State of M&A Data Rooms — Q2 2026 Read the report →
Per-Viewer Watermarking

Send a PDF stamped with each viewer's email.

A static “CONFIDENTIAL” stamp is the same on every copy, so a leak traces to no one — and hand-making a copy per recipient does not scale past three people. Per-viewer dynamic watermarking flips it: you share one link, and every page every viewer sees is rendered with their email and timestamp overlaid. One document, N personalized copies, zero manual stamping. A reader whose own email is on every page forwards nothing; and if a page does surface where it shouldn't, the copy itself names the leaker and the moment they opened it. Dynamic per-viewer watermarking is on Peony Data Room ($52/admin/month); viewers are always free. Trusted by 6,800+ customers.

The deeper mechanics live in the dynamic watermarking guide — how server-side rendering makes the overlay unstrippable.

What is per-viewer watermarking?

Per-viewer watermarking overlays each viewer's own identity — their email address and a timestamp — onto every page of a document at the moment they open it. Instead of one identical file passed around, you share a single link, and the page each person sees is rendered with their email and the time they viewed it. That is what makes a leak attributable instead of anonymous: the copy itself names who it was issued to and when.

This is the opposite of a static watermark — a faded “CONFIDENTIAL” baked into a PDF once. A static stamp is the same text for everyone, so when a slide surfaces on a competitor's desk you know it leaked but not from whom, and free tools strip a PDF-layer stamp in seconds. A per-viewer dynamic watermark is generated in real time, unique per viewer, rendered on every page, and tied to your access log. On Peony, the watermark is composited server-side into every rendered frame before it reaches the browser — the original file never leaves Peony's servers, so a viewer can never strip what their browser never received.

The two effects, in order of value: first deterrence — a reader who sees their own email on every page is far less likely to forward, screenshot, or print for someone else; then attribution — if a page does escape, you read the email off the leaked image and match it to a session. Dynamic per-viewer watermarking is a Peony Data Room capability at $52/admin/month ($75 monthly). Business at $30/admin/month adds Simple NDA gating, screenshot protection, and AI document Q&A — but not watermarks — and even the free tier covers page-by-page analytics and password protection. Peony serves 6,800+ customers across fundraising, M&A, private funds, commercial real estate, and professional services.

How do I send a PDF stamped with each viewer's email?

  1. 1. Upload the document once. Drag your PDF, deck, model, or CIM into a Peony Data Room ($52/admin/month). The original file stays in Peony's storage and is never sent to viewers.
  2. 2. Toggle dynamic watermarks on the room. One click. The default payload is the viewer's email plus a UTC timestamp, rendered diagonally at 30-60% opacity so content stays readable.
  3. 3. Add the recipient emails to the allow-list. Paste the viewer emails and Peony generates identity-bound personalized links — one link, one rendered copy per viewer, no manual stamping.
  4. 4. Send one link per viewer. Each person opens their link and every page renders with their own email and timestamp composited server-side into the frame.
  5. 5. Attribute or revoke if a page surfaces. Read the email off any leaked page, match it to a session in the access log, and revoke that viewer's access in one click.

Why doesn't a static “CONFIDENTIAL” stamp protect anything?

A static “CONFIDENTIAL” stamp fails at the exact moment you need it, for three structural reasons. It is the same text for everyone — “Company Confidential” tells a lawyer nothing about which of forty investors forwarded a deck. It gives you no attribution — if the file surfaces on a competitor's desk you know it leaked, but not from whom. And it is easy to remove — most static watermarks are a layer in the PDF that free tools like QPDF strip in seconds, and cropping a screenshot often removes a corner-placed stamp entirely.

Making per-recipient copies by hand does not fix this either: it stops scaling past about three recipients, and one mislabeled export undoes the whole exercise. Per-viewer dynamic watermarking solves all three problems at once — the overlay is unique per viewer, it carries the leaking viewer's email for attribution, and because it is baked into the rendered frame there is no layer to strip. That is why teams sharing anything sensitive externally treat static stamps as theater and per-viewer watermarks as the real accountability layer. For the head-to-head on how the major tools render watermarks, see the dynamic watermarking guide.

How does per-viewer watermarking work on a Peony link?

You share one link, and the watermark is rendered per viewer at view time — there are no manual copies. When a viewer clicks their identity-bound link, Peony verifies who they are, constructs a watermark string from their email and the access timestamp, and composites it as a semi-transparent diagonal overlay onto every page before the frame reaches their browser. Viewer one sees their email; viewer two sees theirs; nobody sees an unwatermarked version. One document becomes N personalized copies with zero stamping on your side.

The reason this survives a screenshot is where the rendering happens. Peony converts your document into a secure rendered format and composites the watermark server-side into every frame — the raw file is never transmitted, so when a viewer screenshots, the image they capture already has the watermark baked in. That is the opposite of a removable PDF layer, which strips in seconds. Because the email comes from an identity-verified link, every overlay maps to a real person rather than an “Anonymous Viewer,” and every access event is written to your access log with page-level granularity. Setup is under 5 minutes for 30 viewers: upload once, toggle watermarks, paste the emails, send the links.

What shows up in the watermark?

On every page: the viewer's verified email address and a UTC timestamp to the second. That is the default payload, and it is the minimum that makes a leak attributable. You can add a document or deal identifier, optionally the viewer's IP address if your counsel wants stronger forensic detail, and an optional confidentiality line such as “Confidential — Do Not Distribute.” On Peony Data Room ($52/admin/month) the payload is configurable per room and per document.

Placement matters as much as content. The overlay renders diagonally at roughly 30-60% opacity — dark enough to read, light enough not to obscure the underlying page during honest review — and it repeats across the page and appears on every page, not just the cover. Diagonal, repeated placement is what lets the watermark survive a crop or a partial screenshot: there is no clean corner to cut off. Because the email is pulled from the identity-bound link, the identity on the page is the identity that actually opened it.

Can a watermark actually stop a leak?

Honestly — a watermark does not physically stop a leak. It cannot prevent someone from pointing a phone camera at their screen, and no browser-based tool can. We say that plainly because the limit is exactly why identity stamping matters: even that un-blockable phone photo carries the leaker's email, so an un-preventable act becomes a traceable one. What a per-viewer watermark does is two things — it deters (a reader whose own email is on every page forwards nothing) and it attributes (a page that surfaces still names the viewer and the timestamp).

Because deterrence-and-attribution is the honest scope, watermarking is not a standalone perimeter — it pairs with the rest of the Data Room ($52/admin/month) stack. Layer it with screenshot protection that blocks and logs the OS-level capture shortcut across every modern desktop browser, view-only links with downloads disabled so there is no file to forward, instant revoke to cut access the moment a leak is traced, and link expiry so access lapses on a schedule. Watermarks handle the psychological and forensic layer; the others add technical friction. Together they cover both the “I might get caught” and the “it is technically harder” angles — which is the layered posture security professionals actually recommend.

What can per-viewer watermarking on Peony do?

One link, N personalized copies

Share a single link; every viewer's rendered pages carry their own email and timestamp. No manual per-recipient files — the identity is rendered at view time, not stamped by hand.

Server-side per-frame rendering

The watermark is composited into every rendered frame on Peony's servers before it reaches the browser. The raw file never leaves Peony — you cannot strip what a viewer never received. Data Room ($52/admin/month).

Email + timestamp on every page

The default payload is the viewer's verified email and a UTC timestamp, repeated diagonally at 30-60% opacity across every page — not just the cover — so it is hard to crop out.

Configurable payload

Add a document or deal ID, optionally the viewer's IP for stronger forensics, and an optional Confidential — Do Not Distribute line. Configure it per room and per document.

Survives screenshots

Because the watermark is baked into the rendered image bytes, a screenshot or screen recording captures it too. Pairs with screenshot protection that blocks and logs the OS-level capture shortcut.

Identity-bound access

The email on the watermark comes from an identity-verified personalized link, so every overlay maps to a real, verified person — not an anonymous viewer.

Access log for attribution

Every view is logged with the viewer's email, timestamp, IP, and per-page dwell time — so a watermark read off a leaked page matches a specific session in seconds.

Instant revoke

Cut off a viewer the moment a leak is traced or a party drops out — access stops immediately, even for a recipient who already opened the link.

Link expiry

Set links to lapse on a schedule so a watermarked document does not live forever in someone's inbox after the process ends.

Flat pricing, free viewers

One flat $52/admin/month whether you watermark for one viewer or thirty. Viewers are always free — no per-viewer, per-document, or per-watermark add-on fees.

Who uses per-viewer watermarking?

Founders sending decks

Send the deck beyond the first investor call with each VC's email on every slide — casual forwarding stops, and a leak names the fund that forwarded it.

M&A sellers sharing CIMs

Every bidder sees their own identity on every CIM page. A forwarded PDF or a photo of a screen still traces back to the specific bidder — source file untouched.

GPs sharing LP reports

Quarterly LP letters, IRR waterfalls, and fee schedules render with each LP's email, so a screenshotted number leads straight back to the LP who leaked it.

CRE sponsors sharing OMs

Offering memoranda, rent rolls, and T-12s carry each prospect's identity on every page — discretion on off-market deals without minting a copy per buyer.

Consultants sharing deliverables

Reports and models render with the client's identity on every page, deterring the forward-to-a-competitor path and the upload-to-a-chatbot path alike.

Board & legal distributions

Strategic plans, comp data, and privileged memos render with each recipient's identity — accountability even on personal devices outside corporate IT.

What happened when a deck leaked?

Here is the attribution effect in practice. A founder shares a deck with a pool of investors, and weeks later a near-identical slide surfaces in a portfolio company's deck — same chart, same competitive matrix, slightly different colors. Because per-viewer watermarks were on, the leaked image carries the forwarding investor's email rendered diagonally across the slide. The founder reads the email, filters the access log by it, finds the session whose timestamp matches the watermark, and now has the chain of custody: who opened the deck, when, from what IP, and which pages they viewed. They revoke that viewer's access to the rest of the room in one click, present the watermark plus the log to the fund's general partner, and get a remediation — no litigation required.

If the first version had gone out without watermarks, the move is to turn them on for the redistribution: rewatermark a tightened version, send it to the cleared list only, and treat any second leak as the test — the watermark then names the leaker exactly. The full 5-phase recovery sequence — contain, identify, rewatermark, redistribute, prevent — is in how to recover from a leaked pitch deck, and the founder-side proactive setup is in how to watermark a pitch deck with each investor's email.

When do you watermark — and when do you deliberately not?

Always watermark anything you would be genuinely upset to see in a competitor's inbox or on social media: pitch decks, financial models, cap tables, M&A diligence documents, board packs, legal memos, and customer data. These are the documents where a single forwarded copy has real consequences, and where per-viewer identity earns its keep.

Consider watermarking the middle tier — product roadmaps, partnership proposals, and internal strategy shared cross-team — where the risk is real but lower.

Deliberately skip watermarking material that is already public or meant to be: public marketing collateral, press releases, and general company info. This is the nuance most teams miss — watermarking everything trains people to tune it out or feel distrusted, which weakens the deterrent exactly where it matters. Microsoft's own guidance for sensitivity labels makes the same point: reserve dynamic watermarking for your most sensitive documents rather than applying it blanket. Because Peony toggles watermarks per room and per document on the Data Room plan ($52/admin/month), the high-sensitivity room is watermarked and the public one-pager is not.

"Peony is easily the best form factor for sharing client-facing material. It lets us stand out by embedding custom booking and website links into secure deck shares."
Y Combinator
RL

Robi Lin

Founder & CEO, Sepal AI (YC S24)

Frequently asked questions

I'm a Series A founder sending my deck to 30 VCs next week — how do I send a PDF stamped with each VC's email instead of one identical file?

You do not send 30 files — you share one link, and every VC who opens it sees their own email and a UTC timestamp rendered diagonally across every page. On Peony Data Room ($52/admin/month), you upload the deck once, toggle dynamic watermarks on the room, paste the 30 investor emails into the allow-list, and copy out 30 personalized identity-bound links in under 5 minutes. There is no manual per-recipient stamping — each link renders the bound VC's identity onto every slide the moment they open it. If a slide surfaces in a competing founder's Slack three weeks later, you read the email off the leaked image and match it to a session in your access log. The watermark is composited server-side into the rendered frame, so it survives a screenshot and there is no PDF layer for the viewer to strip. DocSend does not watermark downloaded documents; Acrobat's static stamp is the same text for everyone, so it attributes nothing.

What is the difference between a static CONFIDENTIAL stamp and a per-viewer dynamic watermark?

A static watermark stamps the same text on every copy — every viewer sees the identical CONFIDENTIAL overlay, so when a page leaks you learn nothing about who forwarded it. A dynamic per-viewer watermark renders different text for each viewer per session: viewer one sees their own email and timestamp, viewer two sees theirs. The practical difference is attribution. On Peony Data Room ($52/admin/month), the leaking viewer's email is rendered into every leaked page, so an anonymous leak becomes a named one. Static PDF-layer stamps also strip in seconds with free tools like QPDF. Peony composites the watermark server-side into the rendered image bytes, so the original file never leaves Peony's servers — a viewer can never strip what their browser never received. Static stamps are theater for external sharing; per-viewer watermarks are the accountability layer that actually changes behavior.

What actually shows up in the watermark on each page?

By default, every rendered page carries the viewer's verified email address and a UTC timestamp to the second, rendered as a semi-transparent diagonal overlay at roughly 30-60% opacity so the underlying content stays readable. You can add a document or deal identifier, optionally the viewer's IP address if your counsel wants stronger forensic detail, and an optional confidentiality line such as Confidential — Do Not Distribute. On Peony Data Room ($52/admin/month) the payload is configurable per room, and the watermark repeats across the page and appears on every page — not just the cover — so it is difficult to crop out. The email is pulled from the identity-bound personalized link, which is why identity verification matters: the watermark maps to a real, verified person rather than an anonymous viewer. Repeating the overlay and rendering it diagonally is what lets it survive a partial screenshot or a crop.

Can a watermark actually stop a leak, or just tell me about it after the fact?

A watermark does not physically stop a leak — it deters most leaks and attributes the rest, and being honest about that limit is the whole point. It cannot prevent someone from pointing a phone camera at their screen; no browser-based tool can. But two effects do the work. First, deterrence: when a viewer sees their own email stamped across every page, casual forwarding drops sharply, because the copy they would forward carries their name. Second, attribution: if a page does surface where it should not, the watermark names the viewer and the timestamp, and you match it to a session in your access log. Because the deterrence-only limit is real, watermarking pairs with the rest of the Data Room ($52/admin/month) stack — screenshot protection that blocks and logs the OS-level capture shortcut, view-only no-download links, instant revoke, and link expiry. Even the un-blockable phone photo carries the leaker's email, which turns an un-preventable risk into a traceable one.

A slide of ours leaked to a competitor. If we had per-viewer watermarks on, how do we find who did it?

If watermarks were on before the leak, you identify the source by reading the email off the leaked image and matching it to a session in your access log. On Peony Data Room ($52/admin/month), every rendered page carries the viewer's email plus a UTC timestamp, and a screenshot or a re-shared image preserves that text. You filter the access log by that email, find the session that matches the watermark's timestamp, and you now have who opened the document, when, from what IP, which pages they viewed and for how long — the chain of custody your counsel needs for a remediation conversation. Revoke that viewer's access to everything else in the room in one click, then rewatermark a tightened version and redistribute to the cleared list only. If your first version had no watermarks, turn them on for the redistribution: any second leak then names the leaker exactly. The full playbook is our leaked-deck recovery guide.

When should I turn watermarking on — and when should I deliberately not bother?

Turn per-viewer watermarking on for anything you would be genuinely upset to see in a competitor's inbox or on social media: pitch decks, financial models, cap tables, M&A diligence documents, board packs, legal memos, and customer data. Consider it for product roadmaps, partnership proposals, and internal strategy shared cross-team. Deliberately skip it for material that is already public or meant to be — public marketing collateral, press releases, and general company info — because watermarking everything trains people to tune it out or feel distrusted, which weakens the deterrent where it matters. Microsoft's own guidance for sensitivity labels makes the same point: reserve dynamic watermarking for your most sensitive documents rather than applying it to everything. On Peony Data Room ($52/admin/month) you toggle it per room and per document, so the high-sensitivity room is watermarked and the public one-pager is not.

I'm an M&A seller sharing a CIM with multiple bidders — does the watermark change the source file or break the financial model?

No — the watermark never touches your source file. A VDR that bakes the stamp into the uploaded PDF will shift page breaks, move footnotes, and break the cross-references in a financial model. On Peony Data Room ($52/admin/month), the watermark is composited server-side into the rendered frame each bidder sees in their browser, not into the uploaded document. The source CIM stays exactly as your team built it; each bidder's session shows their email, IP, and UTC timestamp as a semi-transparent diagonal overlay while page breaks and model links stay intact. Static PDF watermark tools like Acrobat and Foxit bake the stamp into the file itself, which forces layout reflow on dense CIM pages. Server-side rendering is the approach M&A sellers ask for most once they have used both, and it is why the watermark survives a screenshot — it is part of the rendered image, not a strippable layer.

Is per-viewer watermarking on the free tier or the $30 Business plan, or do I need Data Room?

Dynamic per-viewer watermarking is a Data Room capability at $52/admin/month ($75 monthly). It is not on the free tier and not on Business at $30/admin/month — Business adds Simple NDA gating, screenshot protection, and AI document Q&A, but not dynamic watermarks. The free tier includes page-by-page analytics and password protection. So the ladder is: free for tracked, password-protected sharing, Business at $30 for screenshot protection and NDA gating, and Data Room at $52 for dynamic per-viewer watermarks plus unlimited rooms and granular per-file permissions. Pricing is flat per admin — one price whether you run one room or thirty, and viewers are always free, so adding 30 investors or 12 bidders never changes the bill. There are no per-viewer, per-document, or per-watermark add-on fees.

One link. Every viewer's email on every page.

Turn on per-viewer watermarks in under 5 minutes — email and timestamp baked into every rendered frame, on Peony Data Room ($52/admin/month). Viewers are always free. Trusted by 6,800+ customers.

No credit card required