We use cookies and similar technologies to improve your experience and analyse usage. By continuing you agree to our Privacy Policy.

    VendorLens
    ← Guides

    How to share a SOC 2 report securely

    10 min readLast updated

    A SOC 2 Type 2 report contains detailed control descriptions, exception notes, and system architecture details you do not want forwarded around. Email is not the answer. This guide explains why unsafe sharing happens, what a defensible release flow looks like, and how to configure it in practice so buyers get access fast and your security team sleeps well.

    Why email attachments fail

    Once the PDF is in someone's inbox you have no expiry, no watermark, no audit trail and no ability to revoke. The same PDF then ends up in their next vendor review pack, shared drives, and eventually on a competitor's desktop.

    Email also breaks the chain of custody auditors expect. When an examiner asks who has seen your SOC 2 report in the last twelve months, "I sent it to a few prospects" is not an acceptable answer. You need names, companies, timestamps, and proof of NDA acceptance. Email threads do not give you that.

    Examples of unsafe sharing

    Unsafe sharing usually starts with good intentions. A sales rep wants to unblock a deal before quarter-end, so they attach the SOC 2 PDF to a follow-up email. A founder forwards the report to an advisor who asks for it. A customer success manager uploads it to a shared Dropbox folder so an enterprise client can "take a look."

    Each of these creates an uncontrolled copy. The sales rep's email lives in the buyer's inbox forever, forwarded to procurement and legal. The advisor stores it in a personal Google Drive with no retention policy. The Dropbox link is discoverable by anyone with access to the folder, and there is no record of who opened it.

    Another common mistake is publishing the full SOC 2 report on a public marketing page to "build trust." This reveals control descriptions an attacker can use to map your environment. It also exposes exception notes that may worry customers who do not have the context to interpret them. The right balance is a public badge and summary with the full report gated behind an NDA workflow.

    The minimum bar for a release flow

    A defensible SOC 2 release flow has four ingredients: an NDA (or signed acceptance), a watermark tied to the individual requester, a time-limited download link, and an audit log of every view and download.

    The NDA establishes legal accountability. It does not need to be a forty-page custom agreement. A short click-through acceptance with the requester's name, company, and email is enough for most mid-market deals. Enterprise buyers may require their own paper, but you can still route that through a portal so the acceptance is timestamped and logged.

    The watermark creates traceability. If a PDF leaks, the diagonal watermark tells you exactly which requester downloaded it. Most procurement teams understand this and will not object. In fact, many enterprises prefer watermarked copies because it proves the report came from you and has not been altered.

    Time-limited links reduce exposure. A twenty-four hour window is standard. It gives the reviewer time to read the report and share it with their security team without leaving a permanent access path open. If the buyer needs more time, they can request a renewal, which creates another log entry.

    The audit log is what you show your own auditors. It should record the request, the NDA acceptance, the approval decision, the download timestamp, and the IP address. This turns a vague "we shared it with prospects" into a concrete list of every human who has touched the document.

    Set the SOC 2 to NDA-required

    In VendorLens, mark the SOC 2 PDF as NDA-required. It still appears on the trust page so buyers can see it exists, but downloading requires a request and an approved NDA. This single toggle is what separates a public brochure from a controlled document release.

    If you have multiple SOC 2 reports — for example, a Type 2 and a bridge letter — upload each as a separate document and set the visibility independently. Some teams make the bridge letter public while keeping the full Type 2 gated. This gives buyers confidence that the audit is current without exposing control-level detail.

    Configure NDA acceptance

    Use the built-in template, your own NDA text, or a DocuSign / SignNow flow. Decide whether requests auto-approve on signature or wait for manual review. Manual review is the right default for the first month so you can spot patterns before turning on automation.

    The NDA text should cover three things: confidentiality of the report, prohibition on redistribution, and permission to share internally within the requester's organization for the purpose of vendor evaluation. Keep it to one page if possible. Long NDAs slow down procurement teams and increase the chance a buyer abandons the review.

    Watermark the download

    VendorLens injects a diagonal watermark with the requester's name and email on every page of the PDF on download. Even if the buyer forwards the file, the source is traceable. This is not about distrusting your customers — it is about creating accountability that satisfies both your auditors and their auditors.

    Watermarking also protects against accidental leaks. A buyer may forward the PDF to a colleague without thinking. If that colleague then forwards it again, the original watermark is still there. In a worst-case scenario where the file appears on a public forum, you know exactly which organization leaked it.

    Keep the audit log

    Every NDA signature, request, approval, view and download is logged with a timestamp. This is what you show to your own auditors when they ask how you control distribution. The log should include the requester's name, email, company, IP address, document version, and action taken.

    Review the log weekly for the first quarter after launch. Look for repeat requesters, unusual domains, and failed requests. A failed request is often a sign that the buyer hit the expiry window or had a corporate firewall issue. Following up on these proactively improves your close rate and shows buyers you take security seriously.

    Quick checklist

    • SOC 2 PDF uploaded and marked NDA-required
    • NDA template configured (or DocuSign / SignNow connected)
    • Approval rules set (manual or auto-approve by domain)
    • Watermarking enabled
    • Token expiry set to 24h (or your policy)
    • Audit log reviewed and accessible to your team
    • End-to-end test completed after each SOC 2 refresh

    Set up your trust portal

    Free to start. Branded portal in an afternoon.

    Frequently asked questions

    Can we just email the SOC 2 report to trusted prospects?

    No. Email removes expiry, watermarking, and audit trail. Even trusted prospects change roles, and their inboxes are not your system to control.

    Do we need a custom NDA for every buyer?

    Not usually. A standard click-through NDA covers most mid-market deals. Enterprise buyers may send their own paper, which you can route through the same portal for logging.

    How long should the download link last?

    Twenty-four hours is the standard default. Extend to seventy-two hours for complex enterprise procurement if your policy allows it.

    What if a buyer shares the watermarked PDF internally?

    The watermark identifies the original requester, so the leak is traceable. Your NDA should explicitly permit internal sharing for evaluation purposes while prohibiting public redistribution.

    Does watermarking affect the report's validity?

    No. The watermark is overlayed at download time and does not alter the underlying audit content. It is a standard practice accepted by auditors and procurement teams.