access
-
iOS: Full featured app via Salesforce
-
Android: Full featured app via Salesforce
-
Upload files from camera or device storage
-
Download and open files inline
-
Share files with one tap
-
Complete audit trail access
-
Works on WiFi and mobile networks (4G/5G)
Offline Capabilities
-
Cached files accessible offline
-
Cannot upload/share while offline
-
Sync when reconnected
-
Offline changes sync automatically
Security on Mobile
-
Same AES-256 encryption as desktop
-
Mobile device management (MDM) compatible
-
Passcode protection on app
-
Biometric unlock (fingerprint, Face ID)
-
Auto-logout after inactivity
Real-World Scenarios
Scenario 1: Healthcare Provider on Rounds
-
Doctor visits patient
-
Opens Salesforce mobile app
-
Views patient records (including uploaded documents)
-
Discusses treatment with patient
-
Later: Uploads follow-up notes securely
-
All logged in HIPAA audit trail
Scenario 2: Loan Officer in Field
-
Loan officer meets with applicant
-
Opens SFT on mobile
-
Captures applicant's ID with camera
-
File uploaded, encrypted, stored
-
Real-time: Auto-routed to underwriter
-
Applicant sees immediate confirmation
Scenario 3: Government Employee Working from Home
-
Citizen submits permit application via portal
-
Officer working from home views on mobile
-
Officer reviews documents, approves
-
Citizen notified automatically
-
All logged for FOIA requests
Business Benefit
📱 Work Anywhere — Teams aren't confined to desk. Can work from home, in field, at client site with same security and compliance.
11. Feature #9: Complete Audit Trail & Logging
What It Is
Every action in SFT is logged with complete transparency. Who accessed what file, when, from where, on what device—everything tracked automatically.
What Gets Logged
|
Event |
Logged Details |
|---|---|
|
File Upload |
User, timestamp, file name, file size, file type, source (portal, API, manual), IP address, device type |
|
File Download |
User, timestamp, file name, device type, IP address, country (geo-location) |
|
File Shared |
User sharing, recipient, timestamp, link expiration date, access level (view/download) |
|
File Access |
User, timestamp, action (view, download, print), duration, IP address, device |
|
File Deleted |
User, timestamp, file name, reason (retention policy, manual delete), archive status |
|
Policy Violation |
Violation type, user attempted action, policy violated, timestamp, enforcement action |
|
Permission Change |
Who changed permissions, timestamp, what changed (before/after), approval status |
|
Configuration Change |
Admin, timestamp, setting changed (before/after), reason |
Audit Trail Example: Patient Record
Patient uploads medical records:
2024-08-20 10:15:23 | Patient_John_Smith | Upload | file_lab_results.pdf | 2.4 MB | IP: 203.45.67.89 | Device: iPhone
Provider accesses records:
2024-08-20 11:30:45 | Dr_Jane_Williams | Access | file_lab_results.pdf | IP: 192.168.1.45 | Device: Desktop | Duration: 3 minutes
Provider shares with specialist:
2024-08-20 12:00:12 | Dr_Jane_Williams | Share | file_lab_results.pdf | Recipient: Dr_Mark_Jones | Link expiration: 2024-08-27
Specialist accesses records:
2024-08-20 14:22:33 | Dr_Mark_Jones | Access | file_lab_results.pdf | IP: 192.168.1.78 | Device: Desktop | Duration: 5 minutes
File retention policy triggers deletion:
2024-08-20 (7 years later) | System | Auto-Delete | file_lab_results.pdf | Reason: Retention policy (6 years) | Deletion method: Cryptographic erasure
Audit Report Generation
Pre-built reports for compliance:
HIPAA Audit Report:
- All PHI access (patient records) - last 90 days
- Who accessed, when, from where
- Unauthorized access attempts
- Compliance status: ✅ PASS
- Exported as PDF for compliance review
PCI DSS Audit Report:
- All payment card data access - last 90 days
- Who accessed, when, from where
- Encryption validation
- Access control validation
- Compliance status: ✅ PASS
GDPR Audit Report:
- All EU resident data access
- Data portability requests (exported)
- Data deletion requests (completed)
- Data retention compliance
- Compliance status: ✅ PASS
Export Options
-
CSV: For analysis in Excel or BI tools
-
PDF: For compliance audit submission
-
JSON: For API integration with security tools
-
Salesforce Report: Native Salesforce analytics
Retention of Audit Logs
-
Audit logs retained for 10 years (industry standard)
-
Not subject to file retention policy (logs kept even after files deleted)
-
Immutable (cannot be modified or deleted)
Compliance Relevance
-
✅ HIPAA: Proves who accessed PHI and when
-
✅ PCI DSS: Proves access controls and encryption
-
✅ GDPR: Proves data handling and user requests
-
✅ E-Discovery: Provides complete chain of custody
Business Benefit
📋 Compliance Audits in Minutes — Instead of manually compiling access logs from multiple systems (email, shared drives, etc.), generate a complete audit report in one click.
12. Feature #10: Role-Based Access Control (RBAC)
What It Is
Granular permission management. Define what each role/user can do (upload, download, share, delete, audit) without custom code.
Pre-Defined Roles
|
Role |
Permissions |
Typical User |
|---|---|---|
|
Viewer |
View files only, no download |
Clients, read-only stakeholders |
|
User |
Upload, download, view files |
Business users, operators |
|
Uploader |
Upload and manage own files |
Data entry, analysts |
|
Sharer |
Upload, download, share with others |
Team leads, coordinators |
|
Approver |
Review and approve documents |
Managers, compliance officers |
|
Admin |
Full access, manage policies, users |
IT admins, compliance directors |
Custom Roles
Create custom roles for specific scenarios:
Role: "Loan Officer"
Permissions:
- Upload: Yes (loan documents only)
- Download: Yes (own applicant documents)
- Share: Yes (with underwriter only)
- Delete: No (cannot delete)
- Audit: Yes (can view audit trail)
- Export: Yes (can export for compliance)
- Policy Override: No (must follow policies)
Role: "Healthcare Compliance Officer"
Permissions:
- Upload: No (not needed)
- Download: Yes (all patient records)
- Share: No (cannot share)
- Delete: No (retention policy enforced)
- Audit: Yes (full audit access)
- Export: Yes (HIPAA reports)
- Policy Override: Yes (if justified)
Record-Level Access Control
Control access at the record level (not just by role):
Example: Loan officer can only see loan files for their assigned accounts
Role: Loan Officer (John Smith)
Files accessible:
- Account: ABC Corp (assigned to John Smith) ✅ Can access
- Account: XYZ Inc (assigned to Jane Williams) ❌ Cannot access
- File: abc_corp_tax_return.pdf ✅ Accessible
- File: xyz_inc_tax_return.pdf ❌ Not accessible
Time-Based Access Control
Control access based on time:
Example: Temporary contractor access expires after 30 days
User: Contractor_TempStaff
Access: Yes (files for Project_X only)
Duration: 30 days (2024-08-20 to 2024-09-19)
Auto-revoke: 2024-09-19 (access automatically removed)
Reason: Contract ended
Conditional Access
Apply access controls conditionally:
Rule: If accessing from outside company IP, require MFA (multi-factor auth)
Rule: If downloading >100 files at once, require approval
Rule: If accessing after 5 PM, require manager approval
Rule: If accessing from high-risk country, block access
Delegation
Allow managers to delegate file management:
Manager: John Smith
Delegates file approval to: Jane Williams
Duration: 2 weeks (while John is on vacation)
Auto-revoke: Date John returns
Scope: All files in "Approvals Pending" queue
Audit Trail of Permissions
All permission changes logged:
2024-08-20 10:00 | Admin | Changed role | User: John Smith | From: User → Approver
2024-08-20 10:05 | Admin | Added permission | User: Jane Williams | Permission: Export HIPAA reports
2024-08-21 14:30 | Manager | Delegated approval | From: John Smith | To: Sarah Jones | Duration: 2 weeks
2024-08-22 09:00 | John Smith | Revoked access | User: Contractor_X | Reason: Contract ended
Compliance Relevance
-
✅ HIPAA: Restrict PHI access to authorized staff only
-
✅ PCI DSS: Restrict payment card data access by role
-
✅ GDPR: Implement "principle of least privilege"
Business Benefit
🔐 Granular Security — CEO doesn't see loan officer's applicant files. Loan officer doesn't see HR personnel files. Only authorized users access sensitive data.
13. Comparison: SFT Features vs. Alternatives
|
Capability |
SFT |
|
Shared Drives |
Third-Party Tools |
|---|---|---|---|---|
|
Encryption |
✅ AES-256 |
❌ None |
⚠️ Optional |
✅ Yes |
|
Automation |
✅ Full |
❌ None |
❌ None |
⚠️ Limited |
|
Audit Trail |
✅ Complete |
❌ None |
⚠️ Limited |
✅ Basic |
|
Compliance Templates |
✅ HIPAA/PCI/GDPR/FERPA |
❌ None |
❌ None |
⚠️ Partial |
|
Salesforce Integration |
✅ Native |
❌ None |
❌ None |
⚠️ Requires API |
|
Mobile App |
✅ Full |
✅ Yes |
⚠️ Limited |
✅ Yes |
|
User Training Needed |
✅ <5 minutes |
✅ None |
✅ Minimal |
⚠️ 1-2 hours |
|
IT Support Required |
✅ Minimal |
✅ Minimal |
⚠️ Moderate |
⚠️ High |
|
Cost |
⚠️ Per-org pricing |
✅ Included |
✅ Included |
⚠️ $20-100/user/month |
|
Workflow Automation |
✅ Full |
❌ None |
❌ None |
⚠️ Requires code |
14. Next Steps
Want to See These Features in Action?
-
📘 Admin Setup Guide — Learn how to configure each feature
-
🎥 Video Tutorials — See features demonstrated (5-10 min each)
-
🧪 Free Trial — Test all features yourself (30 days, no CC required)
-
💬 Schedule a Demo — See features live with your specific use case
15. Contact
Questions about features?
📧 Email: features@cloudmaveninc.com
📞 Phone: 1-800-XXX-XXXX (ext. Product)
🌐 Website:
http://www.cloudmaveninc.com
© 2026 Cloud Maven, Inc. All Rights Reserved.