The NDA is signed. Then someone pastes a Drive folder into Slack “so they can start diligence.” That is where most NDA workflows fail—not at signature, but at the uncontrolled packet that follows.
This checklist is for GCs, deal desks, and outside counsel who need NDA follow-on materials shared with expiry, revoke, and evidence—without inventing a full virtual data room for every mutual NDA.
Separate signature from sealed distribution
- Execute in your e-sign or CLM tool
- Distribute sensitive follow-ons as sealed packets
- Close out with revoke + activity export when the window ends
Keep drafts in your collaboration suite. Move customer lists, pricing, architecture diagrams, and HR-adjacent materials into a vault. For the broader Drive decision, see Drive vs encrypted vault.
NDA follow-on checklist
- Confirm what the NDA actually covers—and what it does not
- Inventory files by sensitivity before anyone hits share
- Mint per-audience sealed links (counsel ≠ commercial team)
- Set expiry to the stated review window; ban “forever” by default
- Deliver optional passwords out of band—not in the same email
- Name an internal owner who can revoke without Slack archaeology
- Export vault activity into the matter file when diligence ends
Compliance Locker fits the distribution step: client-side encryption, sealed shares, and exportable activity for the packet—not a replacement for your CLM.
Patterns that break NDAs in practice
- One eternal “NDA – Acme” Drive folder reused across renewals
- Emailing the full diligence ZIP “to save time”
- Putting the share password in the calendar invite
- Leaving links open after the LOI dies
- Using Slack as the archive—see why chat is not a vault
When to upgrade to a diligence room
If reviewers multiply, materials change weekly, or investors join, graduate from a single NDA packet to a lightweight sealed room—see diligence rooms without shared Drive.
FAQ
Should every NDA go through a sealed vault?
Not always. Low-stakes mutual NDAs with little follow-on data may be fine in your e-sign stack. Use sealed sharing when the NDA unlocks a diligence packet, source code, pricing, or personal data.
Is DocuSign or HelloSign enough by itself?
E-sign tools handle execution well. They are not a substitute for time-boxed sharing of the sensitive materials the NDA was meant to protect.
One link for counsel and commercial—or two?
Prefer separate sealed packets when audiences need different subsets. One mega-link recreates the shared-folder problem.
What expiry should we use on NDA follow-on packs?
Align to the review window in the NDA or LOI—often 14–45 days—then revoke. Extend only with a named owner and a written reason.
Do we need watermarks on every NDA PDF?
Usually no for the NDA itself. Watermark high-blast-radius follow-on materials (customer lists, financials, source) when leakage risk is material.
Related: Sealed sharing without shared passwords, share expiry policy.