The best way to share confidential documents (it depends what's in them)
The best way to share confidential documents is the one where you can control who opens the file and take that access away later. For most people that means a restricted link, not an email attachment. An attachment is a copy. Once it's sent, it sits in their inbox and goes wherever they forward it, and you have no say in any of that.
The catch is that "confidential" covers a lot of ground. A salary letter, a signed NDA, a set of management accounts and an acquisition data pack all need different handling, and treating them all the same is how people end up either over-engineering a simple send or under-protecting something that really matters.
Why email attachments are the weak spot
I'm not going to pretend I've never attached something sensitive to an email. Years of sending decks, reports and pricing in growth roles means I've done it more times than I could count, usually because I was in a hurry and it was the path of least resistance.
The problem with attachments isn't really that email is insecure in transit. Most business email is encrypted between servers these days. The problem is everything that happens after it arrives. You can't unsend it. You can't see whether it was opened. If the recipient forwards it to a colleague, or their account gets compromised a year later, your document goes with it.
For low-stakes files that's fine. For anything you'd be uncomfortable seeing in the wrong inbox, it's the wrong tool. I've written more about the specific case of sending signed documents via email if that's what brought you here.
Match the method to what's in the file
The way I think about it is to ask two questions. What happens if this ends up with the wrong person? And do I need it back?
Personal or HR documents: password-protected PDF
Say you're sending a contractor their signed agreement with bank details on it. It's sensitive, but it's going to one person who needs to keep it. A password-protected PDF is fine here. Acrobat and most PDF tools can encrypt a file so it won't open without the password.
The part people skip is sending the password separately. If the password is in the same email as the PDF, you've locked the door and taped the key to it. Text it or read it out on a call.
The limitation is that once they've opened it, they have a copy forever. That's fine for their own contract. It's not fine for your pricing model.
Internal or client files: restricted cloud links
For documents shared with a client or team, Google Drive, OneDrive and Dropbox all let you share with specific named people rather than "anyone with the link". That one setting does a lot of work. Someone who gets forwarded the link can't open it without signing in as an approved person.
On paid Google Workspace accounts you can also set an access expiry date for specific people, which is useful for contractors and short projects. Microsoft 365 has similar controls. The catch is that these tools are built for storing and collaborating on files, not for sending them to outsiders, so the recipient often hits a sign-in wall, and you get very little visibility into whether they actually read it.
Proposals, reports and decks: expiring, trackable links
This is the category most people I talk to are dealing with. A proposal with pricing, a board report, a pitch deck, a due diligence summary. You want the recipient to read it properly, you don't want it living forever in their downloads, and you'd quite like to know if they got past page two.
A document-sharing tool fits here. DocSend is the best known, and on its higher plans it adds things like dynamic watermarking and NDA gates before viewing, which matters if you're a founder sending a deck to investors you don't know yet.
This is also what I built LiveDocument for, from a slightly different angle. You upload a PDF or image, share it as one link, and can set that link to expire or revoke it whenever you want. You can also record a short video walkthrough over the document so the reader isn't guessing at what you meant, and you see page-level analytics on what they read. It doesn't do watermarking or NDA gating, and it isn't a data room, so if either of those is a requirement, DocSend or a proper VDR is the better fit. Where it earns its place is when you need control over access and you also need the reader to understand what you've sent.
Deals and anything legally sensitive: a virtual data room
If you're selling a business, raising a large round or handling a legal dispute, use a proper virtual data room. They're built for hundreds of documents shared with several parties, with permissions per folder and a record of who viewed what. They're also expensive and overkill for anything smaller. If you're asking whether you need one, you probably don't yet. The moment lawyers on both sides are involved, you will.
A few habits that matter more than the tool
Whichever method you pick, most leaks come from people rather than software. Check the recipient address twice before you send anything sensitive, because autocomplete is how most mis-sends happen. Share the least you need to: if they only need page four of the accounts, send page four. And when a project ends, go back and revoke the links. Nobody does this, and it's the easiest win on the list.
If you work in a regulated area, your organisation's own policies come first. For UK businesses handling personal data, the ICO's guidance on security is worth a read, and it's more readable than you'd expect.
FAQ
What is the safest way to send confidential documents?
The safest way to send confidential documents is through a restricted link where only named people can open the file and you can revoke access later. For the highest-stakes material, like M&A documents, a virtual data room adds audit trails and granular permissions. Email attachments are the least safe option because you lose control of the copy the moment you hit send.
Is it safe to email a password-protected PDF?
It's reasonably safe if you send the password through a different channel, like a text or a phone call. The encryption is only as good as the password and how you share it. Remember that once the recipient opens it, they have an unprotected copy you can't take back.
How do I stop someone forwarding a confidential document?
You can't completely stop someone forwarding a file once they've downloaded it, which is why links beat attachments. With a restricted or trackable link, a forwarded copy either won't open for the new person or you can revoke the link entirely. Some tools also add watermarks to discourage sharing screenshots.
If proposals and reports are most of what you're sending, the share a PDF as a link page covers how LiveDocument handles it, or you can see it at livedocument.com.
About the Author
Cameron JamesCameron is the founder of LiveDocument. He writes about sharing documents, PDFs, decks and contracts, and why pairing a video walkthrough with a document beats sending it cold.