Client file exchange,
seamless and audit-ready.
Susceptio replaces the ad-hoc intake stack — scattered forms, fragile automations, inbox attachments — with one branded form on your site. Clients send and receive files without secure-email hoops; every file is scanned, audit-logged, and delivered organized into your Microsoft 365 — or kept in our encrypted Azure backend.
Secure upload
First National Community Bank
Client name
Jane Doe
Drop files or click to upload
Resumable · multipart uploads
tax_return_2025.pdf
- Clients meet you — never a vendor.
- Send and receive through your branded form, on your domain
- "Can you resend that?" — never again.
- Nothing lost, nothing misfiled, nothing buried in a thread
- Your team lends. The process files itself.
- Submissions arrive named, filed, and tracked — in your M365 or our encrypted backend
See it in action
One submission, end to end
A client drops files on your site, your team replies in the same secure thread, and everything lands organized — in Microsoft 365 or our encrypted backend.
Narrated · captions available
The status quo is broken
The ad-hoc intake stack doesn't scale — and your clients bear the cost
Most regulated businesses land in one of two places: a secure-email provider that makes clients jump through hoops — or a form tool, an automation flow, and a shared drive cobbled together and held together by scotch tape.
Secure email
Clients fight the door
Accounts, expiring links, 'retrieve your message' detours — so sensitive documents end up in plain email anyway. And when a client needs a file back, there's no clean way to send it.
Ad hoc stack
Every change is a project
New team? Rebuild it. New field? Re-embed it everywhere. The stack doesn't adapt — it gets re-cobbled.
Ad hoc stack
Your staff are the filing system
Someone downloads, renames, drags into folders, and chases whatever's missing. Skilled people doing file management instead of the work that earns.
Secure email
Nobody can answer 'who touched this'
Files sit unscanned in inboxes. When the auditor asks who uploaded what — and who saw it after — the honest answer is a search through email.
Secure email
The biggest files are the ones that fail
Attachment caps and ~25 MB upload ceilings force clients to split packages, resend, or give up. The most important documents fail first.
Ad hoc stack
It fails silently
A flow breaks, a folder permission drifts, and nobody knows — until the client calls weeks later asking why nobody looked at their file.
One product, every layer
One system of record for every client file
Every layer — the form, the scan, the audit trail, the delivery — designed around the two people it serves: your clients and your team.
White-label, embeddable form
One script tag on your site — your logo, colors, fonts. Create a form per team or workflow, each with its own notifications, and update it instantly — no re-embedding, no deploy.
Two-way file exchange
Clients send and receive files through the same branded channel — no secure-email hoops, no portals to log into. Returning a signed document is as easy as sending it.
Who can submit — your choice
Invite-only accounts, one-time email verification, or fully anonymous open intake — configured per tenant to match each workflow's risk.
Resumable large-file uploads
Multi-part uploads with Azure Blob SAS tokens. Survive dropped connections and resume in place for large files.
Append-only audit trail
Form loaded, file uploaded, file accessed, file downloaded, email sent — every state-changing event is written to an append-only audit log. A full servicing history for every client.
Zero-trust malware scanning
Every file is scanned before it's marked available for staff download or synced to SharePoint. Infected files are quarantined, never delivered.
Organized delivery — your Microsoft 365 or ours
Every clean file is copied, filed, into your SharePoint or OneDrive folder structure — or stays in Susceptio's encrypted backend behind secure download links. On the M365 path you also choose how long we keep our copy: retained under your retention policy, or auto-purged days after delivery while the record and audit trail stay.
Microsoft Entra ID sign-in, MFA required
No custom auth to breach — staff sign in with Microsoft Entra ID. MFA is required on every login, enforced by Conditional Access policies.
Bank-grade architecture
Tenant isolation enforced in the database engine. Secrets in Azure Key Vault, never in code. Every resource defined in Terraform. Built to survive your vendor review.
Security & architecture →How it works
From your site to organized delivery in four steps
No secure-email hoops for your clients — and delivery that fits the tools your staff already use. Microsoft 365 included, not required.
- 01
Embed the form
Drop one script tag on your existing website. Susceptio renders a fully white-labeled intake form — your logo, your colors, your fields. Spin up a form per team or workflow and update it instantly.
- 02
Clients send — and receive
Your client completes the branded form and uploads files; staff can send files back through the same channel. Resumable, encrypted in transit, and gated by your access rules — invite-only, email-verified, or fully anonymous.
- 03
We scan & audit
Every file is scanned before it's available — nothing reaches staff until it's deemed non-hostile. Each event is written to an append-only audit log: a full servicing history for every client.
- 04
Organized — your M365 or ours
Files sync into your SharePoint library or OneDrive via Microsoft Graph, filed the way you configure — or stay in Susceptio's encrypted backend behind secure download links. Staff get notified and keep working in the tools they already use.
See it live with your own tenant
We'll provision a branded sandbox in under a business day.
Security & compliance
Built for the auditors who audit you
Compliance isn't a feature we bolted on — it's the architecture we started from. When your auditor asks who touched a file, the answer is a log, not a guess.
Encryption everywhere
TLS 1.2+ in transit, AES-256 encryption at rest in Azure Storage. Customer-managed keys (BYOK) via Azure Key Vault — Enterprise, roadmap.
Row-Level Security
Postgres RLS enforces tenant isolation at the engine. A query that omits tenant_id returns zero rows — by construction, not by convention.
Append-only audit log
Every state-changing event is recorded to an append-only log — a trail you can hand to an auditor or regulator on demand.
Mandatory MFA
Staff authentication is Azure Entra ID only — no custom auth, no shared passwords. MFA required on every login, enforced by Conditional Access policies.
Zero-trust files
All uploads are treated as hostile. Every file is scanned before it's downloadable or synced. Infected files are quarantined.
Single-cloud custody
Client files live in Microsoft Azure from upload to delivery — no fourth-party file services sit in the data path.
Integrations
Integrates with the Microsoft stack you already pay for
Most regulated businesses already run on Microsoft 365. Susceptio integrates with it rather than replacing it — a faster sale, faster onboarding, and zero new tools for your staff. No M365? Files stay in our encrypted Azure backend — same scan, same audit trail.
Microsoft 365
SharePoint & OneDrive delivery via Microsoft Graph
Azure Entra ID
Staff SSO + mandatory MFA, no custom auth
Azure Blob Storage
Resumable multipart uploads with SAS tokens
Azure Key Vault
Secrets custody + customer-managed keys (roadmap)
Azure Communication Services
DKIM/SPF/DMARC-authenticated email
PostgreSQL + RLS
Engine-level multi-tenant isolation
Pricing
Per-tenant pricing. Seats bundled, not metered.
We charge by the tenant, not by the seat — every plan includes a block of staff users. Growth tracks submissions, storage, and sites — aligned with real value, never headcount.
Starter
Solo practices and small teams that need a professional front door.
Month-to-month
- 750 submissions/mo included
- 250 GB storage · 12-mo retention
- 1 site — one branded embedded form
- 5 staff users
- M365 delivery or Susceptio-hosted
- Email support · 48h
Professional
Growing teams and mid-size organizations with multiple workflows.
Month-to-month
- 3,000 submissions/mo included
- 3 TB storage · 72-mo retention
- 5 sites — a form per team
- 25 staff users
- Per-site branding
- Email + chat support · 24h
Enterprise
Large and highly regulated organizations.
Month-to-month
- 10,000 submissions/mo included
- 10 TB storage · 72-mo retention
- 25 sites
- 100 staff users
- API & webhooks · SSO/SCIM & BYOK (roadmap)
- Email + chat support · 24h
Need something that doesn't fit a card? Custom plans are scoped per deal — talk to sales.
FAQ
Questions, answered
How is Susceptio different from our current form + email stack?
Form tools cap file sizes, spreadsheets corrupt under concurrent edits, and automation flows fail silently — and none of it produces an audit trail. Susceptio is one multi-tenant SaaS: resumable large-file uploads, engine-level tenant isolation, an append-only audit trail, and organized delivery into your Microsoft 365 or our encrypted backend. And it's bi-directional — staff deliver files back to clients through the same branded, audited channel. One secure exchange in both directions, not a one-way drop box — no vendor sprawl, no silent failures.
Can't we just use SharePoint or OneDrive Request Files?
A file-request link is a drop box, not a system of record. It carries no branding — your client sees a Microsoft page, not yours — and it trains them to hand highly sensitive files to any unfamiliar page that asks, the exact habit phishing exploits. There's no client identity, no per-event audit trail, no malware scan before staff open the file, and nothing to hand an auditor. Susceptio is intake on a page your clients recognize as yours: the file arrives branded, identified, scanned, and logged — then lands in the same SharePoint library you already use.
What if our organization doesn't use Microsoft 365?
No problem — M365 delivery is an option, not a requirement. If you have an organizational Microsoft 365 tenant — any plan that includes SharePoint or OneDrive for work — we can deliver files straight into the libraries your staff already use, once your IT admin consents to the connection. Without it, files stay in our encrypted Azure backend and staff retrieve them through the Susceptio dashboard or secure download links — same scanning, same audit trail. Either way, the choice is where your team best manages the data — we fit your workflow, not the other way around.
Do my staff need to learn a new tool?
On the Microsoft 365 path, files land in the SharePoint library staff already use — an email notification, no new tool. On the Susceptio-hosted path, staff work in one dashboard with the same notifications. Either way: one place to look, not five.
How do you handle multi-tenancy and data isolation?
Your data is isolated at the database engine, not just in our application code — Postgres Row-Level Security means a query that omits your tenant ID returns zero rows by construction, not by convention. Files live in a per-tenant partition of our object storage, and every access through Susceptio is logged. (Once a file is delivered into your own Microsoft 365, access there is governed — and audited — by your own Entra and SharePoint controls.) Your security team can go deeper on the security page.
What if we don't want the form open to unauthenticated users?
You control the front door — three levels, set per tenant: invite-only (only clients your team pre-registers, via magic-link sign-in), email-verified (anyone can submit after a one-time email code — no account), or fully open anonymous intake. You can override it per site, so a private client form stays invite-only while a public-facing one stays open.
Is pricing per-seat?
No. We price per tenant with seats bundled — 5 staff users on Starter, 25 on Professional, 100 on Enterprise — and additional seats are a flat $10/mo, not a per-seat license. Growth tracks submissions, storage, and sites, not headcount.
How long does onboarding take?
Time-to-value target is under one business day. Tenant provisioning is Terraform-driven and automated — no manual console work. We can stand up a branded sandbox for your evaluation quickly.
What about compliance and audit?
Every state-changing event is written to an append-only audit log; staff sign in with Microsoft Entra ID and MFA is required; files are scanned before anyone touches them; and tenant data is isolated at the database engine — the controls your IT and compliance teams will ask about. SOC 2 Type II attestation is on the roadmap; in the meantime we'll walk your reviewers through the architecture directly.
Can we bring our own encryption keys?
On the Enterprise tier — customer-managed keys (BYOK) via Azure Key Vault, with per-tenant data encryption keys, is on the roadmap. Every tenant's data is encrypted at rest regardless of tier.
Replace your intake stack with one audit-ready system
See Susceptio live with your own branded tenant. We'll have a sandbox ready in under a business day.