Your client sends a contract. You drop it in a shared Dropbox folder. They download it, sign it on their phone, and email it back to you. You now have three versions of the same document scattered across email, Dropbox, and your local drive. When you need to prove who signed what, and when, you dig through timestamps and folder structures. Six months later, a client asks for a copy of an old agreement. You search your folders. Nothing surfaces. This is where most service businesses live: they've outgrown ad-hoc email but haven't bought into the idea that document management needs a dedicated system. File drops feel free and frictionless until they don't. Custom client portals cost £5k to build and feel like overkill for a five-person team. The middle ground—where most businesses actually need to be—doesn't get much attention. We've seen this pattern repeat: companies build elaborate document portals with permission trees, audit trails, and branded interfaces. Then they realise 80% of document exchange happens once, in one direction, with one person. The portal sits quiet. The team goes back to email and Dropbox. The cycle repeats. Here's what actually matters, and where the equation has shifted. Where file drops fail (and when they still work) Dropbox and Google Drive are not document management systems. They are storage. That distinction matters. They work fine for: One-time document exchanges (client sends invoice receipt, you file it). Internal team collaboration on living documents (spreadsheets, drafts, brainstorms). Archival storage you rarely need to retrieve fast. They break down when: You need proof of delivery and signature. Dropbox doesn't track who opened what, when, or whether they actually read it. For contracts, quotes, and compliance documents, this matters. Legally and operationally. Permissions become complex. If a client needs access to one project's docs but not another, or if you have subcontractors who should see specs but not pricing, file permissions get tangled fast. Dropbox permissions are binary: they see everything or nothing in a folder. You need a single source of truth across your business. A contract lives in Dropbox. A signed version lives in email. The finalised version lives on your accountant's system. Nobody knows which one is current. Disputes happen. Your clients expect a professional touchpoint. When a client logs in to a white-label portal with your logo, sees their documents in one place, and signs with a single click, it changes how they perceive your business. A shared Dropbox folder reads as scrappy. You're managing dozens of ongoing relationships. With five clients, email and Dropbox work. With 50 or 200, you're spending hours hunting documents and chasing signatures. The math breaks. Why custom portals are usually the wrong answer A custom client portal—the kind built with React, hosted on your own server, with login management and permission matrices—costs £8k–£20k to build and £2k–£5k a month to maintain. A contractor changes jobs. Your hosting costs spike. You realise you need to add two-factor authentication or SSO. The scope creeps. The costs accelerate. More often, a custom portal gets built for one client's specific request and then sits underused because: Adoption is low. Your clients don't use it because they're already in email. They download the file, take it somewhere else, and send you a message asking where to sign. The portal becomes a filing cabinet, not a workflow. Maintenance is invisible. Security patches, database backups, user resets—these don't appear on an invoice, so they feel free. They're not. Someone on your team is handling them. Integration costs compound. Your portal needs to talk to your CRM, your billing system, your contracts tool, and your email. Each integration takes time. Each one is another failure point. For most small teams, a custom portal is a solution to a problem you haven't actually defined yet. Where SaaS portals win (and it's narrower than vendors claim) A SaaS client portal—the kind you license from a vendor—fixes the build and maintenance burden. You get hosted infrastructure, user management, and usually some level of integrations out of the box. They genuinely shine when you need: Audit trails. Proof that a document was sent on Tuesday at 3 PM, opened at 4:15 PM, and signed at 4:32 PM. This matters for contracts, compliance documents, and anything where timing or intent might be disputed later. Granular permission control. Client A sees projects 1 and 2. Client B sees projects 2 and 3. Subcontractor C sees specifications but not pricing. Portals with role-based access control handle this cleanly. Branding and professionalism. Your logo, your colours, your domain. Your clients interact with your brand every time they log in. This is worth something, especially in wealth management, legal services, or B2B consulting where trust is currency. Centralised compliance. If you're subject to SOC 2, ISO 27001, or GDPR, a