Two Locks Are Better Than One: How to Deliver Client Financial Reports Securely.
Two Locks Are Better
Than One
How to deliver client financial reports securely, without email attachments, link sprawl or guesswork.
Picture the 5th of the month. You finish a client's P&L, attach the PDF, and start typing a name. Autocomplete offers two people with the same first name. You pick the wrong one and hit send.
Nothing was hacked. Your accounting software was locked down, your passwords were strong, and a client's profit, payroll and owner draws still landed in a stranger's inbox.
Most bookkeeping security advice stops at logins and software settings. The step that actually exposes client data is the last one: delivery. This post shows where delivery goes wrong, and how a simple two-lock model, a passcode-protected portal backed by restricted Google Drive access, closes the gap without adding work to your month-end.
The StakesWhat's at Stake
Your clients hand you their bank feeds, payroll records, EINs and owner draws. By month end you turn all of it into a P&L that shows exactly how a business is doing. That document is valuable to the client, and just as valuable to anyone who shouldn't see it.
People are the common thread in breaches. Verizon's 2026 Data Breach Investigations Report found the human element present in 62% of breaches, up from 60% the year before. That figure covers all industries and attack types, not bookkeeping specifically. The same summary also points to misdelivery, meaning information sent to the wrong recipient, as a driver of errors in public administration, where correspondence volume is high.
Month-end delivery has the same ingredients: high volume, tight deadlines, and a human choosing the recipient. For a small firm, one misdirected file costs trust, and trust is the product.
The ProblemWhere Delivery Usually Goes Wrong
Four habits cause most of the exposure, and most bookkeepers use at least one of them.
- Email attachments. A PDF in an inbox can be forwarded, synced to a phone, or sent to the wrong person with one click. Once it leaves your outbox, you can't pull it back.
- "Anyone with the link" Drive shares. It's convenient, but anyone who holds the URL can open the file, whether or not you meant them to have it. Links get pasted into group chats and forwarded along.
- Link sprawl. Twelve clients and twelve months means a new link every time. Nobody, including you, can say which links are still live or who has them.
- No clean off switch. When a client's office manager leaves or a contact changes, the old emails and links keep working.
None of these require a hacker. They require a busy week. The fix is not more vigilance on your part. It is a delivery method where a single slip doesn't expose the file.
The SolutionThe Two-Lock Model
A client needs two things to open a report: the portal passcode and the right Google account. Each lock covers a different risk.
Lock 1: The Passcode-Protected Portal
Each client gets one private portal with its own passcode. It works as a professional delivery bridge, one branded place that holds all of that client's report links, with no portal account or password for the client to manage.
Lock 2: Restricted Google Drive Access
Each report stays in your Drive. You share it as a restricted link with the client's Gmail address, so Google itself checks who is signed in before the file opens. One portal can hold many of these links.
The client opens the portal link and enters the passcode.
Unique passcode for each client. No portal account or password.The client clicks a report link. Google checks that they are signed in with the Gmail address you shared the file with.
Link restricted to the client's Gmail. Granted by the bookkeeper, per file. Files stay in the bookkeeper's Drive.A report opens only after the passcode and the right Google account.
Without the passcode the portal stays closed, and without the right Gmail account Google denies access to the file. You decide who gets each file and can remove that access at any time.
Under the HoodWhy Building on Google Workspace Matters
LinklyReports is built around the Google Workspace ecosystem, and Google Drive in particular. That choice has three practical benefits for security.
- Your files never move. They stay in your own Google Drive. LinklyReports stores only the link to each report, never a copy of the file, so there is no second copy of client documents sitting in another system.
- You already know the controls. Restricted access, named accounts, and the ability to change or remove access are Google Drive features you use today. There is nothing new to learn or audit.
- Control stays with you. You decide which files each client can open, and you can change or remove that access whenever you need to.
Your Drive remains the vault. The portal gives clients one consistent, professional place to start.
The ChecklistA 10-Point Checklist for Secure Report Delivery
Use this for every client, every month. Most items take seconds once they become routine.
- Set every report file to Restricted. Never "anyone with the link." Open the sharing dialog and confirm before you add the link to a portal. This is the single most important check, because the Drive layer only protects you when it is applied.
- Share with named Gmail accounts only. Add the exact address of each person who needs the report, nothing broader.
- Deliver from one place. Give each client one portal and add each month's links there, instead of emailing a new link every time.
- Send the link and the passcode separately. For example, the portal link by email and the passcode by text or phone call.
- Use a unique passcode per client. Never reuse one across clients.
- Turn on 2-Step Verification for your own Google account. Your Drive is the vault, so protect the key.
- Ask clients to turn on 2-Step Verification for the Gmail account they use to open reports.
- Deliver reports, not raw documents. Keep bank statements and payroll files out of the portal unless the client truly needs them there.
- Review access every quarter. Check who can open what, and remove anyone who no longer needs to.
- Remove access when people change. When a client's contact leaves, take their Gmail address off the Drive files right away.
For Your BusinessTurn Secure Delivery Into a Selling Point
Clients can't see your security unless you describe it. Treat delivery as part of the service you sell, and mention it early, in plain language.
- Proposals: add one line about how reports are delivered.
- Onboarding: walk each client through their first access once, covering the passcode step and the Google sign-in.
- Engagement letters: state how reports are delivered and who may access them. Have your attorney review the wording.
- Pricing tiers: include secure, branded portal delivery in your premium or advisory-level package, next to your analysis and commentary.
- "Your reports are delivered through a private, passcode-protected portal, never as an email attachment."
- "Your files stay in our Google Drive, and only your named Gmail account can open them."
- "If someone on your team changes, tell us and we remove their access."
A client who has seen how carefully you handle delivery has one more reason to stay, and one more reason to refer you.
ActionTry the Two-Lock Approach With One Client
Pick one client, set up a portal, share their reports as restricted Drive files, and see how month-end feels. A client portal takes under five minutes to set up.
Related reading: Linkly-Reports Client Portal: A Faster, Smarter, More Secure Way to Deliver Monthly Reports
Put Two Locks on Your Next Delivery
One client, one portal, one more reason for clients to trust how you handle their numbers.
Start your free 14-day trial — no credit card required.
Your files stay in your Drive, and your clients get one professional place to find them.