State of M&A Data Rooms — Q2 2026 Read the report →
Customer Document Portal

Give customers one always-current set of your company documents.

Most vendors distribute their trust documents — annual reports, ISO and SOC certifications, pentest summaries, privacy documentation and DPAs, SLA documents, onboarding packs — one email at a time, re-sending the same certificate to every customer who asks and hoping nobody is holding a stale copy. Replace that "available on request" flow with one controlled surface. Publish the set once; update a file and every audience sees the current version. Give existing customers, prospects, and third parties each their own permissioned slice of the same corpus, gate the confidential layer behind an NDA, and read page-by-page analytics on every open. Free tier to start; Business $30/admin/month; Data Room $52/admin/month. Trusted by 6,800+ customers.

The customer's side is account-free: they open the link they were granted, verify their email, and read the current documents — nothing to install, nothing to pay. Viewers are always unlimited and free.

What is a customer document portal on Peony?

A customer document portal on Peony is a standing, permissioned surface that gives your customers, prospects, and partners one always-current set of your company documents — annual reports, ISO and SOC certifications, pentest summaries, privacy documentation and DPAs, SLA documents, and onboarding packs — instead of the "available on request" email flow where the same file is re-sent by hand every time someone asks. You publish the set once, and when a document renews you replace it in one place: the standing link a customer already has keeps working and now resolves to the current version, so no re-send is needed and no stale copy is left in circulation.

It is the outbound, multi-audience side of a data room. Rather than one public page that shows everyone the same thing, you cut a different slice of the same corpus for each audience — existing customers, active prospects, outside auditors — using granular per-file permissions on the Data Room plan ($52/admin/month), plus email authentication and allow/block-by-domain on the Business plan ($30/admin/month) and up. There is a free tier to start, and pricing is flat per admin seat — only admins are billed, and the customers viewing your documents are always unlimited and free.

The confidential layer stays gated: a full pentest report or detailed security architecture sits behind an Advanced NDA that produces a signed PDF from both parties with an audit trail before the file opens, while lighter documents take a Simple NDA or no gate at all. Every open is logged page by page, access can be revoked instantly or set to expire, and the same room also collects documents back from customers during onboarding. Peony serves 6,800+ customers, and this is how you turn a scattered email habit into one trust surface you control.

Why does the "available on request" email flow break down?

Because distributing your own trust documents by hand, one email at a time, fails on exactly the axes that matter most for security and compliance material. When a customer or prospect asks for your certifications and you "just send them over," you inherit five structural problems at once:

  • Stale copies proliferate. The moment a certificate is emailed it is frozen — when ISO or SOC renews, every customer holding last quarter's PDF now has an out-of-date document, and you have no way to pull it back.
  • No control over who sees what. An attachment goes to one inbox and can be forwarded anywhere; a prospect and an existing enterprise customer get the same file whether or not each should, because email has no per-recipient permission.
  • Confidential material leaves unguarded. A full pentest report sent as an attachment is out of your hands the instant it lands — no NDA gate, no watermark, no way to prove who read it or to revoke it later.
  • No record of distribution. Months later, when you need to show which customer received which version of a DPA, your sent-mail folder is not an audit trail — and it certainly is not one an auditor will accept.
  • It scales into pure repetition. The same certificate goes out dozens of times a year, each request handled manually by a person who has to find the current file, confirm the requester, and attach it — again and again.

A customer document portal fixes each of these by inverting the model: you maintain one always-current set, cut per-audience slices with real permissions, gate the confidential layer, and let every customer pull the current version from a link that never goes stale — while you keep the audit trail, the retention clock, and the ability to shut access off.

How does a customer document portal work on Peony?

Publish once, slice per audience, gate the confidential layer, and keep it current from one place. There is a free tier to start:

  1. 1. Load the always-current set. Upload your annual report, ISO and SOC certifications, pentest summary, DPA, privacy documentation, SLA, and onboarding pack into one place — the single source everyone will draw from.
  2. 2. Cut a slice per audience. Create a room per audience — existing customers, prospects, third-party auditors — over the same corpus, and use granular per-file permissions on the Data Room plan to decide who gets view, download, or no access to each file.
  3. 3. Authenticate by email and domain. Bind access to named addresses, and allow or block whole domains (Business, $30/admin/month, and up) — open a room to a customer's entire domain or shut a former partner's out in one move.
  4. 4. Gate the confidential layer. Put the full pentest report and detailed security docs behind an Advanced NDA (Data Room) — a signed, countersigned PDF with an audit trail before the file opens; lighter docs take a Simple NDA on Business.
  5. 5. Track and revoke. Read page-by-page analytics on every open (every tier), stamp released documents with the viewer's identity via dynamic watermarks (Data Room), and revoke instantly or by link expiry when a relationship changes.
  6. 6. Keep it current. When a certificate renews, replace the file once — every standing link resolves to the new version automatically, so nothing is re-sent and nothing goes stale.

What does it cost — and what do customers pay?

Customers pay nothing, ever, and never create an account — viewers are always unlimited and free, and only admin seats on your side are billed. You can start on the free tier ($0), which already carries page-by-page analytics and link expiry. Above that, two flat per-admin plans add the controls a real trust surface wants:

  • Business — $30/admin/month. Its plan subtitle is literally "Best for proposals, recruiting & client portals." Adds email authentication, allow/block by domain, Simple NDA acknowledgement, screenshot protection, download prevention, instant access revocation, and a year of analytics retention.
  • Data Room — $52/admin/month. Adds granular per-file permissions, dynamic watermarking, Advanced NDA with a signed PDF and countersigning, auto-indexing, and a custom domain — the plan for distributing confidential security material with per-audience control.

The pricing is flat per admin seat, not metered: there are no per-room, per-file, or per-viewer fees, so running separate slices for customers, prospects, and auditors costs nothing extra. One honest note for teams that need it: the default hosting is AWS US with Standard Contractual Clauses, and EU-region hosting is available on the Enterprise plan for organizations that require their trust documents to sit inside the EU. Full plan detail is on the pricing page.

How do you give each audience a different slice of one corpus?

You keep a single set of documents and control visibility with permissions, rather than copying files into separate portals that drift apart. On the Data Room plan ($52/admin/month), granular per-file permissions let you decide — file by file, person by person — who gets view, who gets download, and who gets no access at all. An existing customer under contract might see the SLA, the current certifications, and the pentest summary; a prospect mid-evaluation sees the certifications and a security whitepaper, with the detailed report held back until an NDA is signed; an outside auditor gets a wider slice with an expiry date attached.

Email authentication and allow/block-by-domain (Business, $30/admin/month, and up) keep each slice bound to the right people — you can open a room to a customer's entire domain in one move, or block a former partner's domain the moment the relationship ends. Because a file changes in one place and every permitted slice reflects it immediately, there is no three-copy maintenance problem: the version is always current everywhere, and who-sees-what is a permission setting rather than a duplicate file you have to remember to update.

What can a customer document portal on Peony do?

One always-current set

Update a file once and every audience sees the current version. Standing links survive certificate renewals — the link a customer bookmarked last year still resolves after you swap in this year's ISO or SOC document.

Granular per-file permissions (Data Room)

On the Data Room plan ($52/admin/month), set view, download, or no access per file per user. An existing customer, a prospect, and an auditor each get a different slice of the same corpus without maintaining separate copies.

Email authentication and domain control

Bind access to named email addresses, and allow or block whole domains (Business, $30/admin/month, and up) — open a room to a customer's entire domain, or shut a former partner's domain out in one move.

Gate the confidential layer with an NDA

Put pentest reports and detailed security docs behind an Advanced NDA with a signed, countersigned PDF and audit trail (Data Room). Lighter documents can sit behind a Simple NDA acknowledgement on Business.

Prove who pulled what

Page-by-page analytics on every tier, including free, plus a full audit trail on Data Room. You can show which customer opened which document and how far they read, instead of reconstructing it from sent mail.

Instant revoke and link expiry

Cut a viewer or a whole domain off the moment a relationship changes with remote access revocation (Business+), and set links to lapse on a schedule with link expiry — available on every tier.

Dynamic watermarking

Stamp every page a customer or prospect opens with their email and a timestamp (Data Room, $52/admin/month), so a released pentest report or SLA is attributable to the exact reader it went to.

Custom domain and branding

On the Data Room plan, the portal lives on your own domain with your logo and background, so customers reach your trust documents on a surface that looks like yours, not a third party's.

It collects documents back too

The same room that distributes your company documents also collects documents from customers during onboarding — security questionnaires, signed order forms, KYC packets — so intake and distribution share one surface.

How do you release a pentest report without losing control of it?

The confidential layer stays gated, attributed, tracked, and revocable — never simply attached to an email. This is the payoff of distributing security documents from a data room rather than a one-way page. Three things hold:

  • An NDA gates the file. The full pentest report and detailed architecture sit behind an Advanced NDA (Data Room, $52/admin/month) — the reader signs, both parties countersign, and Peony retains the signed PDF and audit trail before the document is reachable. Lighter material can take a Simple NDA acknowledgement on Business.
  • It opens under watermark and tracking. Dynamic watermarking burns the reader's email and a timestamp onto every page, download can be turned off entirely, and the page-by-page log shows exactly how far into the report that reader got.
  • You can take it back. Remote access revocation (Business+) cuts a viewer or a whole domain off instantly, and link expiry lapses access on a schedule — so a report released during an evaluation does not stay reachable after the evaluation ends.

That is control an email attachment can never return once it leaves your outbox: gated before it opens, attributable while it is read, and revocable the moment you need it back.

Can the same portal collect documents back from customers?

Yes — the surface that distributes your documents also collects documents from customers, so onboarding intake and trust distribution share one room instead of two tools. During onboarding you often need things back: a signed order form, a completed security questionnaire, a KYC packet, tax documentation. On Peony you send the same named audience a permissioned upload link into a folder you pre-build, and they submit those files directly — with no account and no charge to them, every upload logged with email, timestamp, and version.

So a single customer relationship runs in one place: they read your current certifications and SLA on the outbound side, and hand back the documents you need on the inbound side, all under the same permissions and the same audit trail. For the full inbound playbook — standing upload links, per-submitter logs, retention, and instant revoke — see collect documents from clients.

Who uses Peony as a customer document portal?

Information security officers

Distribute ISO 27001, SOC 2 Type II-ready attestations, and pentest summaries from one always-current set — with the full report behind an Advanced NDA and every open logged.

Customer success leads

Stop fielding one-off document requests over email. Give each customer a standing link into the current certifications, SLA, and onboarding pack, and see who has read what.

Compliance & privacy officers

Distribute DPAs and privacy documentation to customers with per-audience control and an audit trail, and share a standard DPA with SCCs directly through the portal.

Sales engineers

Answer a prospect's security review from a permissioned slice — certifications and whitepaper in the open, the detailed report released under NDA and watermark when they sign.

What should you be precise about before you commit?

The certification status is stated honestly. Peony is SOC 2 Type II-ready with the audit underway and ISO 27001-ready — we describe the current status rather than claiming a completed report that does not yet exist, which is the same standard the security reviewer on the other side is applying to you. Available for reviews today: a security whitepaper, completed questionnaires such as CAIQ and vendor-risk assessments, and a standard DPA with SCCs.

Data residency has a plan boundary. The default hosting is AWS in the US with Standard Contractual Clauses, and EU-region hosting is available on the Enterprise plan. If your customers require their trust documents to sit inside the EU, that is an Enterprise conversation — on Free, Business, and Data Room the underlying region is US-default with SCCs, and it is worth being straight about that with an EU customer rather than implying otherwise.

A trust center and a data room solve different jobs. If all you need is a public status badge that shows everyone the same page, a dedicated trust center is simpler. The moment you need per-audience control, NDA-gated confidential documents, an audit trail, and the ability to collect documents back, the data room is the surface that does it — the full comparison is in trust center vs data room.

"Peony is easily the best form factor for sharing client-facing material. It lets us stand out by embedding custom booking and website links into secure deck shares."
Y Combinator
RL

Robi Lin

Founder & CEO, Sepal AI (YC S24)

Frequently asked questions

I'm an information security officer at a software vendor and I send the same ISO 27001 certificate, pentest summary, and SOC report to every customer who asks. How does a customer document portal stop that repetition?

You publish one always-current set once and point every audience at it, so a certificate you distribute a hundred times a year lives in exactly one place. Build a room per audience — existing customers, active prospects, third-party auditors — grant access by email or by domain, and drop in your annual report, ISO 27001 certificate, SOC 2 Type II-ready attestation, pentest summary, DPA, and SLA. When a certificate renews you replace the file once and every viewer with a standing link now sees the current version; the link they bookmarked last year still resolves, so nothing breaks and no re-send is needed. The confidential layer — a full pentest report, detailed security architecture — sits behind an Advanced NDA that produces a signed PDF from both parties with an audit trail on the Data Room plan ($52/admin/month), while lighter documents can go behind a Simple NDA on Business ($30/admin/month) or straight to a named audience with no gate at all. Every open is logged page by page, on every tier, so you can prove which customer pulled which document and when instead of reconstructing it from your sent-mail folder. Peony serves 6,800+ customers, and this replaces the "certificates available on request" email flow with one surface you control.

What does a customer document portal cost, and do my customers have to pay or create an account to view the documents?

Customers pay nothing and never create an account — only admin seats on your side are billed, and viewers are always unlimited and free. You can start on the free tier ($0). Above that, two flat per-admin plans add the controls a real trust surface needs. Business at $30/admin/month — its own plan is subtitled "Best for proposals, recruiting & client portals" — adds email authentication, allow/block by domain, Simple NDA acknowledgement, screenshot protection, download prevention, instant access revocation, and a year of analytics retention. Data Room at $52/admin/month adds the pieces that matter when you distribute confidential security material: granular per-file permissions (view, download, or no access, set per file per user), dynamic watermarking that stamps every page with the viewer's identity, Advanced NDA with a signed PDF and countersigning, auto-indexing, and a custom domain so the portal lives on your own brand. Pricing is flat per admin seat with no per-room, per-file, or per-viewer fees, so running separate slices for customers, prospects, and auditors costs nothing extra. Link expiry is available on every tier, including free, and full plan detail is on the pricing page.

How is a Peony customer document portal different from a dedicated trust center product?

A trust center is a one-way marketing surface for your security posture; a data room is a permissioned document surface that also controls, gates, and audits access per recipient — and can collect documents back. The practical difference shows up in three places. First, control: a trust center typically shows the same page to everyone who requests access, whereas on Peony you set granular per-file permissions per user (Data Room, $52/admin/month), authenticate by email, and allow or block whole domains (Business+), so an existing enterprise customer, a prospect in evaluation, and an outside auditor each see a different slice of one corpus. Second, gating: confidential material — a full pentest report, detailed architecture — sits behind an Advanced NDA that produces a signed, countersigned PDF with an audit trail before the file opens, not just a checkbox. Third, direction: the same room that distributes your documents to customers also collects documents from them during onboarding, so you are not standing up a separate tool for intake. If you want the full comparison of where each model fits, we wrote it up in trust center vs data room. The honest read: if all you need is a public status badge, a trust center is simpler; if you need per-audience control, NDA gating, and an audit trail, the data room is the surface that does it.

How do I show existing customers, prospects, and outside auditors different documents without maintaining three separate copies of everything?

You keep one corpus and cut per-audience slices from it, rather than copying files into three places that then drift out of sync. Create a room per audience over the same underlying documents, and use granular per-file permissions on the Data Room plan ($52/admin/month) to decide, file by file and person by person, who gets view, who gets download, and who gets no access at all. An existing customer under contract might see the SLA, the current certifications, and the pentest summary; a prospect mid-evaluation sees the certifications and a security whitepaper but not the detailed report until an NDA is signed; an outside auditor gets a wider, time-boxed slice with an expiry date. Email authentication and allow/block-by-domain (Business+, $30/admin/month) keep each slice bound to the right people — you can open a room to an entire customer domain or shut a former partner's domain out in one move. Because a document changes in one place and every permitted slice reflects it immediately, there is no three-copy maintenance problem: the version is always current everywhere, and who-sees-what is a permission setting, not a duplicate file.

A prospect's security team wants our full pentest report, not just the summary. How do I release confidential documents without losing control of them?

You gate the confidential layer behind an Advanced NDA and release it under watermark with per-page tracking, so the report opens only after a signed agreement and every page carries the reader's identity. On the Data Room plan ($52/admin/month), put the summary and certifications in the open slice a prospect sees, and place the full pentest report and detailed security architecture behind an Advanced NDA — the reader signs, both parties countersign, and Peony retains the signed PDF and an audit trail before the file is reachable. When it opens, dynamic watermarking burns the viewer's email and a timestamp onto every page, download can be turned off entirely, and the page-by-page log shows exactly how far into the document that reader got. If the evaluation ends or the relationship changes, remote access revocation (Business+) cuts them off instantly and link expiry lapses access on a schedule you set. So the confidential document is never simply "sent" — it is gated, attributed, tracked, and revocable, which is the control an email attachment can never give you back once it leaves your outbox.

We're an EU company and our customers ask where their data is hosted. Can Peony keep the portal in an EU region?

Yes, EU-region hosting is available, on the Enterprise plan; the default for other tiers is AWS in the US with Standard Contractual Clauses in place. Peony is GDPR-compliant, and for a customer document portal that distributes DPAs and privacy documentation this is worth being precise about: on Free, Business ($30/admin/month), and Data Room ($52/admin/month), the underlying hosting is AWS US by default and cross-border transfers are covered by SCCs, while EU-region data residency is an Enterprise-plan option for organizations that require their trust documents to sit inside the EU. For reviews today you can share a security whitepaper, completed questionnaires such as CAIQ and vendor-risk assessments, and a standard DPA with SCCs directly through the portal. On the certification side, Peony is SOC 2 Type II-ready with the audit underway and ISO 27001-ready — we describe the current status honestly rather than claiming a completed report that does not yet exist, which is exactly the standard a security reviewer on the other side is applying to you.

Stand up your customer document portal in minutes.

Publish one always-current set, cut a slice per audience, and read page-by-page analytics on every open — off the "available on request" treadmill for good. Free tier to start; Business $30/admin/month; Data Room $52/admin/month. Every customer viewing your documents is free and never needs an account.

No credit card required