Sharing AI Artifacts (Live HTML) Securely
Upload an .html/.htm AI artifact from Claude or GPT to a Peony data room and share it live — JavaScript runs for the viewer, under screenshot protection, NDA, permissions, and analytics.
Last updated July 22, 2026
Sharing AI Artifacts (Live HTML) Securely
This page covers how to share an AI-generated HTML artifact — a dashboard, calculator, financial model, or mini-app built in Claude, ChatGPT, or any tool — through a Peony data room so it runs live for the recipient while staying under a security layer. Peony renders .html and .htm natively in the in-browser viewer with JavaScript executing, so the artifact works as intended instead of being flattened into a dead PDF or a screenshot.
Uploading an HTML artifact requires the Business plan ($30/admin/month) or above — HTML/HTM upload is gated to Business and up. The security controls that wrap the live render are screenshot protection, NDA gates, granular permissions, and analytics. Note the one exception below: the per-viewer dynamic watermark is not currently drawn over a live HTML preview the way it is over PDFs, images, and Office files.
If you have an interactive work product you built with an LLM and you need to send it to investors, buyers, lenders, or a board without losing control of who opens it, this is the workflow. For the commercial overview and use cases, see Share AI-generated documents securely.
What is an AI artifact, and does Peony render it live?
An AI artifact is a self-contained interactive file — usually a single .html file — that an LLM generates for you: a valuation dashboard, a pricing calculator, a scenario model, a one-page mini-app. It has its own HTML, CSS, and JavaScript, so it does real work in the browser rather than just displaying text.
Yes, Peony renders it live. When you upload an .html or .htm file, Peony displays it in its secure in-browser viewer with JavaScript executing, so the artifact runs exactly as it would in a normal browser — sliders move, inputs recalculate, charts redraw. It is not converted to a static image or a PDF first. This is the difference that matters: most data rooms convert HTML to a watermarked PDF before showing it, which kills interactivity and turns a working app into a flat page. Peony keeps the artifact live and wraps it in a control layer — screenshot protection, NDA gate, granular permissions, page-level analytics, and instant revoke. (The per-viewer dynamic watermark that Peony renders over PDFs, images, and Office files is not currently drawn over a live HTML render — see the security section below.) More than 6,800 customers share documents on Peony this way.
For the format reference, see Supported File Formats. For the deal-side context, see how to securely share a Claude artifact.
How do I upload and share a live HTML artifact?
Export the artifact as a single .html file, upload it to a data room, layer your security on the link, and send a per-viewer link. The artifact previews live in the browser; the viewer sees the running app inside Peony's viewer rather than a screenshot.
The key is to keep the artifact self-contained. If your LLM produced one HTML file with the CSS and JavaScript inline, it will render cleanly. Save Claude or GPT output as a .html file (most tools have a download or export option, or copy the code into a file ending in .html), then follow the numbered setup below.
Numbered setup: share an AI artifact in 6 steps
-
Export the artifact as one
.htmlfile. From Claude, ChatGPT, or your editor, save the interactive output as a single file ending in.html(or.htm). Inline CSS and JavaScript render most reliably, and a self-contained file with no external links behaves best in the viewer. -
Create or open a data room. From the data-room dashboard, use Create new data room (or open an existing one). Creating a data room requires the Business plan or above. Name it by the deliverable and audience, for example "Project Atlas — Lender Model".
-
Upload the
.htmlfile. Drag it into the room or use the upload control. Peony detects it as HTML and previews it live in the viewer — open it once yourself to confirm JavaScript runs and the artifact behaves as expected. HTML/HTM upload requires the Business plan ($30/admin/month) or above; on Free the upload is blocked with an upgrade prompt. -
Set granular permissions. Open the Permissions tab. Each group opens a two-step wizard — step 1 Visitors (who has access), step 2 Document permissions (which files each group can open). Create a separate group and gated link per viewer or per group so each one carries its own trail.
-
Layer security on the link. Turn on the protections your audience requires — screenshot protection, NDA gate, email verification, download prevention, and link expiry. See the next section for which tier unlocks each. (Dynamic watermarking applies to PDFs, images, and Office files, not to a live HTML render.)
-
Send the per-viewer link and watch the analytics. Share the gated link. From the Analytics tab you see who opened the artifact, for how long, and how often. Revoke any link the moment access should end.
How do I secure a shared AI artifact?
Layer Peony's controls on the link so the live artifact carries a real protection layer: screenshot protection, an NDA gate, granular permissions, download prevention, page-level analytics, and instant revoke. Each control sits at a specific plan tier — here is exactly where.
-
Screenshot protection (Business $30/admin/month and up; Screenshield on Data Room and up). This is the deterrence layer that does apply to a live HTML render — the viewer wraps the running artifact in screen-capture blocking. Desktop screen-capture blocking is included from Business up across major browsers on macOS and Windows. Screenshield, which blocks mobile screen capture on iOS, iPadOS, and Android, is on Data Room and up. See Screenshot Protection.
-
Dynamic watermark — not currently rendered over live HTML. Peony's per-viewer dynamic watermark (name, email, and timestamp) is drawn over PDF, image, Office and Google document, audio/video, CSV, and TXT previews on the Data Room plan ($52/admin/month) and up. It is not currently burned into a live HTML render — the HTML artifact runs in a sandboxed frame with no watermark overlay. For an interactive artifact, lean on screenshot protection, the NDA gate, and the access log for attribution; if you need a watermarked copy, export the artifact to PDF and upload that alongside the live version. See Dynamic Watermarks or the watermarks feature page.
-
NDA gate (Simple NDA on Business; Advanced NDA on Data Room). Require a viewer to accept an NDA before the artifact opens. Business includes a Simple NDA (view and acknowledge). Data Room adds the Advanced NDA — a digitally signed PDF with countersigning, stored for counsel. See NDA Gates or the NDA feature page.
-
Granular per-file permissions (Data Room and up). Control who sees the artifact versus the rest of the room, and create one gated link per viewer so each has isolated access. Available from the Data Room tier.
-
Download prevention (Business $30/admin/month and up). The Allow downloads toggle lets you stop viewers from downloading the raw
.html. On Free the toggle shows a Requires Business plan badge; download prevention unlocks on Business and above. -
Page-level analytics (included). The Analytics tab shows who opened the artifact, total time on it, and return visits — useful intelligence about which viewers are seriously engaged. See Page Analytics.
-
Instant revoke. Kill any shared link immediately and the holder loses access the next time they try to open the artifact. To revoke one individual viewer while everyone else keeps theirs — without disturbing anyone else — use granular per-viewer permissions on the Data Room plan ($52/admin/month) and up. See Revoke Access.
Because screenshot protection is a deterrence layer, treat it as identity-binding on the live render, not as a physical barrier against a determined leaker. The combination — signed NDA, blocked capture, download prevention, and a complete access log — is what makes a leak traceable and a deal-grade artifact defensible. When the artifact needs a per-viewer watermark on the record, share a watermarked PDF export in parallel.
Can I connect my own LLM and audit it?
Yes — on the Enterprise plan you can connect your own LLM (GPT, Claude, or Gemini) to the room, and every query the AI runs and every document it accesses is logged in the same access record as a human viewer. Connecting an external LLM is an Enterprise-only capability; lower tiers use Peony's self-contained native AI for document Q&A and extraction.
What makes this useful is the audit, not the connection. The moment an AI assistant reaches confidential documents, your access log normally goes silent on what the AI actually read — leaving an unattributed actor in the room — which is exactly the record counsel or a regulator will ask for. With Peony's Enterprise audit, the connected AI gets a row like every other viewer, so you can produce the complete list of documents it touched and the queries it ran during diligence. For day-to-day document questions on lower tiers, Peony's native AI Q&A answers from the room's own documents without any external connection.
What if my artifact won't render?
If a .html file doesn't render as expected, it is almost always because the artifact pulls assets from external sources, or because it tries to open a link in a new tab. Self-contained files with inline CSS and JavaScript render most reliably. There is no fixed size cap on the HTML preview, but very large single files load slowly — keep the file lean and self-contained.
A common gotcha: the artifact must not open links in a new tab. Peony does not modify uploaded HTML, so a target="_blank" link (or a script that opens a new window) breaks rendering inside the sandboxed viewer. Remove target="_blank" from any anchors before uploading.
Re-export the artifact as a single file with styles and scripts inline rather than linked, confirm the extension is .html or .htm, and open it once yourself in the viewer before sending. If it still won't preview, contact support — and as a fallback, any artifact can be shared as a PDF, though that flattens the interactivity.
Common Questions
My artifact links out to individual files in the room — which URL should I put in the HTML?
Do not paste the raw file-explorer URL from your browser address bar. That URL is not a controlled, analytics-tracked link. Instead, open the Permissions tab for the item you want to link to, create a brand-new link with the control settings you want, and use that link inside your HTML. Only a purpose-created link preserves the controlled viewing experience and per-link analytics. (Also remember the artifact must not open those links in a new tab — no target="_blank".)
Why doesn't the watermark show up on my HTML artifact?
The per-viewer dynamic watermark is drawn over PDF, image, Office, audio/video, CSV, and TXT previews, but not over a live HTML render — the artifact runs in a sandboxed frame with no watermark overlay. Screenshot protection, the NDA gate, permissions, and the access log all still apply. If you need a watermark on the record, export a PDF copy of the artifact and share it alongside the live version.
Do I need a paid plan just to upload an HTML artifact?
Yes. HTML/HTM upload requires the Business plan ($30/admin/month) or above. On Free the upload is blocked. Creating a data room also requires Business and above.
Related Articles
- Share AI-generated documents securely (Solution)
- Supported File Formats (Including Live HTML & AI Artifacts)
- Dynamic Watermarks: Setup and Limits
- Screenshot Protection: What's Blocked and What Isn't
- NDA Gates: Signed Before Access
- AI Q&A: Ask Questions About Your Documents
- How to Securely Share a Claude Artifact
- Which Data Rooms Support HTML Display
- HTML Viewer (Feature)
