How to share a SOC 2 report securely
A SOC 2 Type 2 report contains detailed control descriptions, exception notes, and system architecture details you do not want forwarded around. Email is not the answer. This guide explains why unsafe sharing happens, what a defensible release flow looks like, and how to configure it in practice so buyers get access fast and your security team sleeps well.
Why email attachments fail
Once the PDF is in someone's inbox you have no expiry, no watermark, no audit trail and no ability to revoke. The same PDF then ends up in their next vendor review pack, shared drives, and eventually on a competitor's desktop.
Email also breaks the chain of custody auditors expect. When an examiner asks who has seen your SOC 2 report in the last twelve months, "I sent it to a few prospects" is not an acceptable answer. You need names, companies, timestamps, and proof of NDA acceptance. Email threads do not give you that.
Examples of unsafe sharing
Unsafe sharing usually starts with good intentions. A sales rep wants to unblock a deal before quarter-end, so they attach the SOC 2 PDF to a follow-up email. A founder forwards the report to an advisor who asks for it. A customer success manager uploads it to a shared Dropbox folder so an enterprise client can "take a look."
Each of these creates an uncontrolled copy. The sales rep's email lives in the buyer's inbox forever, forwarded to procurement and legal. The advisor stores it in a personal Google Drive with no retention policy. The Dropbox link is discoverable by anyone with access to the folder, and there is no record of who opened it.
Another common mistake is publishing the full SOC 2 report on a public marketing page to "build trust." This reveals control descriptions an attacker can use to map your environment. It also exposes exception notes that may worry customers who do not have the context to interpret them. The right balance is a public badge and summary with the full report gated behind an NDA workflow.
The minimum bar for a release flow
A defensible SOC 2 release flow has four ingredients: an NDA (or signed acceptance), a watermark tied to the individual requester, a time-limited download link, and an audit log of every view and download.
The NDA establishes legal accountability. It does not need to be a forty-page custom agreement. A short click-through acceptance with the requester's name, company, and email is enough for most mid-market deals. Enterprise buyers may require their own paper, but you can still route that through a portal so the acceptance is timestamped and logged.
The watermark creates traceability. If a PDF leaks, the diagonal watermark tells you exactly which requester downloaded it. Most procurement teams understand this and will not object. In fact, many enterprises prefer watermarked copies because it proves the report came from you and has not been altered.
Time-limited links reduce exposure. A twenty-four hour window is standard. It gives the reviewer time to read the report and share it with their security team without leaving a permanent access path open. If the buyer needs more time, they can request a renewal, which creates another log entry.
The audit log is what you show your own auditors. It should record the request, the NDA acceptance, the approval decision, the download timestamp, and the IP address. This turns a vague "we shared it with prospects" into a concrete list of every human who has touched the document.
Recommended workflow
Start by uploading the SOC 2 PDF to your trust portal and marking it NDA-required. The document still appears on the public page so buyers know it exists, but the download button triggers a request flow instead of serving the file directly.
Next, configure your NDA. Choose between a built-in click-through template, your own uploaded text, or a full e-signature integration like DocuSign or SignNow. For teams under ten security reviews a month, click-through is usually enough. For teams doing fifty or more, e-signature gives you a legally stronger paper trail.
Set the approval rules. Manual review is the safest default. It lets you spot unusual request patterns — like a competitor domain or a free email address — before releasing the file. As volume grows, you can auto-approve requests from known domains while keeping manual review for everyone else.
Enable watermarking and set the expiry. The watermark should include the requester's name and email on every page. The link expiry should match your policy; twenty-four hours is standard, but some teams prefer seventy-two hours for long holiday weekends.
Finally, test the full flow end to end. Request the document yourself, sign the NDA, download the PDF, and check the audit log. Verify the watermark is visible, the link expires on schedule, and the log captures every step. Run this test after every SOC 2 refresh so you know the process still works when a real buyer shows up.
Set the SOC 2 to NDA-required
In VendorLens, mark the SOC 2 PDF as NDA-required. It still appears on the trust page so buyers can see it exists, but downloading requires a request and an approved NDA. This single toggle is what separates a public brochure from a controlled document release.
If you have multiple SOC 2 reports — for example, a Type 2 and a bridge letter — upload each as a separate document and set the visibility independently. Some teams make the bridge letter public while keeping the full Type 2 gated. This gives buyers confidence that the audit is current without exposing control-level detail.
Configure NDA acceptance
Use the built-in template, your own NDA text, or a DocuSign / SignNow flow. Decide whether requests auto-approve on signature or wait for manual review. Manual review is the right default for the first month so you can spot patterns before turning on automation.
The NDA text should cover three things: confidentiality of the report, prohibition on redistribution, and permission to share internally within the requester's organization for the purpose of vendor evaluation. Keep it to one page if possible. Long NDAs slow down procurement teams and increase the chance a buyer abandons the review.
Watermark the download
VendorLens injects a diagonal watermark with the requester's name and email on every page of the PDF on download. Even if the buyer forwards the file, the source is traceable. This is not about distrusting your customers — it is about creating accountability that satisfies both your auditors and their auditors.
Watermarking also protects against accidental leaks. A buyer may forward the PDF to a colleague without thinking. If that colleague then forwards it again, the original watermark is still there. In a worst-case scenario where the file appears on a public forum, you know exactly which organization leaked it.
Expire the link
Default token expiry is 24 hours. For longer access, configure a longer window, but most reviews do not need more than a day. A security reviewer typically downloads the PDF, reads it, and shares selected pages with their team within a single working session.
If a buyer asks for an extension, treat it as a new request. This creates a fresh audit log entry and reminds the requester that access is temporary. Some teams offer a seventy-two hour window for enterprise deals with complex procurement committees. The key is to document the policy and apply it consistently.
Keep the audit log
Every NDA signature, request, approval, view and download is logged with a timestamp. This is what you show to your own auditors when they ask how you control distribution. The log should include the requester's name, email, company, IP address, document version, and action taken.
Review the log weekly for the first quarter after launch. Look for repeat requesters, unusual domains, and failed requests. A failed request is often a sign that the buyer hit the expiry window or had a corporate firewall issue. Following up on these proactively improves your close rate and shows buyers you take security seriously.
Quick checklist
- SOC 2 PDF uploaded and marked NDA-required
- NDA template configured (or DocuSign / SignNow connected)
- Approval rules set (manual or auto-approve by domain)
- Watermarking enabled
- Token expiry set to 24h (or your policy)
- Audit log reviewed and accessible to your team
- End-to-end test completed after each SOC 2 refresh
Frequently asked questions
Can we just email the SOC 2 report to trusted prospects?
No. Email removes expiry, watermarking, and audit trail. Even trusted prospects change roles, and their inboxes are not your system to control.
Do we need a custom NDA for every buyer?
Not usually. A standard click-through NDA covers most mid-market deals. Enterprise buyers may send their own paper, which you can route through the same portal for logging.
How long should the download link last?
Twenty-four hours is the standard default. Extend to seventy-two hours for complex enterprise procurement if your policy allows it.
What if a buyer shares the watermarked PDF internally?
The watermark identifies the original requester, so the leak is traceable. Your NDA should explicitly permit internal sharing for evaluation purposes while prohibiting public redistribution.
Does watermarking affect the report's validity?
No. The watermark is overlayed at download time and does not alter the underlying audit content. It is a standard practice accepted by auditors and procurement teams.