Simply Discover | Secure delivery

LFX

Send securely.
Keep the conversation going.

Protected messages and large files from Outlook or the web. Verify recipients, exchange documents, and bring colleagues into a collaboration room when the work grows.

  • Encrypted content
  • Recipient-bound access
  1. 01

    Prepare

    Outlook or the web

  2. 02

    Verify

    Identity before access

  3. 03

    Continue

    Replies, files and rooms

Outlook or the webMessages, files, or both
Verified recipient accessEmail verification or passkeys
Evidence of accessPeople, files and timestamps
From the first message to the next piece of work

A confidential brief is only the beginning.

Consider a legal team sharing documents with external counsel. Priya needs to send a confidential brief, receive documents back, and bring a colleague into the matter as it develops.

01 / Send

Start where the conversation already happens.

Priya prepares the delivery in Outlook. She can protect the whole message and its files, or keep her email and signature in Outlook while protecting just the attachments.

The browser composer offers the same essentials: multiple recipients, a subject, a protected message and files. She sets an expiry and decides whether Alex can reply or return documents.

The notification carries an invitation. Protected content is accessed through Simply Discover after the recipient verifies their identity.

Outlook deliveryLFX
To
Alex / External counsel
Subject
Documents for review

The email contains a secure invitation.

A protected message from Priya

The message body and files are available after identity verification.

Protected message2 secure files
Outlook sends the email once preparation is complete.
Illustrative delivery. Both protection modes use the recipient gateway.
02 / Verify & respond

A secure exchange that works for the recipient.

Alex follows the link and verifies the addressed email identity. Depending on the delivery policy, access uses an email code, a passkey or a security key. A full Simply Discover account is normally unnecessary for external recipients.

After explicitly opening the delivery, Alex can preview supported PDFs and images, download selected files, and send a protected reply. Priya has enabled file returns, so Alex can upload documents into the same conversation.

Each recipient has their own access. Forwarding the invitation alone does not authorise someone else to open the content.

Protected deliveryIdentity verified

Documents for review

From Priya · Addressed to Alex

PDF
Review brief.pdfPreview and download
PDF
Supporting documents.pdfPreview and download
Alex replied
I've added the signed instructions to this conversation.
Signed instructions.pdf · Returned securely by Alex
Illustrative recipient experience. Replies and uploads follow the sender's policy.
03 / Continue together

When the work grows, the conversation can grow with it.

Priya promotes the private delivery into a collaboration room and adds Morgan to the legal team. The original messages, files and access evidence are retained, so Morgan can pick up the work with its context intact.

Authorised owners and administrators manage membership, roles and invitations. New files can be kept internal to the team or deliberately shared with external participants.

Room membership and file visibility are separate choices. Inviting an external guest does not automatically reveal the original files or internal-only uploads.

Legal review roomConversation retained
  • PriyaOwner
  • MorganInternal member
  • AlexExternal participant
Internal review notes.pdfInternal only
Updated instructions.pdfExternal access enabled
Original messages, files and recipient permissions are preserved.
Illustrative room. Later uploads have an explicit audience.
Larger matters, manageable transfers

470 files. One legal matter.

Some matters involve hundreds of mailbox exports. In this example, the team declares a 470-file room batch and follows each file from upload to availability.

  • Per-file status and overall progress show what has arrived and what still needs attention.
  • Retry failed files or resume remaining work while retaining files already completed.
  • Declare the batch ready after file counts and byte totals reconcile.
  • Search the catalogue and download a selection through a managed queue.

Room batches support up to 10,000 declared files, subject to storage and upload policy. Practical transfer performance depends on the deployment, network and browser.

Mailbox exportsPreparing
467 / 470files available
Completed files retained3 remaining
PST
Mailbox 467.pstAvailable
PST
Mailbox 468.pstUploading
PST
Mailbox 469.pst & Mailbox 470.pstQueued
The room is usable while the remaining files arrive.
Example batch state. PST files are downloaded for use in a compatible application.
Control that stays with the delivery

Clear decisions about people, content and time.

Senders choose the audience and delivery options within the organisation's policy. Administrators govern the service. Protected access is checked when content is requested.

Recipient verification

Use email verification or passkeys according to policy. For phishing-resistant deliveries, email verification alone cannot unlock the protected content.

Encrypted content

Messages use authenticated encryption and files use AES-256-GCM. The authorised service manages decryption, preview and delivery.

Expiry and use limits

Set delivery expiry and protected-message view or file-download limits. Recipients can request more time where replies are enabled; the sender decides.

File policy and DLP

Apply upload limits and blocked file types. With DLP configured, sharing waits for an allowed policy decision and downloads can recheck that decision.

Governed collaboration

Manage owners, admins, members and external invitations. Transfer ownership explicitly and choose who can see each later room upload.

Organisation settings

Configure roles, verified link domains, recipient branding, storage, key management and retention. Administrative content review requires separate authority.

See what happened after the invitation.

Authorised reviewers can distinguish message views, file previews and download events by person, file and time. Filter the audit history and export evidence to CSV.

The record shows what the service observed. A message view does not prove that a person read it, and a transfer does not prove what happened to a downloaded copy.

  1. Alex opened the protected messageMessage view
  2. Alex previewed Review brief.pdfFile preview
  3. Supporting documents.pdf transferredFile download

Example events. Email delivery and room-guest activity have their own evidence sources.

The experience at a glance

One delivery, different ways to work.

The sender chooses how to begin. Recipients use the protected gateway, and a room adds collaboration when needed.

Availability and limits follow the organisation's licence, roles, deployment and policy.
CapabilityWeb senderOutlook senderRecipient & room
Messages and filesMessage, files, or bothProtect the whole message or selected filesOpen authorised content
Multiple recipientsInternal and external addressesPreserves To, Cc and BccRecipient-specific access
Replies and returnsEnable replies and file uploadsOptions depend on protection modeRespond when permitted
Preview and downloadSearch and select filesManage through the platformPDF/image preview and managed downloads
Expiry managementOwner sets and changes expiryManage through the platformRequest an extension; room managers can approve within policy
Collaboration roomsPromote a private deliveryPromote through the platformRoles, invitations and file audiences
Larger file batchesRoom upload workflowContinue in a platform roomSearch, select and download available files
Access evidenceReview delivery activityReview through the platformAuthorised audit and CSV export
A few practical details

What to know before using LFX.

The controls are useful when their scope is clear.

Does everyone need an account or an add-in?

External recipients normally use the browser gateway without a full platform account. They must verify the addressed identity and meet the delivery's authentication policy. The Outlook add-in is for senders; authorised senders can also use the web composer. Internal recipients can open addressed deliveries from their Received list, with the same protected-access checks.

Which Outlook content can be protected?

Whole-message protection can preserve supported formatting and eligible inline images on a compatible deployment. Attachments-only mode keeps the ordinary body and signature in email. Native conversion supports eligible local file attachments; Outlook item and cloud attachments are not supported by that conversion. Larger files can be selected through the add-in's file picker, within configured limits. Subjects and recipient addresses remain email metadata, so confidential detail belongs in the protected content.

What happens if a transfer is interrupted?

Uploads support resumable transfer and per-file retry. Completed files can be retained while remaining work is recovered. After a browser reload, the user must reselect the original files to match retained upload state. Managed multi-file downloads support stopping after the current file, resuming remaining files and retrying failures. Browser and device capabilities still affect recovery and performance.

Can access be withdrawn after sending?

Expiry and supported revocation controls prevent future service access. Room owners and admins can remove members or revoke guest access, but that does not remove a separate original-recipient entitlement. Whole-delivery revocation is owner-authorised; a general revoke button is not currently exposed in the modern sender workspace. No control recalls an independent copy already downloaded.

What are the file and recipient limits?

Ordinary deliveries default to 10 recipients and 10 attachments. Administrators can configure up to 1,000 recipients and 100 attachments, including bound inline assets, within server limits. Room batches support up to 10,000 declared files. File-size policy, storage, browser, network and DLP capacity determine what is practical for a particular deployment. These are validation limits, not transfer-speed promises.

How are encryption, storage and retention handled?

Content is encrypted by the application before final protected storage, using the configured key-management service and compatible Azure Blob or S3 storage. This is service-managed encryption, not zero-knowledge end-to-end encryption. Delivery expiry controls access; retention and cleanup are separate administrator policies. Historical audit availability depends on those retention choices.

Does a room include meetings, approvals or signing?

A promoted delivery provides protected conversations, files and governed collaboration. Audio/video meetings, approval workflows, signatures and Secure Intake are separate Simply Discover capabilities, not automatically included in a promoted delivery room. Supported archive and case exports can also be shared securely through their established sharing workflow.