The file leaves.
It can be saved, forwarded and re-sent. You cannot expire it, revoke it or know which copy was opened.
Control ends at sendCreate a personal link for the exact recipient, require verified email, decide what can leave the room, and close access without chasing a file.
Name the recipient instead of sending one shared URL.
Verify the email before any protected material loads.
Set an expiry, or revoke the link immediately.
Control downloads, print, watermark and screenshots.
The important difference is not another copy of the document. It is a live access policy wrapped around the original material.
It can be saved, forwarded and re-sent. You cannot expire it, revoke it or know which copy was opened.
Control ends at sendAnyone who finds or receives the same URL can look like the same anonymous visitor.
Fast, but identity-blindName the audience, verify email, add expiry, keep downloads off and see each session on the same link record.
Access stays live and editableRoundOS resolves access across the workspace, the published room, groups, sections, individual items and the link itself. A personal link can tighten the room policy; it cannot quietly weaken it.
Set defaults for downloads, screenshot deterrence and automatic expiry across new links.
The room defines the minimum gates. Links inherit required verification, NDA, watermarking and download limits.
Give one group access to a section, hide another, and keep a specific file view-only even when the rest can be downloaded.
Add a recipient email, allowlist or blocklist, password, expiry, print setting, version policy and stricter link-level controls.
One link for the audience you intended, not one URL for everyone it reaches.
A link is not an email campaign. Create it, copy it when ready, and keep the full access history attached to the link you sent.
Share a room or a direct document. Name a person, a fund, a domain or a generic audience.
Email verification, NDA, password, allowlists and manual approval can run before protected material appears.
See verification, opens, sessions, documents viewed, downloads and suspected forwarding on the link record.
End access immediately. A revoked link can be reactivated later after its expiry is made valid again.
A verified-email gate can stop an unexpected address. New device, IP and visitor patterns can also surface suspected forwarding instead of folding the activity into the original recipient.
Controls and analytics sit on the same link. You can tell not only that access was protected, but how the protected material was used.
Verified email status, visitor, company, device and session continuity.
Gate events, approval state, NDA signature, expiry and revoke history.
Documents opened, pages seen, time spent, completion and return visits.
Downloads, new-device opens and suspected forwarding appear in context.
No. They open the link in a browser and pass only the gates you selected, such as verified email, NDA, password or approval.
No. RoundOS creates and copies the secure link. You decide when and where to send it.
Yes. Print is a link setting. Download access is resolved across workspace, room, group, section, item and link policies, so a stricter rule can protect one file without opening everything else.
Yes. Reactivate it when needed. If the link has already expired, set a future expiry or choose no expiry before reactivating it.
A PDF password travels with the file and cannot show you what happened. A RoundOS link can verify identity, expire, revoke, watermark, limit download and keep a session-level access record.
Create the personal link in minutes and keep every rule editable after it leaves your inbox.