Sharing a Document With a Contractor Without Losing Control
By Simon Themiot - freelance cybersecurity consultant. Published October 7, 2026.
Summary
- A file sent as an attachment or through a download link escapes all control: it can be copied, kept and passed on without leaving a trace.
- The realistic approach never hands over the original: a view-only, watermarked, time-limited copy, with proof of the hand-over and a viewing journal.
- With the Team plan, PrivCloud adds an invisible mark that names the copy a leaked capture comes from, and evidence verifiable offline for three years.
Table of contents
1. A file sent never comes back
Audits, expert assignments, subcontracting: every day, companies entrust documents to outside people for a limited time. Contracts, plans, financial data, staff files. Once the file is e-mailed or downloaded from a link, it lives its own life: copies on a personal computer, backups, forwards. The end of the assignment makes nothing disappear.
And the day the document turns up where it should not, the question 'who?' often has no answer: several contractors had received exactly the same file.
2. What the usual solutions leave open
- Encrypted attachment: it protects the transport, not what follows. The recipient then holds the file in clear.
- Sharing link with an expiry: the expiry cuts access to the link, not to copies already downloaded.
- Viewing space with downloads disabled: useful, but every guest often sees the same rendering, and the record of what they viewed depends on the vendor's internal logs.
- PDF with print or copy restrictions: these depend on the goodwill of the PDF reader and are easily bypassed.
The limit nobody lifts
No solution prevents a photo of the screen. The realistic goal is twofold: never hand over the original, and make any leak attributable.
3. The view-only copy
With the PrivCloud Team plan, an administrator picks a document in a team folder and shares it with one of the team's two contractors. Their browser renders each page as an image, adds a watermark with the company and contractor names, then encrypts the pages for that contractor alone.
- The contractor never receives the original file, nor the team key.
- The server only sees encrypted pages.
- Access is limited in time, 90 days at most, and revocable at any moment.
- The contractor sees neither the folders, nor the members, nor the other files of the team.
4. Proving the hand-over and every viewing
- Passkey approval. The administrator approves the hand-over with their passkey (fingerprint, face or device PIN). The signature covers the exact hash of every page: the server cannot publish anything other than what was approved.
- Qualified timestamp. An independent timestamping authority dates the hand-over. It only receives a hash, never the document.
- Chained journal. Every opening and every page displayed is recorded before display. Each event contains the hash of the previous one, and the chain is timestamped every hour: an edited, deleted or inserted event shows.
- Contractor informed. Before any viewing, they are told that pages are marked and that every viewing is recorded.
5. Tracing the source of a leak
The visible watermark deters, but it can be cropped. Each copy therefore also carries an invisible mark of its own. If a screenshot circulates, even reduced, cropped, recompressed as JPEG or pasted into a PDF, the administrator drops it into the team's analysis tool. Their browser finds the original copy, the contractor and the hand-over date, without sending the image to anyone.
What the mark does not do
A photo of the screen remains possible, and a filter that turns the whole background white can remove the invisible mark. The visible watermark then remains. The mark holds no personal data: only the team can link it to a copy, and the key that produces it cannot be read by the server.
6. What an auditor checks alone
For each hand-over, the team downloads a PDF certificate and an evidence bundle. The bundle contains a verification script: with Python 3 and OpenSSL, an auditor redoes every check offline, without an account or access to the platform. They verify the approved document, the administrator's passkey, the certified date, the hash of the original file and the continuity of the journal.
7. GDPR: how long to keep this evidence
The register and journal contain personal data: the contractor's address and the viewing dates. They are kept three years, long enough to discover a leak and act, then erased automatically. During that period, they remain available even if the team is deleted: GDPR Article 17(3)(e) sets the right to erasure aside when the data serves the defence of legal claims.
The platform administrator returns them on written request, from a vault that only opens with their passkey and where every extraction is recorded in the journal. The title and content of the document never appear there. Details are in the Data Processing Agreement.
8. FAQ
Can the contractor take a screenshot?
Yes, as on any screen. The capture carries the watermark with their name and the invisible mark of their copy: it names where it comes from.
Can PrivCloud read the document entrusted?
No. Rendering, watermarking and encryption happen in the administrator's browser. The server stores pages encrypted for the contractor alone.
What happens when the assignment ends?
Access stops on the set date, or as soon as it is revoked. The copies disappear, the register and journal remain three years.
Does the contractor need an account?
Yes, a free account with two-factor authentication and end-to-end encryption. That is what guarantees that only they open their copies.
Related articles
Keep control of the documents you entrust
View-only copies for contractors, the timestamped register, the invisible mark and the evidence vault are included in the PrivCloud Team plan, with two contractor seats per team.
This article is provided for informational purposes. Consult your DPO or legal department for compliance adapted to your organisation. Last updated: October 7, 2026.