Share an Excel financial model with an investor without sending the file. Upload the model, send each investor a view-only tracked link with downloads off, and they review it in the browser — while you see who opened which tabs and pages, and for how long. When the numbers change mid-raise, update the model in place and the same link stays current. Revoke any single link the moment a fund passes. Free to start; the per-viewer dynamic watermark lands on Peony's Data Room plan at $52/admin/month.
See a live room: the Seed Round template — including its Operating Model and Financials folders.
Upload the workbook, send a view-only link, update it in place when the numbers move, and pull access back when a fund passes
The investor opens the link and the workbook renders as a real spreadsheet — formulas carried through so every calculated cell shows its computed value, and every sheet tab browsable, not the flattened PDF preview most data rooms fall back to. The view stays read-only: they read the model without changing an input cell, and without the .xlsx ever landing on their desktop.
When the numbers move mid-raise, upload a new version of the workbook instead of emailing a v2. Peony keeps the version history, and every investor holding the link sees the current model the next time they open it.
Each investor group holds its own access link, and permissions are set per group and per file on a slider from no access through view, download, and upload. Drop one group's model back to no access and that link stops serving it, while every other group in the round keeps working.
You stop sharing a file and start sharing an identity-bound view. Instead of attaching the .xlsx to an email, you upload the model once and send each investor a view-only link tied to their name and email, with downloads turned off. The investor reviews the model in their browser; the underlying workbook never lands on their desktop. The file effectively leaves your hands, but not your control.
An emailed workbook is the leakiest way to share a model that exists. It hands over your live formulas, your hidden tabs, your assumption cells, and any other-investor terms you forgot to scrub — and it's trivially forwardable, with no link to expire and no way to know who opened it or who passed it on. Worse, the instant an investor edits a cell in their copy, their numbers and yours diverge, and on the follow-up call you're each looking at a different model without realizing it. A link stays a single source of truth: when the numbers change mid-raise you update the model in place, and every investor who holds the link sees the current version the next time they open it — no re-send, no version sprawl.
Peony at $52 per admin per month on the Data Room plan turns that into a controlled disclosure: page-level analytics show which investor opened the model and which scenario tabs they stressed, a per-viewer dynamic watermark burns each investor's name, email, and a timestamp over the render, and per-link controls let you revoke one investor's access the instant a fund passes without touching anyone else. And if your model is an interactive HTML build — exported from your spreadsheet, or built in Claude or GPT — Peony renders .html/.htm natively in the browser with JavaScript executing, so it actually runs for the investor rather than collapsing to a flat PDF. We serve 6,800+ customers, a lot of them founders and CFOs in exactly this moment.
One caveat, stated plainly: a watermark and screenshot protection are attribution and deterrence, not capture-prevention. A determined viewer can still photograph a screen or retype your numbers — but with a per-viewer watermark, they're photographing their own name. These controls raise the cost of a leak and create a forensic trail; they are not magic.
Upload the workbook and issue each investor a link tied to their name and email — one per person, not one link for everyone, with downloads turned off.
They read the model in a viewer you control; the raw .xlsx never lands on their desktop, so there's no file to save or forward.
Page-level analytics attribute every view to the named investor — which scenario tabs and pages they spent time on, and for how long — so a cold follow-up becomes a precise one.
When the model changes mid-raise, update it in place — the same link stays current, and every investor who holds it sees the latest version the next time they open it. No re-send.
Cut off any single investor's link the instant they pass or the round closes — without breaking access for anyone else.
You want a few trusted people to co-edit it. Use Google Sheets. Real-time collaborative editing with people you trust is exactly what it's for. The task here is the opposite — controlled disclosure to people you're still deciding about — which is where analytics, gating, and revocation matter and a shared editable link does not.
You want a free, no-login, public link in thirty seconds. For a genuinely non-confidential teaser, a public artifact link from a tool like ShareDuo or Stacktree is fast and frictionless, and honestly fine. A public link just can't bind the view to a named investor, gate on an NDA, show you who looked, or revoke one person after the fact.
You haven't built the model yet. This is about sharing a model you've already built, not constructing one. For the architecture, the waterfall math, and the Excel mistakes that get a model rejected, start with the deep-dive guide and the build resources it links to.
You're standing up the whole raise. If you're assembling the full diligence inventory — cap table, incorporation docs, financials, contracts — that's a data room, not a single share. See Seed Round Data Room for the room; this page is the single act of sharing one live model.
"Peony has been great for sharing documents with investors, employees, and customers. It's easy to use, good value, and new features are constantly being added. Definitely recommend!"

Ed Harris
Founder & CEO, Ligo Bio (YC S24)
Share a link, not a file, and update in place. When you share your model as a view-only link instead of emailing the .xlsx, the link points at the model you published — so when the numbers change mid-raise, you update the model in place and every investor who holds the link sees the current version the next time they open it. There's no re-send, no 'v7_FINAL_final.xlsx', and no risk that a partner is quietly diligencing a three-week-old burn figure. An emailed workbook is a dead snapshot the moment it's opened; a link stays a single source of truth. Peony's page-level analytics also show which investors re-opened after your update, so you can see who's still actively looking. The whole point is that the file effectively leaves your hands but not your control — one live model, one current version, for all eight investors at once.
Here's the honest version. You can't make a forward physically impossible, but you can make it pointless and traceable. Send each investor their own link tied to their name and email, not one link for everyone. Turn download prevention on so the underlying workbook never lands on anyone's desktop — there's no file to attach and forward. If they hand their link to another fund, you see the mismatch in the per-viewer analytics, and you can revoke that one link the instant you notice, without breaking anyone else's access. On the Data Room plan ($52/admin/month) a per-viewer dynamic watermark burns each investor's name, email, and a timestamp over the render, so any screenshot or photo carries the leaker's identity. The caveat I'll state plainly: a watermark is attribution and deterrence, not capture-prevention — a determined bad actor can still retype your numbers into a fresh sheet from memory or from a screen. These controls raise the cost of leaking and create attribution; they are not magic. What they buy you is that a casual 'let me forward this to my partner' becomes a deliberate, self-incriminating act.
Default to view-only, and grant a download only to the party you've already decided to build the round around. A view-only link lets a diligence team read the whole model in the browser — every tab, every calculated cell, at the current numbers — without the raw workbook ever leaving your control. For most of the process that's exactly right, because it keeps your formulas, hidden tabs, and assumption cells in your hands while still showing them the real thing. What a view-only link does not do is let them drive the model themselves: the render is read-only, so they can't re-point an assumption and watch it flow through. The moment to hand over a downloadable .xlsx is narrow: a signed lead who genuinely needs the workbook in their own environment to build an investment memo, after terms are far enough along that the file walking out is an acceptable trade. Peony lets you set download permission per link, so you can keep every exploratory investor on a view-only, no-download link and issue exactly one downloadable version to the lead — and revoke it if the process changes. The mistake is granting download by default to everyone who asks; when someone says 'the live model' they usually mean 'the current numbers', and a view-only link on the latest version answers that. Reserve the download for the party that genuinely needs to rebuild the scenarios in their own environment.
Issue one link per bidder, not a shared link, and let the analytics rank them for you. Each bidder gets a link tied to their name, so every view is attributable — you can see which of the six actually opened the operating model, which scenario tabs and pages they spent time on, and how long they stayed. That turns 'who's real' from a guess into a readout: the bidder who spent twenty minutes across the downside case and the working-capital build is telling you something the bidder who opened it once for ninety seconds is not. Keep every link view-only with downloads off so the model doesn't circulate between bidders, and on the Data Room plan ($52/admin/month) a per-viewer watermark stamps each bidder's identity across the render. When a bidder drops, revoke just their link. Viewers are unlimited and free on every plan, so six bidder-side teams — or sixteen — cost nothing extra; you're billed only for your own admin seat.
Yes, a screen can always be photographed, and I won't tell you otherwise. What you get is friction and attribution, not a vault. Screenshot protection is available on the Business plan ($30/admin/month) and blocks in-app capture on desktop; the Data Room plan ($52/admin/month) adds mobile screenshot blocking and the per-viewer dynamic watermark. The honest limit is the one every serious vendor shares: someone can still point a phone camera at their monitor. The difference a watermark makes is that when they do, they're photographing their own name, email, and a timestamp burned over your numbers — so the artifact that leaks identifies the person who leaked it. Treat these controls as raising the cost and creating a forensic trail, not as making the model uncapturable. For a confidential model going to multiple named investors, that trade — deterrence plus attribution — is usually the honest best you can do short of never showing the numbers at all.
You can start for free, with real limits. Peony's Free plan is $0, requires no credit card, and doesn't expire: it covers up to 50 documents, gives you page-by-page analytics so you can see who opened your model and which pages they viewed, includes password protection, and supports unlimited visitors. That's already enough to send a named investor a link, gate it behind a password, and see whether they actually looked — which is the core of a controlled share. What Free does not include is the per-viewer dynamic watermark, which lives on the Data Room plan ($52/admin/month), and the screenshot protection and Standard NDA gating that start on Business ($30/admin/month). So the honest framing: for a broke solo founder who mainly needs 'send it to a few named people and know who read it', Free does the job; the moment the model is confidential enough that you want a viewer's identity burned over every page or an NDA in front of it, that's when you step up a tier.
Be honest with yourself about the task first. If you want a handful of people you trust to collaboratively edit the model with you, Google Sheets is genuinely the right tool and I'd use it — real-time co-editing is its whole point. But sharing a model with an investor mid-raise is a different task: it's controlled disclosure, not collaboration. A Google Sheets 'anyone with the link' URL is anonymous and forwardable — it identifies no one, it can't gate on an NDA before the model loads, it doesn't tell you which investor opened what, and you can't cut off one person without disrupting the rest. Even a link scoped to specific Google accounts gives you sharing, not a diligence readout. What a view-only tracked link adds for this task is exactly the controlled-disclosure layer: per-viewer attribution, page-level analytics, NDA and password gating, downloads off, a per-viewer watermark on Data Room ($52/admin/month), and instant revoke. Different jobs — Sheets for editing with people you trust, a tracked link for showing numbers to people you're still deciding about.
You see who opened the link, which pages or tabs they spent time on, and for how long — attributed to the named investor the link was issued to. So instead of wondering whether a partner read the model, you can tell that they opened it twice, spent most of their time on the downside scenario and the cohort build, and skimmed the summary. That's what turns a cold 'just following up' into 'I saw you spent time on the downside case — want to walk the churn assumption?'. Two honest framings for a spreadsheet: first, the granularity you get depends on how the model is laid out as viewable pages, so a model structured into clear tabs or pages reads more usefully than one giant sheet; and second, analytics tell you what was viewed and for how long, not what the investor concluded — they point you at where attention concentrated, not at a verdict. Analytics retention runs 30 days on Free, a year on Business, and two years on Data Room, so you keep the history across a long raise.
The deep-dive twin: emailing an .xlsx versus a live, interactive view — what you lose and what you keep.
When you're standing up the whole raise — cap table, financials, contracts — not just sharing one model.
See which investor opened your model and which scenario tabs and pages they spent time on, attributed by name.
One link per investor with downloads off, per-link permissions, and instant revoke when a fund passes.
Free to start; Business at $30/admin/month; per-viewer watermark on Data Room at $52/admin/month. Viewers are always free.
More task-shaped ways teams share sensitive files under per-viewer control on Peony.
Share your investor model as a view-only tracked link in under 5 minutes. Downloads off, per-viewer analytics, update-in-place, and instant revoke. Free to start; per-viewer watermark on Peony Data Room at $52/admin/month. Trusted by 6,800+ customers.
No credit card required