Skip to content
MSP Process

HaloPSA AI VoiceAssist with Authenticator verification and SMS

Your sensitive data.
Shared with the right person.

Luke F.

Northwind Dental

00:18
  1. 00:00

    compliance-Q4-report.pdf

    Northwind Dental, Ticket #5102, 2.4 MB encrypted

  2. 00:18

    +2 stepsYour document, delivered securely

AES-256 encryption, PSA sync, SIEM export

Your team shares passwords, files and credential bundles through branded, single-use encrypted links, with identity checks and a record in your PSA (professional services automation). Forwarded emails can expose sensitive content to someone other than the intended recipient, so access includes verification.

Created inside your PSA
1-Click
Expires after first access
Single-Use
Recorded for your audit
100%

READY TO SHARE

The details clients need.
The sharing your team needs.

Your team can share six asset types through encrypted links tied to the ticket, without opening another app or copying sensitive details into messages.

  • Passwords and temporary credentials

    Your team generates and shares encrypted passwords for one viewing, without reading them aloud or typing them into an email.

    • Passwords for client account resets
    • Temporary credentials for client access
    • App-specific passwords for client use
    Most common
  • Documents for verified recipients

    Your team shares contracts, compliance reports, security assessments and business associate agreements through encrypted downloads with multifactor authentication and recipient watermarks.

    • Encryption on your technician's device
    • Downloads protected by multifactor authentication
    • Document watermarks with recipient identity
    Audit-ready
  • License keys and access credentials

    Your team bundles software keys, application programming interface credentials and service account details into one verified portal session for single-use access.

    • Software keys for client applications
    • Tokens for application programming interfaces
    • Credentials for client service accounts
    Bundleable
  • Configuration and setup details

    Your team shares virtual private network profiles, wireless network keys, server addresses and installation scripts through encrypted links tied to the ticket.

    • Profiles for virtual private networks
    • Keys for client wireless networks
    • Server addresses and installation scripts
    Config-safe
  • New starters, one handoff

    Your team packages a new starter's setup into one verified portal handoff, with one link, six items and one audit row.

    • Network profiles and wireless keys
    • Software licenses and welcome documents
    • One verified portal for setup
    One-shot
  • Instructions with sensitive details

    Your team sends setup instructions containing authentication tokens, recovery codes and internal web addresses through a single-use page outside the email body.

    • Setup steps with sensitive details
    • Authentication tokens and recovery codes
    • Internal web addresses for setup
    Plaintext-free

Generate, send, and log without leaving the ticket.

Tech opens the secure share panel inside their existing PSA. The full chain, generated, delivered, accessed, expired, writes back to that ticket automatically.

  • One-click share, text, file, or request, from any open ticket.
  • Single-use, time-limited links with location and period controls.
  • Every event auto-written to the ticket and the internal note.

Service ticket showing the embedded MSP Process Secure Data Sharing panel with Text, File, Send Request, and Request list tabs, a drag-and-drop file area, and link options for period, location, single-use link, and log destinations.

HOW IT WORKS

From your team's ticket.
To your verified recipient.

Each share follows a five-step process, with plaintext visible for milliseconds on the recipient's device only after their identity is verified.

  1. Create from your ticket

    Your technician creates a password, file share or bundle inside the PSA ticket with one click, without switching apps or copying details.

  2. Encrypt before sending

    Content is protected with AES-256 encryption and a single-use link on your branded domain, without storing plaintext on the server.

  3. Deliver through your brand

    Your client receives a branded text message or email through their verified channel, with email signed with DKIM.

  4. Verify before opening

    Your recipient confirms their identity with biometrics or an Authenticator push before they can open the shared content.

  5. Record each step

    Your PSA ticket and SIEM record when the share was created, sent, accessed and expired, keeping each step together.

WHAT YOU LEAVE WITH

Your sharing history.
Ready for your next audit.

Your team gets a tamper-evident record for every encrypted, identity-verified share, so compliance teams and auditors can follow what happened.

  • Encryption before content leaves

    AES-256 encrypts content before it leaves your technician's session, with the link acting as the key and no plaintext stored on your servers.

    • Encryption within your technician's session
    • Link as the decryption key
    • No plaintext on your servers
    Zero-knowledge
  • Access with an expiry

    Each link expires on first access or after a configurable 24-hour default, limiting the "I forwarded it to my team" exposure.

    • Default expiry after 24 hours
    • Expiry settings for each share
    • Link expiry after first access
    Burn-on-read
  • Verification before content opens

    Your recipient verifies with biometrics or Authenticator on the right device before opening content, so the link alone doesn't grant access.

    • Biometric verification for your recipient
    • Authenticator approval before content access
    • Recipient approval on the right device
    MFA-required
  • Your brand throughout delivery

    Your clients see your brand across sender and link domains, the portal, email layout and text message sender.

    • Your sender and link domains
    • Your portal and email layout
    • Your branded text message sender
    Your brand
  • Records for your audit

    We provide sharing records for your audits covering HIPAA, SOC 2, CMMC, PCI-DSS and GDPR Article 32, with evidence from each share.

    • Sharing records for compliance teams
    • Tamper-evident evidence from each share
    • Access history for auditor review
    HIPAA, SOC 2, CMMC

IN EVERYDAY USE

84%
Time saved per credential share
One click vs. copy / encrypt / send / explain. Generate the link inside the PSA, branded delivery, MFA gate, audit row all included.
100%
Shares with an audit trail
Every share, every access, every expiry, logged to the PSA ticket and streamed to your SIEM in real time.
0
Plaintext stored on servers
Encrypted at rest, in transit, and on retrieval. AES-256 client-side, plaintext exists for milliseconds, only on the recipient's device.
$0
Spending on separate encryption tools
Most MSPs retire their paid email-encryption subscription within the first quarter. The line item just disappears.
“We use this a lot for passwords and sensitive data with our clients. It killed our email-encryption add-on, the auditor loves the trail, and clients keep asking why we didn't have this five years ago.”

David Spencer

Integritek, ConnectWise partner

SEE IT AT WORK

Your next secure share.
Together in a demo.

In a demo, we'll walk through a secure share using a sample branded link and review multifactor authentication. You'll see single-use access and the audit log recorded in a representative PSA environment.

  1. Walkthrough

  2. Product walkthrough

  3. Your quote

Bring us the sharing process your team handles most.

  • Torch Awards, Most Innovative 2025
  • AICPA SOC for Service Organizations