Security that starts when they open it.
Encryption protects a file while it travels. It does nothing once it lands. Share a document as a link that stays yours: bound to one verified reader, watermarked with their identity, revocable the moment you change your mind.
Every control below is a real setting —
Every control below is a real setting, and every row in the trail is a real event type. This is the surface you actually work in.
Four ways a document escapes, and what closes each one.
None of these is an attack. Every one happens after decryption, to a person who was allowed to open the file.
- 01The moment it arrives
It becomes a copy you no longer own
An email attachment is duplicated onto a mail server, a laptop, a phone, and a backup. Recalling the message changes none of them. From here the document has a life you cannot observe.
Send a link, never the file
The document stays on one server you control. The recipient views it; they never receive a copy to keep.
- 02Within the first hour
It gets forwarded to someone you never chose
The most common leak is not an attack. It is a partner forwarding your deck to a colleague for a second opinion. Nothing is stolen, and you still lose track of who holds it.
Bind access to a verified identity
An email allowlist and a verification step mean a forwarded link opens for nobody but the named recipient.
- 03While they read
The screen is captured
No web platform can truly stop a phone pointed at a monitor, and anyone claiming otherwise is selling you something. What you can do is make a captured page traceable to one person.
Watermark with the viewer's own identity
Their email and IP are rendered into every page as they view it. A leaked screenshot names its source.
- 04Weeks later
The link is still live
A round closes, a deal dies, an employee leaves. The link you sent in March is still working in September, and you have no record of who opened it in between.
Expiry and revocation, with an audit trail
Set a date, or kill a link on demand. Every open, by whom and when, stays on the record.
What ten million document views tell us.
Measured across SendNow over roughly eighteen months. It changes which controls are worth paying for.
- 10M+
- document views analysedAcross roughly 18 months of platform activity.
- 2m 30s
- average viewing sessionNobody reads your document end to end on the first pass.
- 1.5x
- rise in repeat viewingA second visit is the strongest signal of real intent.
Two and a half minutes across a document is why an opened-or-not notification is not enough to act on: it cannot tell you which pages held the attention. Full methodology, and the caveats on every derived figure, are in the 2026 State of Document Engagement report.
One file, or the whole set?
Most teams get this wrong in both directions, and it is the difference between a tidy handover and eleven attachments across four emails.
A single link, for a single document
Right for one contract, one deck, one report going to one named person. You get per-viewer analytics, an identity gate and a watermark without setting anything else up.
A secure document sharing portal, for a set
Once you are sending a deck plus financials plus references, separate links stop being manageable. Secure file sharing for business teams at that point means one branded portal holding every file, with its own permissions per section and one access log across the whole room. Vendors also market this as a data room; it is the same object.
How the major platforms handle it.
Every one of these encrypts your file properly. They differ on what you can do after the recipient opens it, which is where documents actually leak.
| Platform | Encrypted | Ties access to a person | Watermark | Revoke after sending | Page-level analytics |
|---|---|---|---|---|---|
| SendNowSendNow | Yes | Allowlist and verification | Dynamic, per viewer | Any time, with audit trail | Page by page |
| Dropbox | Yes | Password on link | No | Delete the link | No |
| Box | Yes | Named collaborators | Yes, static | Any time | No |
| WeTransfer | Yes | Password on link | No | Expiry only | No |
| Proton Drive | End to end | Password on link | No | Delete the link | No |
| DocSend | Yes | Email gate | Yes, on higher tiers | Any time | Page by page |
Behaviour described is each product’s generally available functionality at the time of writing. Enterprise agreements and add-ons can change what any of them supports. A closer comparison against DocSend covers pricing tier by tier.
Questions people ask first.
What is the most secure way to send a confidential document?
Send a link to a document that stays on a server you control, not a copy of the file. Bind that link to the recipient's verified email address, watermark each page with their identity as they read, and set an expiry date. Encryption alone only protects the file between two machines; every one of these controls governs what happens after it arrives.
Is email encryption enough for sensitive documents?
No. Transport encryption protects a message while it moves between mail servers. Once delivered, the attachment is a plain file on a laptop, a phone, and a backup, and it can be forwarded to anyone. Encryption is necessary and it is not sufficient, because almost every real leak happens after decryption by someone who was authorised to open it.
Can any platform actually stop screenshots?
Not completely, and be sceptical of anyone who claims otherwise. Browser controls can block the common capture shortcuts, but nothing stops a second phone pointed at the screen. The realistic goal is attribution rather than prevention: a dynamic watermark carrying the viewer's email and IP means any captured page identifies who was looking at it.
How can I share documents securely for free?
Free tiers across this category consistently include the sharing and the analytics, and consistently exclude the security. Identity verification, dynamic watermarking, and access revocation sit behind a paid plan on effectively every platform, open-source ones included. If a document contains financials or personal data, budget for a paid tier rather than evaluating free options.