A short, opinionated list of what makes a difference for privileged documents — and the features that sound impressive but change nothing.
Three private surfaces. Same zero-knowledge architecture.
Client-side encryption. The document is ciphertext before it leaves your device. Everything else on this list is secondary to it.
Per-recipient links. One link per person, so a leak is attributable and revocation is surgical.
Passphrase on a second channel. The link and the passphrase should not travel together; splitting them means intercepting one is not enough.
Expiry by default. A disclosure that stops working on its own is a disclosure you do not have to remember to clean up.
Revocation that is immediate. One click, effective for everything not already downloaded.
Per-viewer watermarking. For read-only distribution, a watermark identifies the source of a screenshot.
Key rotation on removal. Otherwise "removing" someone is decoration.
Append-only audit trail. Grants, revocations, link creation and access, exportable, without content.
Resumable large uploads. Discovery bundles are large; a tool that fails at 80% teaches people to use consumer transfer services.
Encrypted file names and structure. A folder tree can disclose a strategy, a counterparty or a client relationship.
"Bank-level encryption." Meaningless. Ask what the server holds.
"Encrypted at rest." Standard everywhere; protects against stolen hardware, not against the provider.
"ISO-certified data centres." That is the building, not your documents.
"Two-factor available." Necessary, not sufficient, and much weaker than passkeys.
"Compliance ready." Compliance is your programme; a product can support it, not confer it.
"AI-powered document insights." By definition, something is reading your privileged documents.
Three private surfaces. Same zero-knowledge architecture.