Share an Excel financial model with an investor without sending the file. Upload the model, send each investor a view-only tracked link with downloads off, and they review it in the browser — while you see who opened which tabs and pages, and for how long. When the numbers change mid-raise, update the model in place and the same link stays current. Revoke any single link the moment a fund passes. Free to start; the per-viewer dynamic watermark lands on Peony's Data Room plan at $52/admin/month.
You stop sharing a file and start sharing an identity-bound view. Instead of attaching the .xlsx to an email, you upload the model once and send each investor a view-only link tied to their name and email, with downloads turned off. The investor reviews the model in their browser; the underlying workbook never lands on their desktop. The file effectively leaves your hands, but not your control.
An emailed workbook is the leakiest way to share a model that exists. It hands over your live formulas, your hidden tabs, your assumption cells, and any other-investor terms you forgot to scrub — and it's trivially forwardable, with no link to expire and no way to know who opened it or who passed it on. Worse, the instant an investor edits a cell in their copy, their numbers and yours diverge, and on the follow-up call you're each looking at a different model without realizing it. A link stays a single source of truth: when the numbers change mid-raise you update the model in place, and every investor who holds the link sees the current version the next time they open it — no re-send, no version sprawl.
Peony at $52 per admin per month on the Data Room plan turns that into a controlled disclosure: page-level analytics show which investor opened the model and which scenario tabs they stressed, a per-viewer dynamic watermark burns each investor's name, email, and a timestamp over the render, and per-link controls let you revoke one investor's access the instant a fund passes without touching anyone else. And if your model is an interactive HTML build — exported from your spreadsheet, or built in Claude or GPT — Peony renders .html/.htm natively in the browser with JavaScript executing, so it actually runs for the investor rather than collapsing to a flat PDF. We serve 6,800+ customers, a lot of them founders and CFOs in exactly this moment.
One caveat, stated plainly: a watermark and screenshot protection are attribution and deterrence, not capture-prevention. A determined viewer can still photograph a screen or retype your numbers — but with a per-viewer watermark, they're photographing their own name. These controls raise the cost of a leak and create a forensic trail; they are not magic.
Numbers change weekly — new pipeline, a churned logo. Share one live link and update in place so every investor stays on the current version.
The lead asks for 'the live model' to run their own scenarios. Keep it view-only with downloads off; grant a download only to the signed lead.
Put the operating model in front of six bidders on per-bidder links, then read the analytics to see which bidders are actually serious.
Share the deal's LP model with prospective capital partners on tracked, no-download links — see who's deep in the returns build before you call.
Send each client's model to their investors under per-viewer control from one seat — unlimited free viewers, revoke per link when a process ends.
Distribute the board model to directors as a tracked link, gate it, and see which sections each director actually reviewed before the meeting.
.xlsx never lands on their desktop, so there's no file to save or forward.You want a few trusted people to co-edit it. Use Google Sheets. Real-time collaborative editing with people you trust is exactly what it's for. The task here is the opposite — controlled disclosure to people you're still deciding about — which is where analytics, gating, and revocation matter and a shared editable link does not.
You want a free, no-login, public link in thirty seconds. For a genuinely non-confidential teaser, a public artifact link from a tool like ShareDuo or Stacktree is fast and frictionless, and honestly fine. A public link just can't bind the view to a named investor, gate on an NDA, show you who looked, or revoke one person after the fact.
You haven't built the model yet. This is about sharing a model you've already built, not constructing one. For the architecture, the waterfall math, and the Excel mistakes that get a model rejected, start with the deep-dive guide and the build resources it links to.
You're standing up the whole raise. If you're assembling the full diligence inventory — cap table, incorporation docs, financials, contracts — that's a data room, not a single share. See Seed Round Data Room for the room; this page is the single act of sharing one live model.
"Peony has been great for sharing documents with investors, employees, and customers. It's easy to use, good value, and new features are constantly being added. Definitely recommend!"

Ed Harris
Founder & CEO, Ligo Bio (YC S24)
Share a link, not a file, and update in place. When you share your model as a view-only link instead of emailing the .xlsx, the link points at the model you published — so when the numbers change mid-raise, you update the model in place and every investor who holds the link sees the current version the next time they open it. There's no re-send, no 'v7_FINAL_final.xlsx', and no risk that a partner is quietly diligencing a three-week-old burn figure. An emailed workbook is a dead snapshot the moment it's opened; a link stays a single source of truth. Peony's page-level analytics also show which investors re-opened after your update, so you can see who's still actively looking. The whole point is that the file effectively leaves your hands but not your control — one live model, one current version, for all eight investors at once.
Here's the honest version. You can't make a forward physically impossible, but you can make it pointless and traceable. Send each investor their own link tied to their name and email, not one link for everyone. Turn download prevention on so the underlying workbook never lands on anyone's desktop — there's no file to attach and forward. If they hand their link to another fund, you see the mismatch in the per-viewer analytics, and you can revoke that one link the instant you notice, without breaking anyone else's access. On the Data Room plan ($52/admin/month) a per-viewer dynamic watermark burns each investor's name, email, and a timestamp over the render, so any screenshot or photo carries the leaker's identity. The caveat I'll state plainly: a watermark is attribution and deterrence, not capture-prevention — a determined bad actor can still retype your numbers into a fresh sheet from memory or from a screen. These controls raise the cost of leaking and create attribution; they are not magic. What they buy you is that a casual 'let me forward this to my partner' becomes a deliberate, self-incriminating act.
Default to view-only, and grant a download only to the party you've already decided to build the round around. A view-only link lets a diligence team flex scenarios and interrogate the model in the browser without the raw workbook ever leaving your control — for most of the process that's exactly right, because it keeps your formulas, hidden tabs, and assumption cells in your hands while still letting them do real work. The moment to hand over a downloadable .xlsx is narrow: a signed lead who genuinely needs the workbook in their own environment to build an investment memo, after terms are far enough along that the file walking out is an acceptable trade. Peony lets you set download permission per link, so you can keep every exploratory investor on a view-only, no-download link and issue exactly one downloadable version to the lead — and revoke it if the process changes. The mistake is granting download by default to everyone who asks; 'the live model' is almost always satisfied by a view-only link they can operate, not a copy they can keep.
Issue one link per bidder, not a shared link, and let the analytics rank them for you. Each bidder gets a link tied to their name, so every view is attributable — you can see which of the six actually opened the operating model, which scenario tabs and pages they spent time on, and how long they stayed. That turns 'who's real' from a guess into a readout: the bidder who spent twenty minutes across the downside case and the working-capital build is telling you something the bidder who opened it once for ninety seconds is not. Keep every link view-only with downloads off so the model doesn't circulate between bidders, and on the Data Room plan ($52/admin/month) a per-viewer watermark stamps each bidder's identity across the render. When a bidder drops, revoke just their link. Viewers are unlimited and free on every plan, so six bidder-side teams — or sixteen — cost nothing extra; you're billed only for your own admin seat.
Yes, a screen can always be photographed, and I won't tell you otherwise. What you get is friction and attribution, not a vault. Screenshot protection is available on the Business plan ($30/admin/month) and blocks in-app capture on desktop; the Data Room plan ($52/admin/month) adds mobile screenshot blocking and the per-viewer dynamic watermark. The honest limit is the one every serious vendor shares: someone can still point a phone camera at their monitor. The difference a watermark makes is that when they do, they're photographing their own name, email, and a timestamp burned over your numbers — so the artifact that leaks identifies the person who leaked it. Treat these controls as raising the cost and creating a forensic trail, not as making the model uncapturable. For a confidential model going to multiple named investors, that trade — deterrence plus attribution — is usually the honest best you can do short of never showing the numbers at all.
You can start for free, with real limits. Peony's Free plan is $0, requires no credit card, and doesn't expire: it covers up to 50 documents, gives you page-by-page analytics so you can see who opened your model and which pages they viewed, includes password protection, and supports unlimited visitors. That's already enough to send a named investor a link, gate it behind a password, and see whether they actually looked — which is the core of a controlled share. What Free does not include is the per-viewer dynamic watermark, which lives on the Data Room plan ($52/admin/month), and the screenshot protection and Simple NDA gating that start on Business ($30/admin/month). So the honest framing: for a broke solo founder who mainly needs 'send it to a few named people and know who read it', Free does the job; the moment the model is confidential enough that you want a viewer's identity burned over every page or an NDA in front of it, that's when you step up a tier.
Be honest with yourself about the task first. If you want a handful of people you trust to collaboratively edit the model with you, Google Sheets is genuinely the right tool and I'd use it — real-time co-editing is its whole point. But sharing a model with an investor mid-raise is a different task: it's controlled disclosure, not collaboration. A Google Sheets 'anyone with the link' URL is anonymous and forwardable — it identifies no one, it can't gate on an NDA before the model loads, it doesn't tell you which investor opened what, and you can't cut off one person without disrupting the rest. Even a link scoped to specific Google accounts gives you sharing, not a diligence readout. What a view-only tracked link adds for this task is exactly the controlled-disclosure layer: per-viewer attribution, page-level analytics, NDA and password gating, downloads off, a per-viewer watermark on Data Room ($52/admin/month), and instant revoke. Different jobs — Sheets for editing with people you trust, a tracked link for showing numbers to people you're still deciding about.
You see who opened the link, which pages or tabs they spent time on, and for how long — attributed to the named investor the link was issued to. So instead of wondering whether a partner read the model, you can tell that they opened it twice, spent most of their time on the downside scenario and the cohort build, and skimmed the summary. That's what turns a cold 'just following up' into 'I saw you spent time on the downside case — want to walk the churn assumption?'. Two honest framings for a spreadsheet: first, the granularity you get depends on how the model is laid out as viewable pages, so a model structured into clear tabs or pages reads more usefully than one giant sheet; and second, analytics tell you what was viewed and for how long, not what the investor concluded — they point you at where attention concentrated, not at a verdict. Analytics retention runs 30 days on Free, a year on Business, and two years on Data Room, so you keep the history across a long raise.
The deep-dive twin: emailing an .xlsx versus a live, interactive view — what you lose and what you keep.
When you're standing up the whole raise — cap table, financials, contracts — not just sharing one model.
See which investor opened your model and which scenario tabs and pages they spent time on, attributed by name.
One link per investor with downloads off, per-link permissions, and instant revoke when a fund passes.
Free to start; Business at $30/admin/month; per-viewer watermark on Data Room at $52/admin/month. Viewers are always free.
More task-shaped ways teams share sensitive files under per-viewer control on Peony.
Share your investor model as a view-only tracked link in under 5 minutes. Downloads off, per-viewer analytics, update-in-place, and instant revoke. Free to start; per-viewer watermark on Peony Data Room at $52/admin/month. Trusted by 6,800+ customers.
No credit card required