Back to blog
Legal & Compliance7 min read

How to Prove Chain of Custody When Sharing an NDA

A signed NDA is only as strong as your ability to prove who accessed the document, when, and from where. Here is what a real chain of custody looks like for digital document sharing.

When a lawyer shares a confidential settlement agreement with opposing counsel, the expectation is simple: only the intended recipient should see it, and if it leaks, you should be able to prove exactly whose copy it was. That expectation is rarely met in practice. Most NDAs are still shared as email attachments. Once sent, the document lives on the recipient's laptop, in their downloads folder, possibly forwarded to a colleague, possibly printed. If a copy surfaces somewhere it shouldn't, you have no way to trace it back to the source. The signed NDA that was supposed to protect you becomes evidence of how little control you actually had.

What chain of custody actually means for digital files

Chain of custody is a legal concept borrowed from evidence handling. In the physical world, it means documenting every person who touched a piece of evidence, when they touched it, and where it was stored. In the digital world, it means the same thing: a verifiable record of who accessed a document, when they accessed it, from what device, and what they did with it.

For NDA-protected documents, chain of custody serves two purposes. First, deterrence: if a recipient knows their email, IP address, and device are logged on every access, they are less likely to share the document carelessly. Second, accountability: if a document leaks, the audit trail tells you whose copy it was.

The three gaps in traditional NDA sharing

**Gap 1: No identity verification.** When you email an NDA as an attachment, you cannot prove who actually opened it. The recipient might have forwarded it. Their assistant might have opened it. A family member using their laptop might have opened it. You know who you sent it to, but not who saw it.

**Gap 2: No access control after sending.** Once an email attachment is sent, you cannot revoke access. The file is on the recipient's device. You can ask them to delete it, but you cannot enforce it. If the relationship sours or the deal falls through, the document is still out there.

**Gap 3: No audit trail.** Email metadata tells you when a message was delivered. It does not tell you when the attachment was opened, whether it was printed, whether it was forwarded, or from what device it was accessed. If you need to prove chain of custody in litigation, email metadata is not sufficient.

How FileLink closes all three gaps

**Identity verification through OTP.** When you share a document through FileLink, the recipient must verify their identity with a one-time password sent to their email before they can view it. This means you know the person who accessed the document is the person you intended — not someone who happened to have access to their inbox.

**Access control that is real.** Files are streamed to a secure in-browser viewer. They are not downloaded to the recipient's device. When you revoke access, the file becomes inaccessible immediately. There is no local copy to keep. If you set a date and time for access to expire, it expires automatically — no manual follow-up needed.

**A complete audit trail.** Every access is logged: who opened it (verified via OTP), when they opened it, from what IP address, on what device, and how long they spent viewing each page. If the document is watermarked with the recipient's email and IP, a screenshot leak is traceable back to the individual. This is a chain of custody you can export and present as evidence.

The practical checklist

If you are sharing NDAs or other legal documents, ask yourself:

1. Can I prove who opened the document? (Not just who I sent it to.) 2. Can I revoke access after sending? 3. Can I trace a leaked copy back to its source? 4. Is every access logged with timestamp, IP, and device? 5. Is the document watermarked with recipient-identifying information?

If the answer to any of these is no, your chain of custody has a gap. And a gap in chain of custody is a gap in your ability to enforce the NDA you spent time negotiating.

For legal teams handling NDAs, case files, and settlement agreements, a [dedicated legal and NDA workflow](/use-cases/legal-and-nda) with built-in chain of custody is not a luxury. It is the difference between an NDA that protects you and one that is just a piece of paper.

See FileLink on your own files.