How does NDA gating actually work for a document like the SOC 2?
When you mark a document as NDA-required, the document appears on your portal as listed but un-downloadable. A customer clicks "Request access", fills in their name, work email and company, and is presented with your NDA — either the built-in template, your own pasted text, or a DocuSign / SignNow flow on paid tiers. Once they sign, the request lands in your dashboard. You approve in one click and they receive an email with a signed URL that expires in the configured window (default 24 hours). The signed NDA is stored against the request, the document download is watermarked with their identity on every page, and the entire chain — request, NDA, approval, download — is in the audit log against a stable request ID you can cite to your own auditor.
Can I control how long customers keep access?
Yes, and at two levels. Per-request you set an access token expiry, which controls how long the signed URL is valid after approval. The default is 24 hours, but common configurations are 4 hours for highly sensitive reports, 7 days for procurement reviews, and 30 days for ongoing customer relationships. At the document level you can also set "request expiry" — the maximum age of any approved request before the customer has to re-request — which is the right control for documents that go stale (subprocessor list, current pen test). Expired access can be renewed without re-signing the NDA if the original NDA is still within its validity window.
Are downloaded PDFs traceable to the customer who downloaded them?
Yes. NDA-gated PDF downloads are watermarked on the fly by our PDF watermarking edge function. A diagonal stripe with the requester's name and email is injected on every page of the PDF before the signed URL is served. Two customers downloading the same SOC 2 report receive two distinctly traceable files — if a watermarked PDF surfaces somewhere it should not, you can trace it back to the specific approved request and the NDA the customer signed. Watermarking applies to NDA-gated PDFs by default; you can disable it per document where it is not appropriate (a public certificate, for example).
What does the audit log capture, and who can see it?
The audit log captures every meaningful event against every document and request: page views with timestamp and (where authenticated) requester identity, NDA signatures, access requests, approvals and rejections with reviewer identity, downloads with the version downloaded, access expiries, and access renewals. The log is visible only to authenticated members of your VendorLens workspace and is exportable as CSV for your own auditors or for your internal vendor security reviews. It is also the artefact your auditor will ask for when they review how you control distribution of confidential security reports under SOC 2 CC6.1 / ISO A.9.4.
How is this different from DocSend or a shared Drive link?
DocSend and Drive links solve a piece of the problem — they give you view-tracking and sometimes link expiry — but they do not enforce an NDA before viewing, do not watermark PDFs per requester, do not store a signed NDA against each access, and do not produce an audit artefact that maps cleanly to SOC 2 or ISO control language. They are also generic file-sharing tools, so customers do not associate the link with your security program. VendorLens is purpose-built for security documents: every primitive (NDA, watermark, expiry, renewal, audit) exists because a vendor security review asks for it, and the portal sits on your domain so the experience reads as part of your security program rather than an attachment in a third-party reader.
Can I share some documents publicly and gate others?
Yes, and this is the normal pattern. Visibility is set per document, so a security overview, SOC 3 report or ISO certificate can download directly from your portal while the SOC 2 Type 2 report or a full pen-test report shows a request-access button. Most sets sort into three tiers: public documents that need no request (SOC 3, ISO certificate, security overview, subprocessor list, pen-test summary letter), gated documents that need identity plus an NDA and your approval (SOC 2 Type 2, SOC 2 Type 1, bridge letters, full pen-test reports), and internal-only material that never appears on the portal at all (raw control evidence, unredacted findings, audit working papers, customer-specific assessments).
Why do teams gate the full SOC 2 report instead of publishing it?
A SOC 2 Type 2 report includes the auditor's opinion alongside a description of your system, your control activities, the tests performed and any exceptions noted — detail many teams treat as commercially and operationally sensitive. Gating it behind an NDA and an approval step gives you an identity, an agreement and a record attached to every copy, which an emailed PDF cannot provide: no expiry, no watermark identifying the recipient, and no record of who opened or forwarded it. This is common practice rather than a rule — your own legal and security teams decide what to publish, gate or keep internal.
How do I decide what to make public, what to gate and what to keep internal only?
A useful starting point: publish anything written for external distribution (SOC 3 report, ISO certificate, security overview, subprocessor list, pen-test summary letter) since that answers most early questions and cuts down the requests you review. Gate anything with operational detail a competitor or a bad actor could misuse (SOC 2 Type 2 and Type 1 reports, bridge letters, full pen-test reports, detailed architecture documents) behind identity, an NDA and your approval. Keep working materials off the portal entirely — raw control evidence, unredacted findings, remediation tickets and customer-specific assessments belong internal or shared case by case. This reflects common practice among B2B software teams, not a standard or a legal requirement, and it is not legal advice.
What does VendorLens not do?
It does not perform a SOC 2 audit — you bring the report your auditor issued. It does not certify, accredit or validate your company or its controls. It does not collect control evidence or run continuous compliance monitoring, and it is not a GRC platform: no risk register, policy management or control frameworks. It also does not answer security questionnaires for you, with or without AI. VendorLens publishes and controls access to documents you already have.
What happens to old access when a new SOC 2 report is issued?
Replace the document in your library rather than adding a new one. New requests and downloads receive the current report, and the access history for previous versions stays intact, so you can still see who received the earlier report and when. If your next audit period is still open, add the bridge letter alongside the report it covers under the same gating.