suscept.io
Built for regulated businesses that answer to auditors

Client file exchange,
seamless and audit-ready.

Susceptio replaces the ad-hoc intake stack — scattered forms, fragile automations, inbox attachments — with one branded form on your site. Clients send and receive files without secure-email hoops; every file is scanned, audit-logged, and delivered organized into your Microsoft 365 — or kept in our encrypted Azure backend.

app.suscept.io

Secure upload

First National Community Bank

Encrypted

Client name

Jane Doe

Drop files or click to upload

Resumable · multipart uploads

PDF

tax_return_2025.pdf

74%
Clients meet you — never a vendor.
Send and receive through your branded form, on your domain
"Can you resend that?" — never again.
Nothing lost, nothing misfiled, nothing buried in a thread
Your team lends. The process files itself.
Submissions arrive named, filed, and tracked — in your M365 or our encrypted backend

See it in action

One submission, end to end

A client drops files on your site, your team replies in the same secure thread, and everything lands organized — in Microsoft 365 or our encrypted backend.

Narrated · captions available

The status quo is broken

The ad-hoc intake stack doesn't scale — and your clients bear the cost

Most regulated businesses land in one of two places: a secure-email provider that makes clients jump through hoops — or a form tool, an automation flow, and a shared drive cobbled together and held together by scotch tape.

Secure email

Clients fight the door

Accounts, expiring links, 'retrieve your message' detours — so sensitive documents end up in plain email anyway. And when a client needs a file back, there's no clean way to send it.

Ad hoc stack

Every change is a project

New team? Rebuild it. New field? Re-embed it everywhere. The stack doesn't adapt — it gets re-cobbled.

Ad hoc stack

Your staff are the filing system

Someone downloads, renames, drags into folders, and chases whatever's missing. Skilled people doing file management instead of the work that earns.

Secure email

Nobody can answer 'who touched this'

Files sit unscanned in inboxes. When the auditor asks who uploaded what — and who saw it after — the honest answer is a search through email.

Secure email

The biggest files are the ones that fail

Attachment caps and ~25 MB upload ceilings force clients to split packages, resend, or give up. The most important documents fail first.

Ad hoc stack

It fails silently

A flow breaks, a folder permission drifts, and nobody knows — until the client calls weeks later asking why nobody looked at their file.

One product, every layer

One system of record for every client file

Every layer — the form, the scan, the audit trail, the delivery — designed around the two people it serves: your clients and your team.

White-label, embeddable form

One script tag on your site — your logo, colors, fonts. Create a form per team or workflow, each with its own notifications, and update it instantly — no re-embedding, no deploy.

Two-way file exchange

Clients send and receive files through the same branded channel — no secure-email hoops, no portals to log into. Returning a signed document is as easy as sending it.

Who can submit — your choice

Invite-only accounts, one-time email verification, or fully anonymous open intake — configured per tenant to match each workflow's risk.

Resumable large-file uploads

Multi-part uploads with Azure Blob SAS tokens. Survive dropped connections and resume in place for large files.

Append-only audit trail

Form loaded, file uploaded, file accessed, file downloaded, email sent — every state-changing event is written to an append-only audit log. A full servicing history for every client.

Zero-trust malware scanning

Every file is scanned before it's marked available for staff download or synced to SharePoint. Infected files are quarantined, never delivered.

Organized delivery — your Microsoft 365 or ours

Every clean file is copied, filed, into your SharePoint or OneDrive folder structure — or stays in Susceptio's encrypted backend behind secure download links. On the M365 path you also choose how long we keep our copy: retained under your retention policy, or auto-purged days after delivery while the record and audit trail stay.

Microsoft Entra ID sign-in, MFA required

No custom auth to breach — staff sign in with Microsoft Entra ID. MFA is required on every login, enforced by Conditional Access policies.

Bank-grade architecture

Tenant isolation enforced in the database engine. Secrets in Azure Key Vault, never in code. Every resource defined in Terraform. Built to survive your vendor review.

Security & architecture →

How it works

From your site to organized delivery in four steps

No secure-email hoops for your clients — and delivery that fits the tools your staff already use. Microsoft 365 included, not required.

  1. 01

    Embed the form

    Drop one script tag on your existing website. Susceptio renders a fully white-labeled intake form — your logo, your colors, your fields. Spin up a form per team or workflow and update it instantly.

  2. 02

    Clients send — and receive

    Your client completes the branded form and uploads files; staff can send files back through the same channel. Resumable, encrypted in transit, and gated by your access rules — invite-only, email-verified, or fully anonymous.

  3. 03

    We scan & audit

    Every file is scanned before it's available — nothing reaches staff until it's deemed non-hostile. Each event is written to an append-only audit log: a full servicing history for every client.

  4. 04

    Organized — your M365 or ours

    Files sync into your SharePoint library or OneDrive via Microsoft Graph, filed the way you configure — or stay in Susceptio's encrypted backend behind secure download links. Staff get notified and keep working in the tools they already use.

See it live with your own tenant

We'll provision a branded sandbox in under a business day.

Book a demo

Security & compliance

Built for the auditors who audit you

Compliance isn't a feature we bolted on — it's the architecture we started from. When your auditor asks who touched a file, the answer is a log, not a guess.

Encryption everywhere

TLS 1.2+ in transit, AES-256 encryption at rest in Azure Storage. Customer-managed keys (BYOK) via Azure Key Vault — Enterprise, roadmap.

Row-Level Security

Postgres RLS enforces tenant isolation at the engine. A query that omits tenant_id returns zero rows — by construction, not by convention.

Append-only audit log

Every state-changing event is recorded to an append-only log — a trail you can hand to an auditor or regulator on demand.

Mandatory MFA

Staff authentication is Azure Entra ID only — no custom auth, no shared passwords. MFA required on every login, enforced by Conditional Access policies.

Zero-trust files

All uploads are treated as hostile. Every file is scanned before it's downloadable or synced. Infected files are quarantined.

Single-cloud custody

Client files live in Microsoft Azure from upload to delivery — no fourth-party file services sit in the data path.

Integrations

Integrates with the Microsoft stack you already pay for

Most regulated businesses already run on Microsoft 365. Susceptio integrates with it rather than replacing it — a faster sale, faster onboarding, and zero new tools for your staff. No M365? Files stay in our encrypted Azure backend — same scan, same audit trail.

Microsoft 365

SharePoint & OneDrive delivery via Microsoft Graph

Azure Entra ID

Staff SSO + mandatory MFA, no custom auth

Azure Blob Storage

Resumable multipart uploads with SAS tokens

Azure Key Vault

Secrets custody + customer-managed keys (roadmap)

Azure Communication Services

DKIM/SPF/DMARC-authenticated email

PostgreSQL + RLS

Engine-level multi-tenant isolation

Pricing

Per-tenant pricing. Seats bundled, not metered.

We charge by the tenant, not by the seat — every plan includes a block of staff users. Growth tracks submissions, storage, and sites — aligned with real value, never headcount.

Starter

Solo practices and small teams that need a professional front door.

$299/mo per tenant

Month-to-month

  • 750 submissions/mo included
  • 250 GB storage · 12-mo retention
  • 1 site — one branded embedded form
  • 5 staff users
  • M365 delivery or Susceptio-hosted
  • Email support · 48h
Start with Starter
Recommended

Professional

Growing teams and mid-size organizations with multiple workflows.

$649/mo per tenant

Month-to-month

  • 3,000 submissions/mo included
  • 3 TB storage · 72-mo retention
  • 5 sites — a form per team
  • 25 staff users
  • Per-site branding
  • Email + chat support · 24h
Choose Professional

Enterprise

Large and highly regulated organizations.

$1,499/mo per tenant

Month-to-month

  • 10,000 submissions/mo included
  • 10 TB storage · 72-mo retention
  • 25 sites
  • 100 staff users
  • API & webhooks · SSO/SCIM & BYOK (roadmap)
  • Email + chat support · 24h
Talk to sales

Need something that doesn't fit a card? Custom plans are scoped per deal — talk to sales.

See full pricing →

FAQ

Questions, answered

How is Susceptio different from our current form + email stack?

Form tools cap file sizes, spreadsheets corrupt under concurrent edits, and automation flows fail silently — and none of it produces an audit trail. Susceptio is one multi-tenant SaaS: resumable large-file uploads, engine-level tenant isolation, an append-only audit trail, and organized delivery into your Microsoft 365 or our encrypted backend. And it's bi-directional — staff deliver files back to clients through the same branded, audited channel. One secure exchange in both directions, not a one-way drop box — no vendor sprawl, no silent failures.

Can't we just use SharePoint or OneDrive Request Files?

A file-request link is a drop box, not a system of record. It carries no branding — your client sees a Microsoft page, not yours — and it trains them to hand highly sensitive files to any unfamiliar page that asks, the exact habit phishing exploits. There's no client identity, no per-event audit trail, no malware scan before staff open the file, and nothing to hand an auditor. Susceptio is intake on a page your clients recognize as yours: the file arrives branded, identified, scanned, and logged — then lands in the same SharePoint library you already use.

What if our organization doesn't use Microsoft 365?

No problem — M365 delivery is an option, not a requirement. If you have an organizational Microsoft 365 tenant — any plan that includes SharePoint or OneDrive for work — we can deliver files straight into the libraries your staff already use, once your IT admin consents to the connection. Without it, files stay in our encrypted Azure backend and staff retrieve them through the Susceptio dashboard or secure download links — same scanning, same audit trail. Either way, the choice is where your team best manages the data — we fit your workflow, not the other way around.

Do my staff need to learn a new tool?

On the Microsoft 365 path, files land in the SharePoint library staff already use — an email notification, no new tool. On the Susceptio-hosted path, staff work in one dashboard with the same notifications. Either way: one place to look, not five.

How do you handle multi-tenancy and data isolation?

Your data is isolated at the database engine, not just in our application code — Postgres Row-Level Security means a query that omits your tenant ID returns zero rows by construction, not by convention. Files live in a per-tenant partition of our object storage, and every access through Susceptio is logged. (Once a file is delivered into your own Microsoft 365, access there is governed — and audited — by your own Entra and SharePoint controls.) Your security team can go deeper on the security page.

What if we don't want the form open to unauthenticated users?

You control the front door — three levels, set per tenant: invite-only (only clients your team pre-registers, via magic-link sign-in), email-verified (anyone can submit after a one-time email code — no account), or fully open anonymous intake. You can override it per site, so a private client form stays invite-only while a public-facing one stays open.

Is pricing per-seat?

No. We price per tenant with seats bundled — 5 staff users on Starter, 25 on Professional, 100 on Enterprise — and additional seats are a flat $10/mo, not a per-seat license. Growth tracks submissions, storage, and sites, not headcount.

How long does onboarding take?

Time-to-value target is under one business day. Tenant provisioning is Terraform-driven and automated — no manual console work. We can stand up a branded sandbox for your evaluation quickly.

What about compliance and audit?

Every state-changing event is written to an append-only audit log; staff sign in with Microsoft Entra ID and MFA is required; files are scanned before anyone touches them; and tenant data is isolated at the database engine — the controls your IT and compliance teams will ask about. SOC 2 Type II attestation is on the roadmap; in the meantime we'll walk your reviewers through the architecture directly.

Can we bring our own encryption keys?

On the Enterprise tier — customer-managed keys (BYOK) via Azure Key Vault, with per-tenant data encryption keys, is on the roadmap. Every tenant's data is encrypted at rest regardless of tier.

Replace your intake stack with one audit-ready system

See Susceptio live with your own branded tenant. We'll have a sandbox ready in under a business day.