How does NDA gating actually work for a document like the SOC 2?
When you mark a document as NDA-required, the document appears on your portal as listed but un-downloadable. A buyer clicks "Request access", fills in their name, work email and company, and is presented with your NDA — either the built-in template, your own pasted text, or a DocuSign / SignNow flow on paid tiers. Once they sign, the request lands in your dashboard. You approve in one click and they receive an email with a signed URL that expires in the configured window (default 24 hours). The signed NDA is stored against the request, the document download is watermarked with their identity on every page, and the entire chain — request, NDA, approval, download — is in the audit log against a stable request ID you can cite to your own auditor.
