State of M&A Data Rooms — Q2 2026 Read the report →

Customer Document Portal: Share Documents With Customers (2026)

Co-founder and CEO at Peony. I built the data room platform with a background in document security, file systems, and AI. Founded Peony in 2021 in San Francisco.

Customer Document Portal: Share Documents With Customers (2026)

I'm Deqian Jia, co-founder of Peony, and I spend my days looking at how confidential documents move between businesses that need control on both ends. There is one flow I see B2B software vendors get wrong more than any other: not the high-stakes deal share, but the boring, constant, whole-customer-base distribution of the same document set — the annual report, the ISO and SOC certificates, the DPA, the SLA. Almost everyone still does it by hand, and it quietly breaks the moment the customer count climbs. This post is about the portal that fixes it.

Quick answer. A customer document portal is a single, access-controlled home for the standing documents a software vendor gives its customers — annual reports, ISO/SOC certifications, privacy documentation and DPAs, SLAs — plus a standing set for prospects and third parties. Most vendors still run this as an "available on request" page with account managers emailing PDFs on demand, which freezes each copy the moment it is sent and keeps no record of who received what. Built in a Peony data room (free, $0), the portal keeps one always-current document set behind per-audience permissions, gates the sensitive tail behind an NDA, and logs who pulled which version — priced per admin, recipients free. This is trust-center control without the trust-center project.

What is a customer document portal?

A customer document portal is a single, access-controlled place where a B2B vendor publishes the documents its customers repeatedly need — and controls who sees each one, keeps them current, and records who pulled what. Instead of a static "available on request" page plus a folder of PDFs an account manager forwards on demand, it is one corpus with per-audience permissions layered on top.

The document set is remarkably consistent across software vendors. It is the yearly or annual report; the ISO 27001, ISAE 3402, and SOC certifications; the privacy documentation and the DPA a customer's legal team needs before signing; the SLA that defines uptime and support commitments; and, for the more security-conscious buyer, a summary of the latest penetration test. Around that core sits a wider standing set — a marketing-safe overview for prospects, an onboarding pack for new customers, and specific artifacts a third-party auditor or a tender process asks for.

The reason to house this in a data room rather than a public web page is that these documents split cleanly into two piles. The certificate itself is not secret; the detailed architecture diagram and the full pentest report often are. A portal lets you hand out the non-confidential pile freely while gating the sensitive pile behind an NDA and per-recipient access — from the same corpus, without maintaining two systems. If you are still deciding whether you need a data room or a lighter client portal at all, that trade-off is worked through in data room vs client portal; this post assumes you have chosen the room and want to run your customer document set inside it.

Why does "available on request" break at scale?

"Available on request" breaks because it is a manual process bolted onto a document set that keeps changing and an audience that keeps growing. It works for your first twenty customers and quietly becomes a liability at two hundred, for three specific reasons.

The account-manager email flow does not scale. The industry-standard pattern is a page that says certificates are "available on request," behind which a customer emails their account manager, who digs out the current PDF and attaches it. Every one of those emails is a person doing manual work, and every attachment is frozen the instant it is sent. Multiply one certificate request across a growing book of business and a sales team already stretched thin, and the "request" quietly becomes a bottleneck that slows security reviews inside your own sales cycle.

Renewal cycles force a redistribution to everyone at once. ISO 27001, ISAE 3402, and SOC reports are reissued on a cycle. The day a fresh certificate lands, every copy you have ever emailed is out of date, sitting in inboxes you cannot reach. Your choices are bad: either customers keep qualifying you on a superseded certificate, or someone spends a day re-emailing the whole base, then repeats it at the next renewal. A portal inverts this — you replace the file once and every holder of the link opens the current version next time.

Email attachments carry zero audit trail. When a customer audit or a tender asks you to prove that a specific customer received your current SLA or DPA, "we emailed it at some point" is not evidence. An attachment records nothing: not whether it was opened, not whether it was the current version, not which customer is still relying on last year's document. For a document set whose whole purpose is to evidence your compliance to others, the absence of a delivery record is the sharpest failure of all.

What belongs in a customer document portal?

The core is the compliance and trust pack every customer's security and legal teams ask for, plus a standing set for prospects, onboarding, and third parties. The table below maps each document type to its natural audience and the access control that fits it.

Document typePrimary audienceSuggested control
Annual / yearly reportCustomers, prospectsView or download, standing link
ISO 27001 / ISAE 3402 / SOC certificateCustomers, third-party auditorsView, email-authenticated link
Penetration test summarySecurity-conscious customers, auditorsView-only, watermarked, behind an Advanced NDA
Privacy documentation / DPACustomer legal teamsDownload, email-authenticated link
SLA / support commitmentsCustomersDownload, standing link
Onboarding packNew customersDownload, per-customer link with expiry
Prospect overview setProspectsView-only, marketing-safe subset

Two principles drive the control column. First, match the gate to the sensitivity, not the document's importance — a certificate is important but not confidential, so it needs an authenticated link, not an NDA; a full pentest report is confidential, so it earns the NDA and the watermark. Second, keep the audiences separate so a prospect never stumbles onto the DPA and an auditor only ever sees the slice their engagement requires. The next two sections are about building exactly that.

How do you build a customer document portal in a data room?

You build it by laying out one folder architecture for the whole corpus, then setting per-file permissions and per-audience groups on top — so a single room serves every audience under different rules. The mechanics are the same ones a data room uses for due diligence, pointed at a standing document set instead of a one-off deal.

Folder architecture. Structure the room by document class, not by customer: a Compliance folder (certificates, DPA, privacy docs), an Agreements folder (SLA, standard terms), a Security folder (pentest summary, whitepaper), an Onboarding folder, and a Prospect Overview folder. One clean tree, reused for everyone — you never rebuild it per customer.

Granular per-file permissions. Inside the room, granular access control gives every folder and every individual file a four-position slider: No access, View, Download, or Upload. No access means the file is absent from that audience's view of the room, not greyed out, so a file name alone can never leak. This is how the Security folder's pentest report is invisible to prospects while fully visible to a vetted auditor, from the same room.

Email authentication and allow/block by domain. Rather than "anyone with the link," each audience's link can require a verified email before entry, and you can allow or block by domain — so a link meant for @customer.com cannot be used by anyone outside it. This turns every page view into a named event instead of an anonymous one.

Standing links vs per-customer links. Use a standing link for documents that are the same for everyone and rarely change — the current SLA, the published certificate. Use a per-customer link, often with an expiry date, for anything scoped to one account, like a tailored onboarding pack. The standing link is what makes the certificate "always current"; the per-customer link is what keeps onboarding tidy and time-boxed.

What stays gated behind an Advanced NDA. The confidential tail — a full penetration test report, detailed architecture, anything a competitor could exploit — sits behind an Advanced NDA that produces a signed PDF from both parties before the first page renders, with the viewer's identity watermarked across every page. The customer gets what they need to complete their review; you get a traceable, signed record that they agreed to keep it confidential.

How do you serve customers, prospects, and third parties from one place?

You serve them from one corpus by creating a permission group per audience, each seeing a different slice of the same room under its own rules. This is the multi-audience pattern, and it is the single strongest reason to build the portal in a data room rather than three separate shared folders.

In practice you create a group — "Customers," "Prospects," "Third-Party Auditors" — and each group carries its own permission table and its own security stack. The granular controls let the slices diverge sharply from shared files:

  • Prospects get a View-only group scoped to the marketing overview and the published certificate — enough to build confidence in a sales cycle, nothing confidential, no downloads.
  • Customers get the full compliance pack with downloads enabled on the SLA, DPA, and certificates, plus an email-authenticated link so every access is attributed.
  • Third-party auditors get a tightly scoped, watermarked, NDA-gated group that exposes exactly the pentest summary or control evidence their engagement requires and nothing else.

Because each group has its own audit trail and its own on/off toggle, you can revoke one audience — an auditor whose engagement ended, a prospect who went cold — without disturbing the others. One corpus, one folder tree, three permission slices, three audit trails. That is the shape a flat drive or an "available on request" page can never produce.

If your customer-facing polish also needs to carry your logo and colors, the same room supports branded portals and a custom domain, so the portal lives at your own address. Consultants delivering to a handful of clients have a lighter version of this problem, worked through in the branded client portal guide; this post stays on the vendor-to-whole-base case.

What does a customer document portal cost?

With Peony it runs from $0 to $52 per admin per month, and the model that matters is per-admin billing with every recipient free — so the cost never scales with the size of your customer base. Here is how the tiers map to the portal job.

  • Free ($0) covers the essentials to try the pattern: password protection, link expiration, email capture, page-by-page analytics, and real-time visit notifications are on every tier, including Free.
  • Business ($30/admin/month) is the lighter portal. Its subtitle is literally "Best for proposals, recruiting & client portals," and it adds email-authenticated links, allow/block visitor lists, remote access revocation, a Simple NDA (acknowledge-only), screenshot protection, custom logo and background, and folders with bulk upload.
  • Data Room ($52/admin/month) is the tier most portals want. It adds the controls that make the multi-audience compliance portal work: dynamic watermarking, Advanced NDA (signed PDF from both parties with an audit trail), granular per-file permissions (view/download/no-access per file per user), a full audit trail, domain-restricted access, and a custom domain and branding.
  • Enterprise (custom) is where SAML SSO, a custom DPA and SLA, BYOK, and custom data residency — including EU-region hosting — live.

One honest note for EU-default buyers, because it is the objection I would rather answer up front than have you discover later. Peony defaults to AWS hosting in the US with Standard Contractual Clauses, and EU-region hosting is on the Enterprise plan rather than the default. If EU data residency is a hard requirement for this document set, that is a fair reason to prefer an EU-hosted vendor, or to talk to us about Enterprise. On our own posture, Peony is SOC 2 Type II-ready with the audit underway and ISO 27001-ready with that audit underway; a security whitepaper, completed questionnaires such as CAIQ, and a standard DPA with SCCs are available for review today. That transparency is part of why 6,800+ customers are comfortable running controlled document sharing on Peony.

Two boundaries worth stating plainly. If what you actually want is a public, badge-wall trust center as a standing marketing surface, a dedicated trust-center platform will out-polish a data room at that one job — the trust center vs data room comparison walks through when each wins — because the portal wins on the gated tail, the per-audience slicing, and the audit trail, not on public presentation. And for the specific step-by-step of packaging SOC 2 and ISO 27001 for a security review, how to share your SOC 2 report and ISO 27001 certificate with customers covers the open-versus-gated split, renewals, and the NDA layer. Match the tool to the job.

For adjacent flows: sending customer agreements out for signature at volume is covered in e-sign customer agreements at scale, and the always-current-pack discipline applied to a regulated wholesale context is worked through in the GDP compliance pack guide.

Frequently Asked Questions

What is a customer document portal, and how is it different from a public download page?

A customer document portal is a single, access-controlled home for the standing document set a software vendor distributes to its customers — annual reports, ISO and SOC certifications, privacy documentation and DPAs, and SLA documents — instead of scattering those files across email attachments and an "available on request" page. The difference from a public download page is control and proof: a public page is one-way and anonymous, while a portal built in a data room lets you set who sees which document, gate the sensitive tail behind an NDA, and keep an audit trail of who pulled which version and when. You update the file once and every holder of the link sees the current version, so a reissued certificate never leaves a stale PDF sitting in a customer's inbox.

How do I share our ISO 27001 or SOC 2 certificate with customers without emailing it every time?

Put the certificate behind one link in your portal rather than attaching it to every security review. When the certificate is reissued after your next audit cycle, you swap the file behind the link once and every customer opens the current one — there is no round of re-emailing hundreds of accounts. For the non-confidential documents you can hand out a standing link; for the sensitive tail like a full pentest summary, gate it behind an Advanced NDA so the customer signs a confidentiality agreement before the first page. Peony logs who opened which version and when, which is the delivery record an email attachment cannot give you. For the vendor-by-vendor question of who actually holds which certification, see our SOC 2 and ISO 27001 matrix.

How much does a customer document portal cost with Peony?

Peony is free to start at $0, the Business plan is $30 per admin per month, and the Data Room plan is $52 per admin per month on annual billing. The pricing detail that matters for a document portal is per-admin billing with recipients always free: you pay for your internal admin seats, and every customer, prospect, or third party you share documents with is free — your bill never scales with your audience. The $52 Data Room tier is the one most portals want, because that is where granular per-file permissions, dynamic watermarking, Advanced NDA gating, and a custom domain live. The Business plan at $30 — whose subtitle is literally "Best for proposals, recruiting & client portals" — covers the lighter case with email-authenticated links, allow/block lists, and a Simple NDA. It is why 6,800+ customers run controlled sharing on Peony without a per-guest charge.

Can I give customers, prospects, and third parties different access to the same documents?

Yes, and that is the main reason to build the portal in a data room rather than a flat shared drive. One room holds the whole corpus, and you create a group per audience — customers, prospects, third-party auditors — each with its own permission table set to No access, View, or Download on any individual file, with Upload additionally available at folder level. Prospects might see only the marketing-safe overview set, customers get the full compliance pack with downloads on, and a third-party auditor gets a watermarked, NDA-gated slice of exactly the pentest summary they need. Each group also carries its own NDA, its own watermark, and its own audit trail, so you can arm, share, or revoke one audience without touching the others.

We need EU data residency for our compliance documents. Does Peony host in the EU by default?

No, and I would rather tell you that plainly than lose your trust later. Peony defaults to AWS hosting in the US with Standard Contractual Clauses in place, and EU-region hosting is available on the Enterprise plan rather than by default. If EU data residency is a hard requirement for your document portal, that is a legitimate reason to choose an EU-hosted vendor for this job, or to talk to us about Enterprise. On Peony's own security posture: we are SOC 2 Type II-ready with the audit underway and ISO 27001-ready with that audit underway, and a security whitepaper, completed questionnaires such as CAIQ, and a standard DPA with SCCs are available for your review today.