We use cookies and similar technologies to improve your experience and analyse usage. By continuing you agree to our Privacy Policy.

    VendorLens

    A security document portal for NDA-gated sharing, with watermarks, expiry and audit logs

    You need to share sensitive security documents with buyers — but email, Drive links and DocSend leave you with no NDA on file, no expiry, no watermark and no audit trail of who actually opened the file.

    VendorLens is purpose-built for secure security-document sharing. Every document has its own visibility tier, NDA workflow, expiry window and watermarking rule, and every view, request, approval and download is captured in an exportable audit log.

    A security document portal for NDA-gated sharing, with watermarks, expiry and audit logs — VendorLens trust portal screenshot

    Use cases

    SOC 2 report sharing

    Gate the full Type 2 report behind an NDA. Each download is watermarked with the requester's name and email and the signed URL expires in hours, not forever.

    ISO 27001 certificate sharing

    Keep the public certificate downloadable with one click and gate the full Statement of Applicability behind NDA. Replace the file when the certificate renews — the link stays the same.

    DPA sharing

    Publish your DPA as a public, frictionless download so procurement can attach it to the MSA without opening a support ticket. Track which buyers pulled which version.

    Pen test summary sharing

    Share the redacted executive summary publicly or under NDA, keep the full technical report internal-only, and prove controlled distribution with the audit log.

    Policy sharing

    Security, BCP, incident response, acceptable use, vendor management — one place buyers can self-serve every policy, with effective and last-reviewed dates surfaced inline.

    How it works

    1

    Upload the document and pick a tier

    Public, NDA-required or internal-only. Tier is per document and you can change it any time without breaking existing links.

    2

    Configure NDA, expiry and watermarking

    Use the built-in NDA template, paste your own, or wire up DocuSign / SignNow on paid tiers. Default access window is 24 hours; configurable per request.

    3

    Approve requests from one queue

    NDA requests land in the dashboard with company, email and signed NDA attached. Approve in one click or auto-approve once a countersignature arrives.

    4

    See every access in the audit log

    Every view, NDA signature, approval, download, expiry and renewal is logged with a timestamp and exportable as CSV for your own auditors.

    Manual process vs VendorLens

    TopicManual processWith VendorLens
    NDA on fileSometimes — buried in emailStored against every gated request
    Access expiryNever — the PDF lives on their diskTime-limited signed URLs, default 24h
    WatermarkingManual PDF editing per buyerAutomatic, per-requester, on every page
    Audit trailNonePer-document, per-requester, exportable
    Revoking accessImpossible after the file is sentOne click invalidates active URLs
    Updating a documentRe-email everyone, hope they replace itReplace the file — the link stays the same

    Frequently asked

    How does NDA gating actually work for a document like the SOC 2?

    When you mark a document as NDA-required, the document appears on your portal as listed but un-downloadable. A buyer clicks "Request access", fills in their name, work email and company, and is presented with your NDA — either the built-in template, your own pasted text, or a DocuSign / SignNow flow on paid tiers. Once they sign, the request lands in your dashboard. You approve in one click and they receive an email with a signed URL that expires in the configured window (default 24 hours). The signed NDA is stored against the request, the document download is watermarked with their identity on every page, and the entire chain — request, NDA, approval, download — is in the audit log against a stable request ID you can cite to your own auditor.

    Can I control how long buyers keep access?

    Yes, and at two levels. Per-request you set an access token expiry, which controls how long the signed URL is valid after approval. The default is 24 hours, but common configurations are 4 hours for highly sensitive reports, 7 days for procurement reviews, and 30 days for ongoing customer relationships. At the document level you can also set "request expiry" — the maximum age of any approved request before the buyer has to re-request — which is the right control for documents that go stale (subprocessor list, current pen test). Expired access can be renewed without re-signing the NDA if the original NDA is still within its validity window.

    Are downloaded PDFs traceable to the buyer who downloaded them?

    Yes. NDA-gated PDF downloads are watermarked on the fly by our PDF watermarking edge function. A diagonal stripe with the requester's name and email is injected on every page of the PDF before the signed URL is served. Two buyers downloading the same SOC 2 report receive two distinctly traceable files — if a watermarked PDF surfaces somewhere it should not, you can trace it back to the specific approved request and the NDA the buyer signed. Watermarking applies to NDA-gated PDFs by default; you can disable it per document where it is not appropriate (a public certificate, for example).

    What does the audit log capture, and who can see it?

    The audit log captures every meaningful event against every document and request: page views with timestamp and (where authenticated) requester identity, NDA signatures, access requests, approvals and rejections with reviewer identity, downloads with the version downloaded, access expiries, and access renewals. The log is visible only to authenticated members of your VendorLens workspace and is exportable as CSV for your own auditors or for your internal vendor security reviews. It is also the artefact your auditor will ask for when they review how you control distribution of confidential security reports under SOC 2 CC6.1 / ISO A.9.4.

    How is this different from DocSend or a shared Drive link?

    DocSend and Drive links solve a piece of the problem — they give you view-tracking and sometimes link expiry — but they do not enforce an NDA before viewing, do not watermark PDFs per requester, do not store a signed NDA against each access, and do not produce an audit artefact that maps cleanly to SOC 2 or ISO control language. They are also generic file-sharing tools, so buyers do not associate the link with your security program. VendorLens is purpose-built for security documents: every primitive (NDA, watermark, expiry, renewal, audit) exists because a vendor security review asks for it, and the portal sits on your domain so the experience reads as part of your security program rather than an attachment in a third-party reader.

    Ready to publish your trust center?

    Start free, or talk to us about the design partner program.