Blog · Sharing

Stop Emailing Sensitive Document Attachments

Why MSAs, diligence packs, and board materials should not live as email attachments—and how sealed links with expiry, revoke, and access evidence fix the pattern.

· 11 min read · Compliance Locker

Email is how business moves. It is also how sensitive files become immortal: copied into threads, synced to phones, archived by IT, and forwarded to people who were never on the original To: line.

This guide is for legal, security, and ops teams that still send MSAs, diligence packs, and incident attachments as email attachments—and need a cleaner pattern without pretending email will disappear.

Why attachments keep failing high-stakes shares

  • No natural revoke — once the MIME part lands, you cannot pull it back from every inbox copy
  • Unbounded forwarding — “please loop in counsel” becomes three more uncontrolled copies
  • Weak evidence — screenshots of Sent folders are not access logs
  • Backup immortality — legal hold and mail archives keep plaintext long after the deal closes

The pattern that converts risk into control

Replace the attachment with a sealed link workflow:

  1. Encrypt the file on the client before upload
  2. Mint a share with expiry, optional password, view limits, and watermark
  3. Email only the link—and deliver any password out of band
  4. Revoke or let the link expire when the engagement ends
  5. Export vault activity if someone asks who opened what

Compliance Locker is built for that packet job: client-side encryption, sealed shares, and insert-only activity you can export. Use email for notification—not as the storage layer. See Security for the trust boundary.

Playbook by document type

Executed contracts and MSAs

Send a sealed packet with a short default expiry. Do not attach the signed PDF to a 40-person thread “for visibility.”

Diligence and vendor reviews

Prefer discrete sealed sets over a living attachment chain. Update by minting a new packet rather than re-attaching v7_final_FINAL.pdf. For room-style workflows, see vendor diligence rooms without shared Drive.

Incident and IR attachments

Treat blast radius as the design constraint. Use view limits, watermarks when appropriate, and revoke as soon as the bridge call ends.

Board and exec materials

Keep collaboration drafts in your suite; deliver the sealed board pack as a controlled share. See the board pack sharing playbook.

What not to do

  • Put the share password in the same email as the link
  • Reply-all with a refreshed attachment “so everyone has the latest”
  • Assume company DLP makes forever-inbox copies acceptable
  • Use “encrypted ZIP in email” as the standing policy for all packets

30-day rollout checklist

  • Define which document classes may never be email attachments
  • Publish a one-page sealed-link default (expiry, watermark rules)
  • Train assistants and deal desks—the people who actually send files
  • Review open shares weekly during the first month
  • Align evidence expectations with what auditors ask for

FAQ

Is encrypted email good enough for MSAs and board packs?

Encrypted email improves transit confidentiality, but attachments still land in inboxes, backups, and device sync. You rarely get clean revoke, view limits, or packet-level access evidence.

What about password-protected PDFs emailed to someone?

Better than a bare attachment, worse than a sealed link with expiry and revoke. Password delivery usually rides the same channel as the file, and you cannot prove who opened it later.

When is email still fine?

Low-sensitivity drafts, scheduling, and non-confidential coordination. Keep executed agreements, diligence packets, and regulated attachments off ordinary mail threads.

Do sealed links replace email entirely?

No. Use email to notify and deliver the link. Put the sensitive bytes behind a sealed share with controls—not as a MIME part that lives forever in mail stores.

What if legal asks for a paper trail of who received the file?

Prefer vault activity exports over inbox screenshots. See our guide on document audit trails for what reviewers typically ask for.

Related: Share sensitive files without shared Drive passwords, zero-knowledge for business documents.