Secure File Transport

Features

Secure File Transport gives you 10 powerful features—each designed to solve a real business problem. Whether you need to speed up approvals, reduce compliance risk, or cut manual work, these features deliver measurable results. This page explores each feature and shows how it helps your business. For a quick overview, see Overview.


Secure File Transfer & Encryption

Protect Files During Transfer and Storage

Secure File Transport uses encryption and security controls to help protect files from unauthorized access while they are being transferred and stored.

Files can be securely exchanged without relying on traditional email attachments or unsecured file-sharing methods.

How it works:

  1. A user uploads or sends a file through SFT.

  2. The file is transferred using secure communication protocols.

  3. Files are stored using configured security controls.

  4. Access is restricted based on the user's permissions and configuration.

Product Benefits:

  • Protect sensitive documents during transfer and storage.

  • Reduce reliance on email attachments for sensitive information.

  • Restrict access to authorized users and systems.

  • Provide a secure mechanism for exchanging documents with customers and internal teams.


Automation

Automate Collection of Documents

Secure File Transport can automate repetitive file-management activities using configurable rules and workflows. Business can configure automation to determine when files should be collected and processed after they are received or uploaded.

Example: Loan Processing

Before

With SFT

3-4 days (applicant emails → loan officer downloads → routes to underwriter → manual status updates)

Same day (applicant uploads → auto-routes → auto-logs → underwriter notified instantly)

Product Benefits:

  • Reduce manual file-handling activities.

  • Standardize document-processing workflows.

  • Route files based on configured business rules.

  • Improve processing consistency and turnaround time.


File Tagging & Organization

Organize and quickly locate documents

SFT provides mechanisms for organizing files using configurable tags, making it easier for users to locate documents when needed. Files are auto tagged as soon as they are uploaded by the end user.

Example:

A user needs to locate a client's tax return.

Instead of searching through multiple email conversations or shared folders, users can quickly find files associated with the relevant record using tags

Product Benefits:

  • Improve document organization.

  • Reduce time spent locating files.

  • Create a consistent document classification structure.

  • Make documents easier to retrieve and manage.


Reporting & Monitoring

Visibility Into File Activity and Processing

SFT provides reporting and monitoring capabilities that help administrators and users understand file activity and identify areas that may require attention.

Depending on the configured implementation, organizations can monitor information such as:

  • Files received and processed

  • File status

  • Processing activity

  • Transfer activity

  • Failed or pending transactions

  • User activity

Product Benefits:

  • Improve operational visibility.

  • Identify processing issues and bottlenecks.

  • Monitor file-transfer activity.

  • Support operational and management reporting.


Built-In Compliance

Support Your Organization's Security and Compliance Requirements

Instead of buying separate compliance tools for HIPAA, PCI, GDPR, FERPA, etc., SFT handles them all. Encryption, audit logs, access controls, retention policies—all automatically enforced.

  • All HIPAA controls auto-enforced

  • Access automatically logged (no manual work)

Regulations SFT Covers

Regulation

What It Protects

Business Benefit

HIPAA

Patient medical records

Healthcare providers pass audits, protect patient privacy

PCI DSS

Payment card data

Financial companies secure card data, reduce fraud

GDPR

EU resident personal data

European companies comply with privacy laws, avoid fines

FERPA

Student education records

Schools protect student data, comply with education law

SOC2

Overall security controls

Software companies prove security to customers


Mobile & Remote Access

Work from Anywhere, Securely

What It Means for Your Business

Loan officers meeting clients can upload documents from their phone. Doctors on hospital rounds can access patient files. Remote employees can work from home with same security as office. No VPN needed, no special setup.

Real-World Example

Scenario 1: Loan Officer in Field

  • Client meeting: "I have my recent tax return with me"

  • Loan officer: Opens phone, takes picture, uploads to SFT

  • File instantly encrypted, routed to underwriter

  • Underwriter gets notification: "New doc ready"

  • Same day: File reviewed, decision made

  • Result: Faster decisions, better customer experience

Scenario 2: Healthcare Provider from Home

  • Doctor working from home during sick leave

  • Patient calls: "Can I see my test results?"

  • Doctor: Opens phone, views encrypted patient file

  • Doctor: Calls patient back with results

  • All access logged for HIPAA compliance

  • Result: Patients served, HIPAA logged, compliance maintained

Scenario 3: Compliance Officer Remote Work

  • Compliance officer works from Starbucks (WiFi)

  • Manager asks: "Are we audit-ready?"

  • Officer: Opens app, runs compliance report

  • Officer: See all files, access logs, security status

  • Officer: Email report to management

  • Result: Remote work enabled, compliance maintained

Business Benefit

📱 Work Anywhere, Anytime — Remote workers don't need special VPN or IT setup. Same security as office. Perfect for post-COVID flexible work, field teams, and distributed organizations.


11. Feature #9: Audit Trail

Compliance in a Click

What It Means for Your Business

Every file action is automatically logged: who accessed it, when, from where, for how long. No manual tracking needed. When auditors ask "Who accessed this patient file?", you have the answer in 1 second.

Real-World Example

Before SFT (manual audit):

  • Auditor asks: "Who accessed patient files in June?"

  • Compliance officer: Spends 3 days manually reviewing logs

  • Compliance officer: Creates spreadsheet of access

  • Compliance officer: Writes audit report

  • Time: 16+ hours

  • Risk: Missed access, incomplete report

After SFT (automatic audit):

  • Auditor asks: "Who accessed patient files in June?"

  • Compliance officer: Clicks "Generate HIPAA Audit Report"

  • System: Generates report in 10 seconds

  • Compliance officer: Reviews automated report

  • Time: 30 minutes

  • Result: Complete, accurate, professional report

What Gets Automatically Logged

Action

Automatically Logged

File uploaded

User, date/time, file size, file type, upload method

File downloaded

User, date/time, device type, location

File shared

User, recipient, date/time, link expiration

File accessed

User, date/time, duration accessed, IP address

File deleted

User, date/time, reason, approval status

Permission changed

User, what changed, date/time, reason

Policy violated

Violation type, user, date/time, action taken

Real-World Audit Scenario: Hospital

HIPAA Audit Log - June 2024

June 5, 10:15 AM - Patient John Smith's file accessed
  - Accessed by: Dr. Jane Williams (Cardiologist)
  - Device: Office desktop computer
  - IP: 192.168.1.45
  - Duration: 8 minutes
  - Action: Viewed file

June 5, 10:23 AM - File shared with specialist
  - Shared by: Dr. Jane Williams
  - Recipient: Dr. Mark Jones (Cardiologist)
  - Device: Office desktop
  - Link expiration: June 12 (7 days)

June 5, 2:30 PM - File accessed by specialist
  - Accessed by: Dr. Mark Jones
  - Device: Mobile phone
  - Location: Cardiology clinic
  - Duration: 15 minutes

June 12 - Link expired (automatic)
  - Dr. Mark Jones can no longer access file
  - System automatically revoked access
  - Logged in audit trail

Result: Complete transparency. Auditors can see every access.
All legitimate. No unauthorized access. HIPAA compliant. ✓

Business Benefit

📋 Audits Take Hours, Not Weeks — Auto-generated audit logs means compliance reviews go from 3-week projects to 1-hour reviews. Plus, you prove compliance happened—no guessing.


Role-Based Access Control

Only Authorized People See Sensitive Data

What It Means for Your Business

You decide exactly who can access which files: Finance staff see financial docs, HR staff see employee docs, executives see everything. If someone leaves the company, their access disappears instantly.

Real-World Example

Before SFT (manual access control):

  • New contractor hired: "They need to see client files"

  • Admin: Manually adds contractor to 15 file folders

  • Contractor finishes project: "OK, they're done"

  • Admin: Remembers to remove access (sometimes forgets)

  • Risk: Former contractor can still see confidential files

  • Cost: Data breach, compliance violation

After SFT (automatic access control):

  • New contractor hired: Admin sets role "Contractor_ABC"

  • Rule: Can access files tagged "Project_ABC" only

  • Contractor: Can see only their project files

  • Contractor finishes project: Admin changes role to "Contractor_Inactive"

  • System: Instantly revokes all access

  • Result: Clean access control, zero risk of "forgotten" access

Real-World Access Control Examples

Financial Services Company:

  • Loan Officer John Smith: Can see only his client files (50 clients)

  • Underwriter Jane Williams: Can see all loan files awaiting review (500+ files)

  • CEO: Can see all files across company

  • Compliance Officer: Can see all files + audit logs

  • Contractor: Can see only files tagged "Contract_XYZ"

  • Result: Least-privilege security, no one sees data they don't need

Healthcare Organization:

  • Front Desk Staff: Can see patient names/contact info only (no medical records)

  • Doctor: Can see patient's medical records (records they created/authorized)

  • Nurse: Can see medical records + medications

  • Billing Staff: Can see billing/insurance info only (no medical data)

  • Compliance Officer: Can see all patient files + audit logs

  • Patient: Can see own medical records only (via patient portal)

  • Result: Privacy maintained, patients trust healthcare organization

Law Firm:

  • Associate Attorney: Can see only files for cases they're assigned

  • Partner: Can see all cases (attorney oversight)

  • Paralegal: Can see only documents for their attorney's cases

  • Opposing Counsel: Cannot see any files (external access blocked)

  • Court: Can see discovery files (specifically approved by attorney)

  • Result: Attorney-client privilege maintained, court compliance

Business Benefit

🔐 Insider Threat Eliminated — Only authorized people access sensitive data. Employee leaves? Access gone instantly. Contractor finishes? Access gone instantly. No data exposure, zero compliance risk.


13. Comparing SFT to Other Approaches

Capability

SFT

Email

Shared Drives

Other Tools

Files automatically encrypted?

✅ Yes

❌ No

⚠️ Optional

✅ Yes

Workflows automate?

✅ Fully

❌ No

❌ No

⚠️ Limited

Complete audit trail?

✅ Yes

❌ No

⚠️ Limited

✅ Basic

Built-in compliance (HIPAA/PCI/GDPR)?

✅ Yes

❌ No

❌ No

⚠️ Partial

Integrated with Salesforce?

✅ Native

❌ No

❌ No

⚠️ Requires setup

Mobile app included?

✅ Yes

✅ Yes

⚠️ Limited

✅ Yes

Easy to learn?

✅ <5 min

✅ None

✅ Minimal

⚠️ 1-2 hours

Requires IT support?

✅ Minimal

✅ None

⚠️ Moderate

⚠️ Ongoing

Cost per user/month?

⚠️ Org-wide pricing

✅ Included

✅ Included

⚠️ $20-100/person

Reduces manual work 70%?

✅ Yes

❌ No

❌ No

⚠️ Partial


14. Next Steps

Want to See These Features in Action?


15. Contact

Have questions?

📧 Email: features@cloudmaveninc.com
📞 Phone: 1-800-XXX-XXXX (ext. Product)
🌐 Website:

http://www.cloudmaveninc.com


© 2026 Cloud Maven, Inc. All Rights Reserved.


4. Feature #2: Automation

Let the System Do the Heavy Lifting

What It Means for Your Business

Create "if-then" rules without writing code. "If client uploads ID, then auto-verify and route to compliance team." "If applicant uploads 3 required documents, then trigger loan underwriting approval." Rules run automatically 24/7—no humans involved.

Real-World Example #1: Loan Processing Automation

Traditional Process (4 days, lots of manual work):

  1. Applicant calls: "Where do I send my documents?"

  2. Admin sends email: "Email to loans@company.com"

  3. Applicant emails tax return from personal email

  4. Loan officer receives email, downloads file, creates folder

  5. Loan officer manually checks: "Did we get all 3 required documents?"

  6. Missing document! → Loan officer emails applicant: "Need pay stub"

  7. Applicant emails pay stub (wrong format)

  8. Loan officer calls applicant: "We need a recent pay stub"

  9. Applicant re-sends correct pay stub

  10. Loan officer organizes all docs, emails to underwriter: "Ready to review"

  11. Underwriter receives email, downloads files, updates status

  12. Total time: 4 days (because of email delays + back-and-forth)

  13. Manual steps: 12, Error points: 10+

With SFT Automation (same day, zero manual work):

  1. Applicant goes to secure portal (1 minute)

  2. Applicant uploads documents (3 minutes)

  3. System automatically:

    • ✓ Receives all files

    • ✓ Checks: Do we have all 3 required documents?

    • ✓ If missing: Sends applicant email "Please upload pay stub"

    • ✓ When complete: Tags all docs as "Complete Application"

    • ✓ Routes to underwriter automatically

    • ✓ Sends underwriter email: "New application ready to review"

    • ✓ Logs everything for audit trail

  4. Underwriter receives notification, starts review

  5. Total time: 30 minutes

  6. Manual steps: 0, Error points: 0

Business Impact:

  • ✅ Reduce loan processing time from 4 days to 4 hours (90% faster)

  • ✅ Eliminate back-and-forth emails (customer happier)

  • ✅ Zero missing documents

  • ✅ Loan officer has time for other work

  • ✅ Underwriter reviews instantly (more loans funded, more revenue)

Real-World Example #2: Patient Records Automation (Healthcare)

Old Process (manual):

  1. Doctor creates medical summary

  2. Receptionist receives handwritten note

  3. Receptionist scans to PDF

  4. Receptionist manually files in patient folder

  5. Receptionist manually logs access for compliance

  6. Patient calls: "Can I see my results?"

  7. Staff manually retrieves file

  8. Staff manually emails to patient

  9. Problems: Lost emails, missing records, compliance gaps, slow patient service

With SFT Automation (instant):

  1. Doctor uploads medical summary to patient's file (1 click)

  2. System automatically:

    • ✓ Tags it: "Medical Record - Lab Results"

    • ✓ Encrypts the file (HIPAA compliant)

    • ✓ Logs access: who, when, where (audit trail ready)

    • ✓ Creates patient portal access (patient can view instantly)

    • ✓ Sends notification to patient: "New results available"

  3. Patient opens app, sees results immediately

  4. Patient can print/download

  5. All actions logged for HIPAA compliance

  6. Total time: Instant

  7. Manual steps: 0

Business Impact:

  • ✅ Patient satisfaction (instant access to records)

  • ✅ Staff saves 30+ minutes per day (less manual filing)

  • ✅ HIPAA compliance automatic (zero violations)

  • ✅ Audit prep is 1 click (was 16 hours)

  • ✅ No lost records or miscommunications

Real-World Example #3: Client Onboarding (Financial Services)

Traditional Process (5-7 days):

  1. New client: Receives email "Send us KYC documents"

  2. Client emails: ID, proof of address, bank statement

  3. Compliance officer checks email manually: "Do we have everything?"

  4. Missing one document! Officer emails client: "Please resend proof of address"

  5. Client resends (but different format)

  6. Officer: "This doesn't match our requirements"

  7. Back-and-forth emails... 3 days later, correct documents received

  8. Officer manually verifies each document

  9. Officer creates compliance checklist (manually)

  10. Officer updates account status in system (manually)

  11. Account finally "ready to fund"

  12. Total time: 5-7 days

  13. Client experience: Frustrated (lots of back-and-forth)

With SFT Automation (1 day):

  1. New client: Receives email with secure portal link

  2. Client logs in (2 minutes)

  3. Client uploads: ID, proof of address, bank statement (3 minutes)

  4. System automatically:

    • ✓ Checks: Do we have all 3 required documents?

    • ✓ If missing: Sends client email "Please upload proof of address"

    • ✓ Verifies documents (OCR technology reads ID, extracts info)

    • ✓ Creates compliance checklist (auto-populated)

    • ✓ Routes to compliance officer

    • ✓ Logs everything for audit

  5. Compliance officer reviews complete checklist in dashboard (5 minutes)

  6. Officer approves

  7. System automatically updates account: "KYC Complete - Ready to Fund"

  8. Client gets notification: "Your account is ready!"

  9. Total time: 1 day

  10. Client experience: Fast, simple, professional

Business Impact:

  • ✅ Onboarding 80% faster (5 days → 1 day)

  • ✅ Customer satisfaction (simple, fast process)

  • ✅ Compliance guaranteed (no missing docs, complete checklists)

  • ✅ Compliance officer saves 4+ hours per client

  • ✅ More clients funded, more revenue

Key Automation Scenarios

What Can Be Automated:

  • ✅ Document routing (auto-send to right person)

  • ✅ Required document checks (auto-verify all docs received)

  • ✅ Compliance checklists (auto-populate, auto-route)

  • ✅ Customer notifications (auto-email when docs received/reviewed)

  • ✅ Approvals (auto-trigger approval workflows)

  • ✅ Compliance logging (auto-log HIPAA/PCI/GDPR access)

  • ✅ File cleanup (auto-delete after retention period)

  • ✅ Escalations (auto-email if approval pending >2 days)

Rules You Can Create (No Code):

  • "If file type = tax return, auto-tag as 'Income Verification'"

  • "If all required docs uploaded, auto-route to underwriter"

  • "If file not approved within 2 days, send escalation email"

  • "If file is medical record, auto-log for HIPAA audit"

  • "If file expires in 30 days, send renewal reminder"

  • "If file is 5 years old, auto-delete per retention policy"

Business Benefit

🤖 Save 20+ Hours Per Week Per Employee — If your team spends 100 hours/week on file management, automation handles 70-90 hours of that. You just saved $80K-$120K/year in salary costs. Plus, processes run 24/7 (even nights/weekends).


5. Feature #3: Automatic File Tagging & Metadata

What It Is

Automatically organize and categorize files using searchable metadata tags. Users or admins can set rules to auto-tag files based on type, document content, or workflow stage.

Technical Details

  • Auto-Tagging: Rules-based tagging (if file type = "tax return", auto-tag "Financial Document")

  • Manual Tagging: Users can add custom tags (e.g., "Urgent", "Priority Client")

  • Metadata Fields: Document type, date received, source, compliance category, retention period, owner, status

  • Searchable: Full-text search across all metadata (find files in seconds)

  • Bulk Operations: Tag 100+ files at once

Tagging Examples

Healthcare:

Auto-tag rules:

  • PDF + mentions "lab results" → Tag: "Lab Results"

  • DOCX + mentions "discharge" → Tag: "Discharge Summary"

  • Any file + received from Insurance Co. → Tag: "Insurance Document"

Manual tags users add:

  • "Urgent - High Priority"

  • "Follow-up Required"

  • "Review for Authorization"

Financial Services:

Auto-tag rules:

  • "Form 1040" detected → Tag: "Tax Return"

  • Filename contains "W-2" → Tag: "Income Verification"

  • File from client upload portal → Tag: "KYC Submission"

Manual tags users add:

  • "Verified"

  • "Fraud Risk - Flag for Review"

  • "Pre-Approval"

Legal:

Auto-tag rules:

  • File marked "Privileged" → Tag: "Attorney-Client Privilege"

  • File from opposing counsel → Tag: "Discovery Document"

  • File type = "Email" → Tag: "Correspondence"

Search & Retrieval

Find files in seconds:

Search: "Tax Return" → 47 results across all clients
Search: "Tag: Lab Results AND Date: Last 30 Days" → 12 results
Search: "Status: Needs Review AND Compliance: HIPAA" → 8 results
Search: "Owner: John Smith AND Tag: Urgent" → 3 results

Reports using tags:

  • Show all "Unverified" documents (status check)

  • Show all "Expiring Soon" documents (compliance alert)

  • Show all "Fraud Risk" documents (security review)

Compliance Relevance

  • HIPAA: Tag sensitive PHI, track document type for retention

  • GDPR: Tag "Personal Data", track "Right to Deletion" documents

  • E-Discovery: Tag "Relevant to Litigation", "Privilege"

Business Benefit

📊 Instant Document Retrieval — Instead of "Where's that client's tax return from 2024?" taking 30 minutes to search emails, one tagged search takes 5 seconds.


6. Feature #4: Advanced Reporting & Analytics

What It Is

Pre-built dashboards and custom reports showing file transfer patterns, compliance adherence, user activity, and process efficiency metrics.

Pre-Built Reports

Activity Reports

  • File Transfer Volume: Charts showing files transferred per day/week/month

  • Top Users: Who uploads/downloads most frequently

  • File Types: Distribution of PDF vs. DOCX vs. other types

  • Peak Hours: When most file transfers occur (identifies bottlenecks)

Compliance Reports

  • HIPAA Audit Report: All PHI access logged (who, when, from where)

  • PCI DSS Compliance: Payment card data access audit

  • GDPR Data Access Report: Track all access to EU resident data

  • Data Retention Report: Files approaching expiration, files deleted, archives

Performance Metrics

  • Average Time to Upload: How long files take (identifies slow connections)

  • Average Time to Download: User experience metric

  • Failed Transfers: Diagnosis and retry statistics

  • Processing Time: How long from upload → approval → completion

Security Reports

  • Unauthorized Access Attempts: Failed access logs

  • File Sharing Activity: Who shares with whom

  • Bulk Operations: Large batch uploads/downloads (fraud detection)

  • Anomalous Activity: User activity outside normal patterns

Custom Dashboards

Example 1: Finance Dashboard

  • Total loan applications submitted (count)

  • Average time from application → approval (days)

  • Percentage of applications with missing documents (quality metric)

  • Cost savings from automation (manual hours × hourly rate)

Example 2: Compliance Officer Dashboard

  • Files requiring retention review (count)

  • Compliance violations detected (count)

  • Days since last audit (timestamp)

  • Upcoming audit deadlines (calendar)

Example 3: Operations Manager Dashboard

  • Files processed today (count)

  • Average processing time (minutes)

  • Peak load hours (chart)

  • Team productivity (files processed per user)

Export & Sharing

  • Export reports as PDF, Excel, or CSV

  • Schedule reports (email daily/weekly/monthly summaries)

  • Share dashboards with stakeholders (read-only)

  • API access for custom BI integration

Compliance Relevance

  • All Regulations: Audit trail export for compliance reviews

  • SOC2: Report on access controls and compliance adherence

  • Internal Audits: Prove compliance with corporate policies

Business Benefit

📈 Data-Driven Decision Making — See exactly where bottlenecks are (e.g., "approvals take 5 days") and measure impact of process improvements ("automation reduced approval time to 2 hours").


7. Feature #5: Multi-Compliance Support

What It Is

SFT is built with compliance controls baked into every feature—not an afterthought. Support for multiple regulatory frameworks means one solution covers all your compliance needs.

HIPAA (Healthcare)

Requirements SFT Addresses:

  • Encryption: AES-256 encryption in transit & at rest

  • Access Controls: Role-based permissions, audit of all access

  • Audit Trail: Complete logging of who accessed PHI, when, from where

  • Business Associate Agreement: Signed BAA available

  • Data Integrity: Checksums prevent file tampering

  • Breach Notification: Audit logs support breach investigation

  • Encryption Key Management: Keys managed securely by Salesforce

Proof of Compliance:

  • HIPAA BAA (Business Associate Agreement) signed with Cloud Maven

  • SOC2 Type II audit certifies compliance

  • Annual penetration testing

Example Use Case: Patient portal → uploads insurance docs with SSN, medical history → auto-tagged "PHI" → encrypted AES-256 → logged in audit trail → shared only with authorized doctors → deleted after 6 years (HIPAA retention) → all actions logged for compliance audit


PCI DSS (Financial Services)

Requirements SFT Addresses:

  • Encryption: AES-256 encryption of payment card data

  • Access Controls: Restrict who can access card data

  • Audit Trail: Log all access to card data

  • Network Security: TLS 1.2+ for transmission

  • Vulnerability Management: Regular security assessments

  • Compliance Documentation: Reports proving compliance

Proof of Compliance:

  • PCI DSS Level 1 certified

  • Annual third-party audit

  • Penetration testing quarterly

Example Use Case: Client uploads scanned ID with card number → file tagged "PCI-DSS Data" → encrypted AES-256 → access restricted to compliance team only → 1-year retention → audit logs track every access → deleted after retention expires with cryptographic erasure


GDPR (Europe & EU Residents)

Requirements SFT Addresses:

  • Data Portability: Export user data in standard format

  • Right to Deletion: One-click data deletion with cryptographic erasure

  • Consent Tracking: Log consent for data processing

  • Data Residency: Option to store data in EU (not just US)

  • Data Processing Agreement: DPA available with Cloud Maven

  • Breach Notification: 72-hour breach notification process

  • Privacy by Design: Encryption and access controls default-on

Proof of Compliance:

  • GDPR Data Processing Agreement (DPA)

  • Standard Contractual Clauses (SCCs) for US-EU transfers

  • Privacy Impact Assessment (PIA) available

Example Use Case: EU resident customer submits personal data → file tagged "EU Personal Data" → stored in EU data center → auto-logged for GDPR audit → right-to-deletion request → entire file deleted with cryptographic erasure within 30 days → deletion logged in audit trail


FERPA (Education)

Requirements SFT Addresses:

  • Student Privacy: Protect education records

  • Access Controls: Only authorized educators can access

  • Audit Trail: Log all access to student records

  • Data Retention: Configure retention periods (typically 7 years)

  • Directory Information: Configure what can be publicly shared

  • Parental Rights: Support parental access to student records

Proof of Compliance:

  • FERPA compliance documentation

  • Audit reports showing access controls

Example Use Case: Student uploads transcript, financial aid forms → tagged "FERPA Student Record" → access restricted to admissions staff → parent portal allows parent to view student's records → all access logged → deleted after student graduates + 7 years


SOC2 Type II (Data Security)

Requirements SFT Addresses:

  • Security: Encryption, access controls, monitoring

  • Availability: 99.9% uptime SLA, disaster recovery

  • Processing Integrity: Accurate and complete processing

  • Confidentiality: Data encryption and access controls

  • Privacy: Data handling per privacy policies

Proof of Compliance:

  • Annual SOC2 Type II audit by Big 4 auditor

  • Audit report available under NDA


Additional Frameworks Supported

  • GLBA (Gramm-Leach-Bliley Act) — Financial privacy

  • CCPA (California Consumer Privacy Act) — Data privacy

  • CASL (Canada's Anti-Spam Legislation) — Canadian compliance

  • ISO 27001 — Information security management

Business Benefit

🌍 One Solution, All Regulations — Instead of buying separate tools for HIPAA compliance, PCI compliance, GDPR, etc., SFT handles all requirements in one platform.


8. Feature #6: User-Friendly Interface

What It Is

SFT is built for business users, not IT specialists. Intuitive UI, minimal buttons, clear workflows—most users are productive within 5 minutes.

Key UI/UX Features

Upload Files

SQL
One-click upload:
1. Click "Upload File" button
2. Select file from computer
3. File uploaded, encrypted, and logged in <1 second
4. Auto-tagged based on rules
5. Ready to share

No dropdowns, no configuration, no friction.

Share Files

SQL
Share securely:
1. Click file
2. Click "Share"
3. Enter recipient email or select from Contacts
4. Recipient gets encrypted link (no direct access)
5. Recipient downloads file
6. Done. All logged in audit trail.

No passwords, no separate logins, no friction.

Search Files

Find in seconds:
1. Click search box
2. Type "Tax Return" or "Jane Smith" or tag "Urgent"
3. Results appear instantly (indexed search)
4. Click file to preview
5. Done.

No digging through folders, no email scanning, no lost files.

View Audit Trail

See who accessed what:
1. Click file
2. Click "Audit Trail"
3. See: User, Action, Timestamp, IP Address, Device
4. Export to PDF for compliance audit
5. Done.

No manual logging, no spreadsheets, no guessing.

Mobile Experience

  • Full feature access on iOS & Android via Salesforce mobile app

  • Touch-optimized interface

  • Offline access to cached files

  • Same security/audit trail on mobile

Accessibility

  • WCAG 2.1 AAA compliant

  • Keyboard navigation

  • Screen reader support

  • High contrast mode

Business Benefit

👤 Minimal Training Required — Most users need <5 minutes to get started. IT doesn't need to provide extensive training, and users adopt quickly.


9. Feature #7: Configurable Policies & Governance

What It Is

Admins can define rules around file handling—who can upload, who can download, file size limits, retention policies, sharing rules—all without code.

Policy Types

Access Policies

Example: Loan documents can only be uploaded by "Loan Officers" role
- Who can upload? (by role, by user)
- Who can download? (by role, by record owner)
- Who can share? (anyone, only admin, only owner)
- Who can delete? (only admin, only uploader)

File Policies

Example: All financial documents must be encrypted
- Max file size: 2 GB
- Allowed file types: PDF, DOCX, XLS, ZIP (block .exe, .bat)
- Virus scanning: Enabled (scan all files)
- Encryption: Mandatory (AES-256)

Retention Policies

Example: Tax returns kept 7 years, then auto-deleted
- Retention period: 7 years
- Deletion method: Cryptographic erasure (completely unrecoverable)
- Notifications: Alert admin 30 days before expiration
- Compliance: Auto-log deletion for audit trail

Sharing Policies

Example: Healthcare providers can share records with patients only
- Internal sharing: Enable (within organization)
- External sharing: Enable/Disable
- Link expiration: 7 days (link auto-expires)
- Require MFA: Multi-factor auth for sensitive files

Compliance Policies

Example: All documents tagged "HIPAA" must be logged for audit
- Audit logging: Mandatory for HIPAA files
- Encryption: Mandatory for HIPAA files
- Retention: Locked to 6 years (cannot be changed)
- Sharing restrictions: Cannot share externally

Visual Policy Builder

Ruby
Create policy without code:

IF   file type = "Tax Return"
THEN apply retention policy = "7 years"
AND  apply encryption = "AES-256"
AND  auto-tag = "Financial Document"
AND  require approval before sharing = Yes
AND  notify compliance officer when accessed

Visual drag-and-drop, no coding required.

Policy Enforcement

  • Policies automatically enforced in real-time

  • Violations prevent action (e.g., "Can't upload .exe file, blocked by policy")

  • Audit trail logs policy violations for compliance review

  • Compliance officer alerts for policy violations

Compliance Relevance

  • HIPAA: Enforce encryption and access controls per policy

  • GDPR: Enforce deletion policies and consent requirements

  • PCI DSS: Restrict access and require encryption

Business Benefit

⚙️ Governance Without Complexity — IT/Compliance can define strict rules (e.g., "all financial docs encrypted, kept 7 years, no external sharing") and Salesforce auto-enforces them. No workarounds, no human error.


10. Feature #8: Mobile & Desktop Access

What It Is

Access SFT on any device—desktop, tablet, or mobile—with full feature parity. Upload, download, share, and audit files from anywhere.

Desktop Access

  • Full Salesforce web interface

  • All SFT features available

  • Keyboard shortcuts for power users

  • Bulk upload (drag & drop)

  • Offline capabilities (Salesforce offline features)

Mobile App Access

  • iOS: Full featured app via Salesforce

  • Android: Full featured app via Salesforce

  • Upload files from camera or device storage

  • Download and open files inline

  • Share files with one tap

  • Complete audit trail access

  • Works on WiFi and mobile networks (4G/5G)

Offline Capabilities

  • Cached files accessible offline

  • Cannot upload/share while offline

  • Sync when reconnected

  • Offline changes sync automatically

Security on Mobile

  • Same AES-256 encryption as desktop

  • Mobile device management (MDM) compatible

  • Passcode protection on app

  • Biometric unlock (fingerprint, Face ID)

  • Auto-logout after inactivity

Real-World Scenarios

Scenario 1: Healthcare Provider on Rounds

  • Doctor visits patient

  • Opens Salesforce mobile app

  • Views patient records (including uploaded documents)

  • Discusses treatment with patient

  • Later: Uploads follow-up notes securely

  • All logged in HIPAA audit trail

Scenario 2: Loan Officer in Field

  • Loan officer meets with applicant

  • Opens SFT on mobile

  • Captures applicant's ID with camera

  • File uploaded, encrypted, stored

  • Real-time: Auto-routed to underwriter

  • Applicant sees immediate confirmation

Scenario 3: Government Employee Working from Home

  • Citizen submits permit application via portal

  • Officer working from home views on mobile

  • Officer reviews documents, approves

  • Citizen notified automatically

  • All logged for FOIA requests

Business Benefit

📱 Work Anywhere — Teams aren't confined to desk. Can work from home, in field, at client site with same security and compliance.


11. Feature #9: Complete Audit Trail & Logging

What It Is

Every action in SFT is logged with complete transparency. Who accessed what file, when, from where, on what device—everything tracked automatically.

What Gets Logged

Event

Logged Details

File Upload

User, timestamp, file name, file size, file type, source (portal, API, manual), IP address, device type

File Download

User, timestamp, file name, device type, IP address, country (geo-location)

File Shared

User sharing, recipient, timestamp, link expiration date, access level (view/download)

File Access

User, timestamp, action (view, download, print), duration, IP address, device

File Deleted

User, timestamp, file name, reason (retention policy, manual delete), archive status

Policy Violation

Violation type, user attempted action, policy violated, timestamp, enforcement action

Permission Change

Who changed permissions, timestamp, what changed (before/after), approval status

Configuration Change

Admin, timestamp, setting changed (before/after), reason

Audit Trail Example: Patient Record

Patient uploads medical records:
2024-08-20 10:15:23 | Patient_John_Smith | Upload | file_lab_results.pdf | 2.4 MB | IP: 203.45.67.89 | Device: iPhone

Provider accesses records:
2024-08-20 11:30:45 | Dr_Jane_Williams | Access | file_lab_results.pdf | IP: 192.168.1.45 | Device: Desktop | Duration: 3 minutes

Provider shares with specialist:
2024-08-20 12:00:12 | Dr_Jane_Williams | Share | file_lab_results.pdf | Recipient: Dr_Mark_Jones | Link expiration: 2024-08-27

Specialist accesses records:
2024-08-20 14:22:33 | Dr_Mark_Jones | Access | file_lab_results.pdf | IP: 192.168.1.78 | Device: Desktop | Duration: 5 minutes

File retention policy triggers deletion:
2024-08-20 (7 years later) | System | Auto-Delete | file_lab_results.pdf | Reason: Retention policy (6 years) | Deletion method: Cryptographic erasure

Audit Report Generation

Pre-built reports for compliance:

HIPAA Audit Report:
- All PHI access (patient records) - last 90 days
- Who accessed, when, from where
- Unauthorized access attempts
- Compliance status: ✅ PASS
- Exported as PDF for compliance review

PCI DSS Audit Report:
- All payment card data access - last 90 days
- Who accessed, when, from where
- Encryption validation
- Access control validation
- Compliance status: ✅ PASS

GDPR Audit Report:
- All EU resident data access
- Data portability requests (exported)
- Data deletion requests (completed)
- Data retention compliance
- Compliance status: ✅ PASS

Export Options

  • CSV: For analysis in Excel or BI tools

  • PDF: For compliance audit submission

  • JSON: For API integration with security tools

  • Salesforce Report: Native Salesforce analytics

Retention of Audit Logs

  • Audit logs retained for 10 years (industry standard)

  • Not subject to file retention policy (logs kept even after files deleted)

  • Immutable (cannot be modified or deleted)

Compliance Relevance

  • HIPAA: Proves who accessed PHI and when

  • PCI DSS: Proves access controls and encryption

  • GDPR: Proves data handling and user requests

  • E-Discovery: Provides complete chain of custody

Business Benefit

📋 Compliance Audits in Minutes — Instead of manually compiling access logs from multiple systems (email, shared drives, etc.), generate a complete audit report in one click.


12. Feature #10: Role-Based Access Control (RBAC)

What It Is

Granular permission management. Define what each role/user can do (upload, download, share, delete, audit) without custom code.

Pre-Defined Roles

Role

Permissions

Typical User

Viewer

View files only, no download

Clients, read-only stakeholders

User

Upload, download, view files

Business users, operators

Uploader

Upload and manage own files

Data entry, analysts

Sharer

Upload, download, share with others

Team leads, coordinators

Approver

Review and approve documents

Managers, compliance officers

Admin

Full access, manage policies, users

IT admins, compliance directors

Custom Roles

Create custom roles for specific scenarios:

Role: "Loan Officer"
Permissions:
  - Upload: Yes (loan documents only)
  - Download: Yes (own applicant documents)
  - Share: Yes (with underwriter only)
  - Delete: No (cannot delete)
  - Audit: Yes (can view audit trail)
  - Export: Yes (can export for compliance)
  - Policy Override: No (must follow policies)

Role: "Healthcare Compliance Officer"
Permissions:
  - Upload: No (not needed)
  - Download: Yes (all patient records)
  - Share: No (cannot share)
  - Delete: No (retention policy enforced)
  - Audit: Yes (full audit access)
  - Export: Yes (HIPAA reports)
  - Policy Override: Yes (if justified)

Record-Level Access Control

Control access at the record level (not just by role):

Example: Loan officer can only see loan files for their assigned accounts

Role: Loan Officer (John Smith)
Files accessible:
  - Account: ABC Corp (assigned to John Smith) ✅ Can access
  - Account: XYZ Inc (assigned to Jane Williams) ❌ Cannot access
  - File: abc_corp_tax_return.pdf ✅ Accessible
  - File: xyz_inc_tax_return.pdf ❌ Not accessible

Time-Based Access Control

Control access based on time:

Example: Temporary contractor access expires after 30 days

User: Contractor_TempStaff
Access: Yes (files for Project_X only)
Duration: 30 days (2024-08-20 to 2024-09-19)
Auto-revoke: 2024-09-19 (access automatically removed)
Reason: Contract ended

Conditional Access

Apply access controls conditionally:

Ruby
Rule: If accessing from outside company IP, require MFA (multi-factor auth)
Rule: If downloading >100 files at once, require approval
Rule: If accessing after 5 PM, require manager approval
Rule: If accessing from high-risk country, block access

Delegation

Allow managers to delegate file management:

Manager: John Smith
Delegates file approval to: Jane Williams
Duration: 2 weeks (while John is on vacation)
Auto-revoke: Date John returns
Scope: All files in "Approvals Pending" queue

Audit Trail of Permissions

All permission changes logged:

2024-08-20 10:00 | Admin | Changed role | User: John Smith | From: User → Approver
2024-08-20 10:05 | Admin | Added permission | User: Jane Williams | Permission: Export HIPAA reports
2024-08-21 14:30 | Manager | Delegated approval | From: John Smith | To: Sarah Jones | Duration: 2 weeks
2024-08-22 09:00 | John Smith | Revoked access | User: Contractor_X | Reason: Contract ended

Compliance Relevance

  • HIPAA: Restrict PHI access to authorized staff only

  • PCI DSS: Restrict payment card data access by role

  • GDPR: Implement "principle of least privilege"

Business Benefit

🔐 Granular Security — CEO doesn't see loan officer's applicant files. Loan officer doesn't see HR personnel files. Only authorized users access sensitive data.


13. Comparison: SFT Features vs. Alternatives

Capability

SFT

Email

Shared Drives

Third-Party Tools

Encryption

✅ AES-256

❌ None

⚠️ Optional

✅ Yes

Automation

✅ Full

❌ None

❌ None

⚠️ Limited

Audit Trail

✅ Complete

❌ None

⚠️ Limited

✅ Basic

Compliance Templates

✅ HIPAA/PCI/GDPR/FERPA

❌ None

❌ None

⚠️ Partial

Salesforce Integration

✅ Native

❌ None

❌ None

⚠️ Requires API

Mobile App

✅ Full

✅ Yes

⚠️ Limited

✅ Yes

User Training Needed

✅ <5 minutes

✅ None

✅ Minimal

⚠️ 1-2 hours

IT Support Required

✅ Minimal

✅ Minimal

⚠️ Moderate

⚠️ High

Cost

⚠️ Per-org pricing

✅ Included

✅ Included

⚠️ $20-100/user/month

Workflow Automation

✅ Full

❌ None

❌ None

⚠️ Requires code


14. Next Steps

Want to See These Features in Action?


15. Contact

Questions about features?

📧 Email: features@cloudmaveninc.com
📞 Phone: 1-800-XXX-XXXX (ext. Product)
🌐 Website:

http://www.cloudmaveninc.com


© 2026 Cloud Maven, Inc. All Rights Reserved.