Secure file upload portal for Google Drive

Collect files from clients through a private upload link. Senders need no account, they see only their own upload page, and every file is delivered into a folder inside your own Google Drive.

Create an upload link

How it works

Step 1

Create a link

Sign in with Google and set up a link — optional file size, count, and expiry limits included.

Step 2

Share it

Send the link by email, chat, or wherever. No account needed on the other end.

Step 3

Files land in your Drive

Every upload is delivered straight into a dedicated folder in your own Google Drive.

A secure file upload portal is a private page people can send files through without an account, where each sender sees only their own upload box and never the folder behind it. Drive File Request gives you one per link, and delivers every upload into a folder inside your own Google Drive.

What a secure upload portal has to get right

The word “secure” gets attached to anything with a login screen, so it is worth being concrete. For collecting files from people outside your organisation, the security that matters is mostly about isolation and control: senders should not be able to read, rename, or delete anything, you should be able to decide who can open the page at all, and the link should stop working when the work it belonged to is over.

A shared cloud folder fails all three at once, which is why it is the wrong tool for the job even though it is the one most people reach for first. An upload portal is the narrower, safer shape: a page that only accepts, never reveals.

Who uses one

  • Accountants and bookkeepers gathering statements, receipts, and tax documents from clients who will not create an account to hand them over.
  • Freelancers and studios taking brand assets, raw footage, and revisions from clients on a per-project basis.
  • Agencies collecting deliverables and source files from several clients at once, where one client seeing another's folder is an actual incident.
  • Recruiters and HR teams receiving CVs, portfolios, and signed paperwork from candidates who have no internal account yet.
  • Vendors, suppliers, and partners sending documents into a company that does not want to add them to its identity provider.
  • Anyone running an intake process — legal, insurance, applications — where submissions arrive from strangers.

How it works

  1. 01Sign in with your Google account and create a link. This is the only sign-in involved anywhere in the flow.
  2. 02Set the controls for that link: password, allowed senders, expiry, size and count limits, file types, and any questions you want answered at upload time.
  3. 03Send the link by email, chat, or however you already talk to the person. Nothing is installed and nothing is invited.
  4. 04They open a single upload page, drop the files in, and answer whatever you asked. No account, no sign-up, no app.
  5. 05The files land in a folder inside your own Google Drive, owned by you, optionally in a subfolder created for that submission.

Why not email or a shared folder

 EmailShared Drive folderUpload portal link
Size ceiling~25 MBYour Drive quotaYou set it, up to 5 GB per file
Sender needs an accountNoNoNo
Senders see other people's filesN/AYesNo
Senders can delete your filesN/AYes, with edit accessNo
Restrict who can uploadNoOnly by named accountPassword, email, or domain
Closes itselfN/ANoExpiry date
You know who sent whatFrom the senderNoName, email, and custom fields

The shared-folder column is the one worth staring at. “Anyone with the link can edit” is the standard workaround for Google Drive's missing file request feature, and it hands every sender edit rights over everything already in that folder — the background is in does Google Drive have a file request feature.

The controls you get on a link

Everything below is set per link, so a client intake link and an open call for submissions do not have to share a policy:

  • A page password, so the link alone is not enough to open it.
  • An uploader whitelist by email address or by domain, with an optional access code per entry — the way to make a link that only your client, or only people at their company, can use.
  • An expiry date, after which the link stops accepting files without you having to remember to close it.
  • A maximum file size and a maximum number of uploads per link.
  • Accepted file types, so a request for signed PDFs does not come back as photos of a screen.
  • Custom questions — text, email, notes, checkboxes, dropdowns — answered before the upload, so you are not reconstructing context afterwards.
  • A subfolder created automatically for each submission, keeping a repeat sender's second delivery separate from their first.
  • Email notification to you when a submission completes, and an optional confirmation email to the sender.

What the portal can see in your Drive

Drive File Request signs in with Google's narrow drive.file scope, which grants an app access only to the files and folders it creates itself. It cannot list, read, or touch anything else in your Drive, including files you uploaded yourself and folders shared with you. That is a meaningful difference from tools that ask for full Drive access to do the same job, and it is worth checking on whatever you end up using.

Files arrive owned by you, in your own Drive, counting against your own quota. Nothing sits in a third-party silo waiting to be moved.

Secure file sharing for business, one direction only

Most tools sold as secure file sharing for business are two-directional and priced per seat: everyone in the company gets an account, files move both ways, and the security model is built around managing those accounts. That is the right shape when the people exchanging files all work for you. It is the wrong shape, and an expensive one, when what you actually need is for people outside the company to hand you documents.

This is the narrower tool for that second case. There are no seats to license, no accounts to provision for people who will use them once, and no shared workspace to keep tidy — one flat price, and a link per request. The tradeoff is deliberate and worth stating plainly: it will not distribute files outward, so if you need both directions you need something else alongside it. What it removes is the usual reason inbound collection is insecure, which is that someone opened a folder to the world because provisioning an account for a client was too much work.

How the transfer itself is secured

Access control decides who may upload. Secure file transfer is the separate question of what happens to the bytes between the sender's browser and your Drive, and it is worth knowing rather than assuming:

  • Uploads go directly from the sender's browser to private storage over TLS. They are never public and never listed anywhere.
  • The transfer into your Drive runs as a durable background job using Google's resumable upload protocol in 8 MB chunks, so a dropped connection resumes rather than restarting — which is what makes large files arrive at all.
  • The temporary copy in staging is deleted once Google Drive confirms the file has landed. The finished file lives in one place, your Drive, not two.
  • Google tokens are encrypted before they are stored, and the app holds only the narrow drive.file scope described above.
  • Uploads are rate limited per link and per sender without raw IP addresses being stored, and completed submissions are recorded as audit events you can review.

What this is not

It is worth being clear about the boundary, because “portal” is used loosely. This is not a client portal with accounts, dashboards, and a login for the people you work with — the whole design goal is that senders never have an account. There is no message thread, no approvals workflow, and no e-signature step. If what you need is a place clients log in to and live in, this is the wrong shape of tool. If what you need is a safe, controlled way for them to hand you files, it is exactly the right one.

Frequently asked questions

What is a secure file upload portal?

A private page that accepts files and shows nothing else. Senders upload through a link without an account and never see the destination folder, its contents, or anyone else's submissions, while the owner controls who can open the page and for how long.

Do senders need an account to upload files?

No. Only the person creating the link signs in — with Google, once. Everyone sending files just opens a URL, which is the point: an account requirement is the step that loses you the file.

Can I restrict who is allowed to upload?

Yes, in two ways that can be combined: a password on the page itself, and a whitelist of specific email addresses or whole domains, each of which can carry its own access code. A link forwarded outside that list will not open.

Where do the uploaded files go?

Into a folder inside your own Google Drive, created for that link, optionally with a subfolder per submission. You own the files from the moment they arrive — there is no separate storage account to move them out of later.

Is this a client portal?

No, and deliberately so. There are no client accounts, no dashboard for the people you work with, and no project workspace. It is an intake surface: a controlled link for receiving files, described in the category terms in file request software.

Is this secure file sharing software for a business?

For inbound file sharing, yes — collecting documents from clients, vendors, and candidates under per-link access control, at a flat price with no seats to license. It does not distribute files outward, so a business that needs two-way sharing across a team will still want a separate tool for that half.

How is the file transfer itself secured?

Uploads travel over TLS from the sender's browser into private storage that is never public, then transfer into your Drive as a durable background job using resumable chunked uploads. The temporary copy is deleted once Google Drive confirms delivery, and stored Google tokens are encrypted.

Can I stop a link after a project ends?

Yes. Set an expiry date when you create it and it closes itself, or disable it manually at any point. Files already delivered stay in your Drive.

Set up your first upload link

Password, allowed senders, and an expiry date are all set when you create it. Takes about a minute.

Get started free