In document security, deterrence and prevention are two different jobs, and confusing them leads to bad decisions. Prevention tries to make a leak physically impossible; deterrence makes leaking risky and costly enough that most people do not attempt it. The uncomfortable truth is that once a person can legitimately read a document, almost no control can truly prevent them from capturing its contents, so the vast majority of document security is deterrence dressed up in technical clothing. Understanding which of the two a given control actually delivers stops you overpaying for false certainty and helps you build a defence that works in the real world. This guide explains the difference, what each buys you, and how to combine them. It is general information, not legal advice.
If you have ever felt uneasy that a "secure" tool did not seem to physically stop anything, this is why. For the specific case of watermarking, our guide on what document watermarking is and what it cannot do is the natural companion to this one.
The honest distinction
Start with the clearest possible framing. Prevention is a control that makes an outcome impossible: a locked door that cannot be opened, encryption that cannot be broken without the key. Deterrence is a control that makes an outcome undesirable: a security camera does not physically stop a theft, but it raises the risk of being caught enough that fewer thefts happen.
Now apply that to documents. Encryption at rest and in transit is genuine prevention: without the key, the data cannot be read, full stop. Access gating is close to prevention for unauthorised outsiders: someone who cannot pass the gate genuinely cannot open the document. But the moment you authorise a person to read something, you have handed them the contents, and from that point almost everything is deterrence. Watermarking does not stop a leak; it makes leakers traceable. Disabling download does not stop a determined copy; a screen can always be photographed. "View-only" is a speed bump, not a wall.
This is not a criticism of those controls. It is a correction of how they are often sold. A tool that promises to "prevent" leaks by an authorised reader is, in almost every case, actually deterring them, and knowing that changes how much you should trust it.
What deterrence actually buys you
If most controls deter rather than prevent, is deterrence worth anything? Enormously, and it is worth understanding why.
Most leaks are not the work of a determined bad actor willing to photograph a screen frame by frame. They are casual: a document forwarded to a colleague "to be helpful", an attachment left on a personal device, a file shared in a group chat without much thought. Deterrence stops the casual majority cold. A per-recipient watermark that puts someone's own name across every page makes "just forwarding it" feel very different, because the forwarder knows any copy leads straight back to them.
Deterrence also creates evidence and recourse. A watermark and an access log will not physically prevent a leak, but they let you trace it afterwards, which both discourages the leak in the first place and gives you a case if it happens. Our guide on how to trace a leaked document to its source walks through that forensic side. And deterrence shapes behaviour at scale: when readers know a document is gated, tracked and watermarked, they treat it with more care than a casual attachment, which reduces the accidental leaks that make up most incidents. In short, deterrence does not promise a leak-proof world; it makes the likely leaks much less likely and the unlikely ones traceable.
Where prevention genuinely applies
None of this means prevention is a myth. There are real preventive controls, and you should insist on them where they exist.
Encryption is the headline: data encrypted at rest and in transit genuinely cannot be read by someone who intercepts it without the key. Access control is preventive against outsiders: verified-email gating with a one-time code genuinely stops people who are not on your list from opening the document. Revocation is preventive going forward: once you revoke a link, that route to the document is genuinely closed, even if it was open a moment ago. Data residency and infrastructure controls prevent whole classes of exposure by keeping data in one jurisdiction under known safeguards.
The pattern is that prevention works on the boundaries (who can get in, how the data is stored, how it moves) and deterrence works inside the boundary (what an authorised reader does with what they can see). A sensible security posture uses real prevention at the edges and honest deterrence within, rather than pretending deterrence is prevention. If you are choosing a platform, this is one of the things that separates a serious virtual data room from a simple file link, which our guide on what a virtual data room is explores.
How 99 Data Rooms handles this
99 Data Rooms is deliberately built along this deterrence-and-prevention line, and it does not pretend to be more than it is. On the prevention side, data is UK-hosted in London and resident in the UK, encrypted with AES-256 at rest and TLS 1.2 or higher in transit; access is gated behind a verified email and a one-time code, so outsiders genuinely cannot open your documents; and one-click revocation genuinely closes a link the moment you use it, even for someone mid-scroll.
On the deterrence side, dynamic watermarking on the Business tier stamps each viewer's identity across the pages, making every copy traceable and casual forwarding far less likely, while gating and access control and page-by-page analytics record who opened what and when. The design is honest about the split: the boundaries are genuinely prevented, and the behaviour of authorised readers is strongly deterred and fully evidenced, rather than falsely promised to be impossible. That is the realistic shape of document security, and building on it beats trusting a tool that overclaims. Our roundup of watermarking tools shows how the deterrent layer compares across providers.
Build security that is honest about both
You can combine genuine prevention (UK hosting, encryption, verified-email gating, one-click revocation) with strong deterrence (per-recipient watermarking, tracking and access logs) inside 99 Data Rooms. The free tier is genuinely free (three rooms, twenty-five active links, forever, no card), with watermarking and NDA gating on the paid tiers. Start for free and secure documents with controls that do what they claim. The platform is in beta and improving fast, but the prevention and deterrence layers already work together today.
Sources
Can any tool truly prevent an authorised reader from leaking a document?
Realistically, no. Once someone can legitimately view a document, they can photograph the screen or retype the contents, and no software can prevent that. Controls that claim to "prevent" leaks by authorised readers are almost always deterring them. The honest goal is to make leaking risky and traceable, not impossible. This is general information, not legal advice.
If watermarking only deters, is it worth using?
Yes, very much. Most leaks are casual rather than determined, and a per-recipient watermark stops casual forwarding by making every copy traceable to its recipient. It also gives you evidence to trace a leak that does happen. Deterrence that reliably stops the common case and provides recourse for the rare one is genuinely valuable.
Which controls are actually preventive?
Encryption at rest and in transit, access gating against outsiders, one-click revocation going forward, and keeping data in a known jurisdiction. These work on the boundaries: who gets in, how data is stored, how it moves, and how access is withdrawn. They are real prevention, unlike the in-document controls that mostly deter.
Should I pay more for a tool that promises to prevent all leaks?
Be sceptical of that promise. No tool can prevent an authorised reader from capturing content, so a "leak-proof" claim usually overstates deterrence. Spend on genuine prevention at the boundaries plus strong, honest deterrence inside, and on evidence trails for tracing. That combination is more useful than a false guarantee.
How do deterrence and prevention work together?
Prevention secures the edges: encryption, gating, revocation and residency stop outsiders and secure the data itself. Deterrence governs authorised readers: watermarking, tracking and access logs make misuse risky and traceable. Used together they cover both the "who can get in" and the "what they do inside" questions, which is what real document security needs.