Secure Document & Data Portal
Collect your people's most sensitive documents and personal data securely, provably, and without ever storing a password.
- GDPR aligned
- Microsoft Entra ID sign-in
- Tamper-evident audit trail
- Fully white-labelled
- Deployed in your own Azure tenant
Right now, your most sensitive data arrives by email.
Every new joiner hands over the most sensitive information they own: passport or national ID, right-to-work documents, National Insurance number, bank details, home address, next of kin, and sometimes health or disability information. In most organisations that arrives as an email attachment, and from there it multiplies: into mailboxes, shared drives, laptop backups and forwarded threads, with no record of who opened it.
Under UK GDPR, ID documents and bank details are high-risk personal data, and health information is special category data needing its own explicit lawful basis. The ICO expects you to show appropriate technical and organisational measures, and to answer a subject access request within one month. An email thread is not a defensible answer to either.
One door in. Every action recorded.
The Secure Document & Data Portal replaces that whole flow with a single, branded portal that lives in your own Microsoft Azure tenant. New joiners sign in with Microsoft, send what HR asked for, and never see it again. HR reviews it in a controlled workspace where the audit entry is written before the data is released.
For your new joiners
One address, one sign-in, a clear list of what's needed. No attachments, no chasing, no wondering where their passport ended up.
For your HR team
Everything in one place, per person, with status at a glance, and a register they can search instead of a mailbox they have to remember.
For your DPO and IT
A record that answers “who saw this, and when” without anyone assembling it afterwards. In your tenant, on your resources.
Five things that make this different.
- 01
New joiners can send. They can never see.
The personal information form is write-only. Once a new joiner submits their National Insurance number, bank details or ID, they cannot read it back, not on screen, not through the API. A stolen laptop or a phished account exposes nothing, because there is nothing there to expose. Correction is possible (it creates a new version); retrieval is not.
- 02
An audit log that not even we can edit.
The compliance audit trail lives in its own isolated database, and the portal's identity can only create, read and query entries. Update and delete were never granted. Azure enforces that at the platform level, not our application code, so the log cannot be rewritten by a compromised administrator, a rogue insider, or by us.
- 03
Every look is logged before it happens.
When a manager opens an employee's record, the audit entry is written first. If the log write fails, the read is refused. There is no path through the system that reveals personal data without leaving a record behind.
- 04
No passwords. Not one. Ever.
Sign-in is Microsoft Entra ID only, so your existing MFA and conditional access already apply, and disabling someone in Entra removes their portal access automatically. New joiners come in through invitation-only External ID. Services authenticate to one another with managed identities, so there are no connection strings or shared keys either.
- 05
It runs in your tenant, not ours.
Database, documents, email, audit log and telemetry all deploy into your own Azure subscription, in Azure UK South, on resources you own. Innodux Labs has no runtime access to any of it, which removes most of a third-party hosting assessment before it starts.
Enterprise features as standard
Single sign-on, white labelling, a custom domain, UK/EU data residency, SharePoint integration and a real audit trail: the features others reserve for quote-only tiers are the product.
Flat fee. Unlimited employees.
The fee does not move when you hire. Onboarding two thousand people next year does not change your invoice.
Live in days, not quarters.
No data migration and no integration project. An automated installer deploys into your Azure subscription; everything after go-live is self-service.
Everything is included. Everything is live.
Employee experience
- Sign in with Microsoft Entra ID (staff) or invitation-only Microsoft Entra External ID (new joiners and contractors). No passwords stored.
- Invitation-only sign-up, enforced at the identity layer. Invitations can be revoked and their status is tracked.
- Secure document upload against a configurable list of document types (passport, ID, right-to-work and more), with upload history and confirmation emails.
- Personal information form (English/French): identity, address, contact, family, bank details, emergency contacts. Append-only, versioned, and write-only for the employee.
- Article 9 health and disability data behind its own separate, explicit consent, never bundled into the main consent.
- Typed-name declaration with versioned attestation text, timestamped and audit-trailed.
- Versioned consent gate: acceptance recorded with timestamp, IP address, device and policy version. A new policy version re-prompts every user at next sign-in.
- Profile page with the employee's own consent history.
- In-portal data-subject rights: employees raise access (Art. 15) and erasure (Art. 17) requests inside the portal.
HR workspace
- One row per employee with what they have sent and status at a glance.
- Every read of an employee's documents or form is audit-logged before access is granted.
- In-portal document viewer: PDFs, Word files and spreadsheets render inside the portal, so a passport scan never needs to reach a laptop's Downloads folder.
- Tamper-evident PDF export of any personal-information submission, generated from your own Word template, with a SHA-256 integrity fingerprint and an audited, HR-only download.
- Data-subject request queue with status tracking, so the one-month clock is visible.
- Amendments create a new version; the previous one is never destroyed.
Security and governance
- Isolated, append-only audit log store (create, read and query only). Enforced by Azure role assignment, not application code.
- Unified compliance audit-log viewer: admin actions, consent events, policy history and every personal-data read in one filterable timeline.
- Tenant-wide view-only mode: downloads disabled at the server, not just in the browser.
- Upload content validation against the file's actual bytes, not its name. A renamed executable is rejected.
- Separation of duties: IT-administration roles have no access to employee documents or personal-information records.
- Configurable section access by role, with a “View as” preview before saving.
- TLS 1.2+ end-to-end, encrypted at rest, managed identities between services.
- Per-organisation isolated deployment: dedicated resource group, databases, storage, email service and identity tenant.
Microsoft 365 integration
- Microsoft Entra ID single sign-on with your existing MFA and conditional access policies.
- SharePoint write-back: bind your own site, define per-employee folder and file-naming templates, and move documents and generated PDFs into your library so your retention and eDiscovery policies apply as normal.
- Email from your own domain via Azure Communication Services in your tenant.
White-label and self-service administration
- Branding: logo, exact brand colours, typography, custom font upload, favicon, welcome message, home-page content and video.
- Your own web address, editable sign-in page copy and customisable email templates.
- Privacy policy and terms editor with full version history, preview and restore.
- Document-type configuration; the personal information form can be switched off if you don't need it.
- Choose whether access and erasure requests are raised in-portal or routed to a contact address.
- All configured by your own administrators. No change requests to us.
Deployment and operations
- Automated installer into your Azure subscription and Entra tenant.
- Choice of 14 UK and EEA Azure regions.
- Structured logs, error references and telemetry stay in your tenant.
- All platform updates and security patching included throughout the term.
Your tenant. Your region. Your resources.
This is the question a security team asks first, so here is the precise answer.
| Component | Where it runs | Whose resource |
|---|---|---|
| Database (records, personal information forms) | Your chosen Azure region | Yours |
| Document storage (uploaded files) | Your chosen Azure region | Yours |
| Audit log (isolated, append-only store) | Your chosen Azure region | Yours |
| Email service | UK or EU data location | Yours |
| Telemetry and logs | Your chosen Azure region | Yours |
| API and web front end | Your chosen Azure region | Yours |
| Entra identity data | Microsoft's identity platform | Microsoft |
| Application bundle delivery | Fetched server-side by your own App Service; no employee browser connects to it | Innodux Labs |
| Licence check | Outbound call from your tenant; installation ID, version and one configuration counter. No personal data | Innodux Labs |
Supported regions: UK South, UK West, West Europe, North Europe, France Central, France South, Germany West Central, Germany North, Norway East, Norway West, Sweden Central, Poland Central, Italy North, Spain Central.
Two honest caveats
- Your users' Entra identity data sits on Microsoft's identity platform under your own Microsoft agreement. Some identity metadata is processed in Microsoft's non-regional identity services. We do not host it and cannot relocate it.
- Your portal makes two outbound calls to us: it fetches the application bundle and it checks its licence. Both are server-to-server from your own App Service. No employee browser talks to our infrastructure, and no personal data is carried. Both are covered in the data processing agreement.
“This runs inside our own Azure tenant. The supplier doesn't hold our employees' documents or personal data. We do, in our subscription, under our Microsoft agreement.”
How it answers UK GDPR, obligation by obligation.
| Obligation | How the portal answers it |
|---|---|
| Lawful basis and consent (Art. 6, 7, 9) | Versioned privacy policy with an enforced acceptance gate. Every acceptance stored with timestamp, IP address, device and the exact policy version. Article 9 health data behind separate explicit consent. |
| Data minimisation (Art. 5(1)(c)) | You configure exactly which fields and document types are requested. Fields you don't need aren't collected, and your own administrators can change the form without a code change. |
| Integrity and confidentiality (Art. 5(1)(f), 32) | Encrypted in transit (TLS 1.2+) and at rest. No passwords stored. Write-only personal-data intake. Managed-identity access between services. |
| Accountability (Art. 5(2), 30) | A tamper-evident audit log in an isolated store the application cannot modify or delete, covering administrative actions, consent events, policy changes and every read of personal data. |
| Subject access and erasure (Art. 15, 17) | Employees raise requests inside the portal. They land in a managed queue for HR with status tracking, so the one-month clock is visible rather than discovered late. |
| Rectification (Art. 16) | Corrections are submitted as a new version. The record shows both the correction and the history. |
| International transfers (Ch. V) | Personal data is stored and processed in the Azure region you choose, inside your own tenant. The narrow exceptions are disclosed in full above. |
| Exit and portability (Art. 20) | The entire deployment sits in your own Azure subscription. Your data is already yours, in your tenant, on day one. There is no extraction exercise if you leave. |
Live in days, not quarters.
There is no data migration and no integration project. The portal is deployed into your Azure subscription by an automated installer, connected to your Entra tenant, branded, configured and handed over. Everything after go-live is self-service.
You give us
- An Azure subscription
- Your Entra tenant
- Your brand, forms and policy wording
We give you
- A deployed, branded portal
- Configured roles and document types
- Handover to your administrators
One flat fee per organisation. Unlimited employees, unlimited documents.
- The software licence, with every feature included. No higher tier holding back the features you need.
- Unlimited employees and documents. The fee doesn't move when you hire.
- All platform updates and security patching throughout the term.
- Standard support: business hours, email, response within two business days; same-business-day response for incidents affecting portal availability or document access.
- Data processing agreement, sub-processor list and security overview.
- Optional Priority support: a named contact, configuration changes made on your behalf, faster response times.
- Azure consumption is billed by Microsoft directly to your own subscription and is typically modest for this workload.
Questions we're asked most.
Is this a SaaS? Where is our data?
No. The portal is installed into your own Azure subscription and Entra tenant, in the UK or EU region you choose. Your database, documents, audit log, email service and telemetry are your resources. Innodux Labs has no runtime access to them.
Do our employees need a new password?
No. Staff sign in with your Microsoft Entra ID; new joiners and contractors are invited into an invitation-only Microsoft Entra External ID tenant. There is no password database in the product.
Can an employee see what they submitted?
No. The personal information form is write-only. Employees can submit a correction, which creates a new version, but cannot read their data back on screen or through the API.
Who can see employee documents?
Only the roles you assign. IT-administration roles have no access to employee documents or personal-information records. Every read by an authorised HR user is logged before access is granted.
Can the audit log be edited?
No. It lives in an isolated store where the portal's identity holds create, read and query permissions only. Update and delete were never granted, and Azure enforces that.
Does it work with SharePoint?
Yes. Bind your own SharePoint site and push documents and generated PDFs into per-employee folders with your own naming templates. Your retention and eDiscovery policies then apply as normal.
How long does deployment take?
Technical deployment is a matter of days: an automated installer, no data migration, no integration project. The timeline is usually set by your own security review and by how quickly your form and policy wording are signed off.
What does it cost?
One flat fee per organisation with unlimited employees and documents, all features included. Azure consumption is billed by Microsoft to your own subscription. Contact us for a quote.
What happens if we stop using it?
Everything stays in your Azure subscription: data, audit logs, identity objects. There is no extraction exercise.
Do you offer it to partners or resellers?
Yes. Fiduciaries, MSPs and HR consultancies can offer a branded portal to their own clients. Contact us for partner terms.
Security overview, data processing agreement and sub-processor list available on request. We're happy to complete your standard supplier questionnaire.
Book a 45-minute working demonstration.
Live system, your questions. We'll walk your HR lead through a full employee submission and your IT lead through the identity, audit and hosting model.