A daily copy of every client document. Landing in a folder you own in Dropbox.
Connect your firm's Dropbox and ImmiIQ backs up every client and sponsor document, once a day, into a folder tree that lives inside your account. Bring your own storage. Keep the external copy under your firm's control. If you ever move off the platform the archive is already sitting on your side.
- Priya Sharma / passport.pdf2.4 MB
- Priya Sharma / IELTS_2026.pdf1.1 MB
- Daniel Nguyen / skills_assessment.pdf3.8 MB
- Sponsors / Northmore Hotels / SBS.pdf0.9 MB
- Sponsors / Northmore Hotels / labour_agreement.pdf1.6 MB
What the Dropbox backup actually does.
Every capability listed below is live in production today. Nothing here is a roadmap promise or a marketing stub.
Daily incremental run
Once a day the scheduled job compares the sealed manifest against what has changed since the last run and uploads only new or updated documents. Bandwidth stays proportional to real activity.
Folder tree you own
Pick the parent folder from inside ImmiIQ. We create a subfolder per client and a subfolder per sponsor beneath it. Rename, move or share from Dropbox without breaking the backup.
Clients and sponsors
Every uploaded document on both the client record and the sponsor record is included. Passports, skills assessments, references, SBS forms, labour agreements and generated PDFs all end up in your Dropbox.
Manifest and audit log
Each run writes a manifest of what was copied, what was skipped and any errors. The tenant audit log records the run outcome so a compliance reviewer can confirm the backup happened.
How it works.
Three stages. Connect, configure and then everything else runs itself. The next scheduled run kicks off at the hour you picked.
Connect
Sign in with your Dropbox account under Settings then Integrations then Dropbox. Dropbox shows the exact scopes ImmiIQ has asked for. Approve and the connection is live. Dropbox Business team accounts and individual accounts both work.
Configure
Pick the parent folder for the backup tree. Choose whether to include historical documents in the very first run or start from today. Set the hour of day the run fires, in your own timezone, so the copy lands outside office hours.
Automate
The scheduled job runs once a day. Only new or updated documents move. The manifest is sealed and stored so re-runs are idempotent and the audit log records the outcome for compliance.
In the app
One folder. One schedule. A copy of everything.
The Dropbox backup tile sits in the Integrations marketplace inside the app and opens its own settings page. The first run backfills any historical documents you asked for, then the daily cadence takes over.
Security posture
Your Dropbox. Your key. Our copy job.
Access and refresh tokens are sealed with AES-256-GCM using a per-organisation key derived from AUTH_SECRET via HKDF. Dropbox issues a short-lived access token against a long-lived refresh token and the sealed row is updated in place on every exchange. Plaintext tokens never touch the database and never appear in logs. Every connect and disconnect is written to the tenant audit log with the actor, timestamp and IP. Tenant isolation is enforced at the row level: Dropbox credentials for one organisation cannot be queried, indexed or read from another organisation under any code path. Revoking the connection deletes the sealed row immediately, calls the Dropbox token revoke endpoint so ImmiIQ is removed from your linked apps and stops the scheduled job for that organisation within seconds. The daily manifest is stored on our side so re-runs are idempotent and a compliance reviewer can trace exactly what was copied on any given day. Nothing outside the ImmiIQ backup folder is touched by the integration.
Frequently asked.
What exactly gets backed up to my Dropbox?
Every document uploaded to a client or sponsor record in ImmiIQ is copied into a folder tree you own inside Dropbox. Passports, skills assessments, employment references, contracts, invoices and generated PDFs are all included. The client-facing metadata (name and case number) stays with the folder so you can navigate the archive without opening ImmiIQ.
How often does the backup run?
Once a day, at an hour you pick in your own timezone. The scheduled run compares the sealed manifest against what has changed on the case since the last successful run and uploads only the new or updated documents so bandwidth stays proportional to real activity. There is no manual re-run required.
Does the backup work with Dropbox Business team accounts?
Yes. The integration works with both Dropbox Business team accounts and individual Dropbox accounts. The backup writes into the folder tree of the account that authorised the connection, so a team member folder or a shared team space both work. Firms on Dropbox Business usually connect with an admin account so the archive is not tied to one person's login.
Which Dropbox scopes does ImmiIQ ask for?
We request account_info.read, files.metadata.write, files.content.write and files.content.read. account_info.read supplies the account email shown on the settings page. The two write scopes let the daily run create folders and upload documents. The read scope lets a restore flow read back what we wrote. Nothing outside the ImmiIQ backup folder is touched.
How are Dropbox OAuth tokens stored and what happens on disconnect?
Access and refresh tokens are sealed with AES-256-GCM using a per-organisation key derived from AUTH_SECRET via HKDF. Dropbox issues a short-lived access token against a long-lived refresh token and we persist the sealed row in place. Disconnecting the backup deletes that row immediately, calls the Dropbox token revoke endpoint so ImmiIQ drops off your linked apps list and stops the scheduled job for that organisation. Every connect and disconnect is written to the tenant audit log.
Related integrations.
Turn on daily Dropbox backups in one minute.
Start a trial, connect your firm's Dropbox and pick a parent folder. Overnight the first backup lands. From then on your archive stays current on its own.