To send an RFP securely, you control the document instead of emailing it as an attachment: gate access behind a verified email, share a tracked and revocable link rather than a file that forwards forever, watermark sensitive pages with each recipient's identity, and, where the specs are genuinely commercially sensitive, put a mutual NDA in front of them first. The risk in a request for proposal is rarely the vendors you chose; it is that your detailed requirements, budgets and technical specs travel further than intended, reaching competitors or the wider market. This guide walks through how to run an RFP so your specifications stay with the suppliers you meant to reach. It is general information, not legal advice.
If you want the broader comparison of tools and approaches for this, our roundup on the best way to send an RFP without leaking specs sits alongside this guide; here we focus on the how, step by step.
Why RFPs leak in the first place
An RFP is unusually leaky by nature. You are deliberately sending detailed, sensitive information (requirements, volumes, budgets, timelines, sometimes proprietary technical specifications) to multiple parties at once, several of whom are competitors with each other. The document is designed to be read widely, which is exactly what makes it dangerous.
The default method makes it worse. Email an RFP as a PDF attachment and you have lost control the instant it lands: any recipient can forward it to a colleague, a subcontractor, or a friend at a rival firm, and you will never know. There is no expiry, no record of who opened it, and no way to pull it back. The specs you spent weeks refining are now a file of unknown provenance circulating beyond your list. That is not a hypothetical; it is the ordinary behaviour of email attachments, which is why our guide on tracking who opened a PDF exists at all.
The fix is not to send less information, because a vague RFP produces vague proposals. The fix is to change how the information travels, so that the level of detail stays high while the control over reach stays with you.
Step 1: Decide what needs an NDA
Not every RFP needs a non-disclosure agreement, but many do. If your specifications reveal a proprietary process, unreleased product plans, sensitive commercial figures or anything a competitor could exploit, put a mutual NDA in front of the document before anyone reads it. A mutual NDA that binds both sides is usually the easiest to get accepted, because vendors expect confidentiality to run both ways in a competitive procurement.
The NDA does two things. Legally, it gives you a contractual remedy if a recipient misuses or leaks your material. Practically, it sets the tone: recipients treat a document behind an NDA with more care than a casual attachment. It is not a technical control (an NDA cannot physically stop a forward) but it changes behaviour and gives you recourse, which is why it pairs so well with the technical measures below.
Step 2: Gate access and send tracked links
Once you know what protection each part of the RFP needs, change the delivery. Instead of attaching the document, host it and share a link that is gated and tracked.
Gating means a recipient has to prove who they are before the document opens, typically by entering a verified email address and a one-time code sent to it. That single step means only the people you invited can view the RFP, and every view is tied to a named recipient rather than an anonymous download. Our guide on gating and access control explains the mechanics.
Tracked and revocable links replace the fire-and-forget attachment. Each recipient gets their own link, which you can expire on a date or revoke on the spot. If a supplier drops out of the process, you cut their access with one click rather than hoping they delete the file. And because every open is logged, you can see who is actually engaging, which is useful process intelligence as well as a security measure.
Step 3: Watermark the sensitive pages
Watermarking is the measure that changes behaviour most directly. By stamping each page with the recipient's identity (their email or name) and often a timestamp, you make every copy traceable to the person who received it. If a watermarked RFP later surfaces where it should not, the watermark points to the source.
Be honest about what this does and does not achieve, because it matters. Watermarking is a deterrent and a forensic aid, not a lock: a determined leaker can still photograph a screen or retype the specs, and no watermark physically prevents a copy. What it does is raise the cost and risk of leaking, because the leaker knows any copy carries their name, and it gives you an evidence trail if a leak happens. Our guide on what document watermarking is and what it cannot do sets out the limits plainly, and the wider question of relying on deterrence versus prevention is worth thinking through before you decide how much to lean on it.
How 99 Data Rooms handles this
Running an RFP the secure way usually means stitching together several tools; 99 Data Rooms puts the whole flow in one place. You can draft a mutual NDA from vetted England and Wales clauses with the AI Legal Drafting feature, then, on the Business tier, gate the RFP so a recipient must accept that NDA before the document opens. Access is controlled by verified email and a one-time code, and every recipient gets a tracked, revocable link rather than an attachment.
Once the RFP is open, page-by-page analytics show you who viewed it and how far they read, with a clear split between a raw visit and a verified viewer who passed the gate. On the Business tier, dynamic watermarking stamps each recipient's identity across the pages, so any leaked copy is traceable. If a vendor withdraws, one click revokes their access. The result is that your specs stay behind a gate, tied to named recipients, watermarked, tracked, and revocable, which is exactly the posture an RFP needs and which a plain email cannot offer. If you also want the tool-by-tool view, our roundup of the best ways to send a contract securely covers adjacent use cases.
Send your next RFP with control
You can draft an NDA, gate the RFP, share tracked and revocable links, watch who reads it and watermark every page, all inside 99 Data Rooms. The free tier is genuinely free (three rooms, twenty-five active links, forever, no card), with NDA gating and watermarking on the Business tier. Start for free, load your RFP, and keep your specs with the suppliers you chose. The platform is in beta and improving fast, but gated, tracked, watermarked sharing already works today.
Sources
Can I really stop an RFP from being leaked?
Not absolutely, and it is worth being honest about that. You can make leaking far harder and far riskier: gating limits who gets in, watermarking ties every copy to a named recipient, and an NDA gives you legal recourse. What you cannot do is physically prevent someone from photographing a screen. The goal is strong deterrence plus a clear evidence trail, not a guarantee.
Do I need an NDA for every RFP?
No. For routine RFPs with nothing especially sensitive, gating and tracking may be enough. Reserve the NDA for RFPs that expose proprietary processes, unreleased plans or commercially sensitive figures. A mutual NDA is usually the easiest to get vendors to accept. This is general information, not legal advice.
How is a tracked link safer than an email attachment?
An attachment can be forwarded endlessly with no visibility or expiry, and you can never pull it back. A tracked, revocable link is tied to a verified recipient, logs every open, can expire on a date, and can be revoked instantly. You keep control of reach after sending, which an attachment never allows. Our guide on tracking who opened a PDF explains the visibility side.
Does watermarking slow down the vendors reading my RFP?
No. A dynamic watermark is applied to the pages the recipient views and does not change how they read or respond. It simply means each copy carries the viewer's identity. The friction is on would-be leakers, not on the legitimate vendors you want to engage.
Should every recipient get the same link?
No. Give each recipient their own gated link. That way you can see engagement per vendor, revoke one without affecting the others, and, with watermarking, tie any leaked copy to a specific recipient. One shared link removes most of those advantages.