Built for confidential deal sharing

Control who can access each data room and document, how they access it, and what they can do once inside.

AES-256

Encryption at rest

TLS

Encryption in transit

Short-lived URLs

Temporary file access

Owner-controlled access

Per-link security controls

You control who enters the room

Configure security independently for each data room or document you share.

Identity

Verified email

Email whitelist

Access requirements

Password protection

NDA gating

Link lifecycle

Link expiration

Maximum views

Instant revocation

Control what happens after access

Access doesn’t have to mean unrestricted access.

Control downloads

Let recipients view documents without downloading them.

Granular room permissions

Control which folders and documents are visible to different recipients.

PDF watermarking

Add identifying or custom text to shared PDFs.

Custom share domains

Serve shared content from your own branded domain with TLS.

E-signatures

Collect signatures directly alongside shared documents.

Files aren’t exposed through permanent URLs

After a viewer is authorized, Pageform generates short-lived access to the requested file. Once that access expires, authorization is required again before the file can be retrieved.

1

Authorize

Pageform checks workspace membership or the security requirements configured on the share link.

2

Create temporary access

A short-lived file URL is generated for the specific object.

3

Deliver file

The authorized file is delivered to the viewer.

4

Access expires

The viewer must be authorized again after temporary access expires.

Public access to document storage is blocked.

Security beneath every room

Pageform infrastructure

Edge

Cloudflare

Application access

Backend authorization

Application data

Supabase + row-level security

Documents

Private AWS S3

Document processing & AI

Microsoft Azure

Encrypted at rest & in transit

Layered authorization

Private file storage

Malware protection

Restricted internal access

Keep internal access structured

Workspace access is limited to three customer-facing roles.

Owner

Full control of the workspace

Editor

Can view, edit, and share

Viewer

Can view assigned content


Owner

Editor

Viewer

View

Edit & share

Manage workspace

Know what happens after you share

See who entered, what they looked at, and how your organization is using the room.

Viewer identity

Engagement analytics

Activity audit trail

Organization access

How Pageform AI handles your data.

Your content is never used to train models or shared with other customers.

No training or cross-customer sharing

Customer content is not used to train AI models or shared with or exposed to other Pageform customers.

You stay in control

AI-proposed changes can be reviewed, adjusted, or reverted before you finalize the room.

AI processing on upload

Uploaded documents may be automatically processed to generate summaries and support room organization.

Data retention and deletion

Active account

Customer content is retained while the account is active and needed to provide the service.

Trial expiration

If a trial ends without an upgrade, the workspace is retained for one month before deletion.

Account deletion

Deleting an account begins deletion of the account, owned organizations, and associated customer content from active systems.

Deletion requests

Customers can also request deletion directly. Residual backup copies may remain temporarily as part of normal backup processes and are not actively used.

*A Data Processing Addendum and subprocessor information are available on request.

Frequently asked questions

Documents are stored in private AWS S3. Application data uses Supabase. Public access to document storage is blocked.

Documents are stored in private AWS S3. Application data uses Supabase. Public access to document storage is blocked.

Yes. Files are encrypted at rest with AES-256 and in transit with TLS / HTTPS.

Yes. Files are encrypted at rest with AES-256 and in transit with TLS / HTTPS.

No. After a viewer is authorized, Pageform generates short-lived access to the requested file. Once that access expires, authorization is required again.

No. After a viewer is authorized, Pageform generates short-lived access to the requested file. Once that access expires, authorization is required again.

Yes. You can disable downloads on a share, and apply per-document and room-level permissions.

Yes. You can disable downloads on a share, and apply per-document and room-level permissions.

Yes. Access can be revoked instantly for a share link.

Yes. Access can be revoked instantly for a share link.

Yes. Use verified email, an email whitelist, password protection, and NDA gating on each share.

Yes. Use verified email, an email whitelist, password protection, and NDA gating on each share.

Customer content is not used to train models for other customers. AI features are user-initiated.

Customer content is not used to train models for other customers. AI features are user-initiated.

Deleting your account in Settings permanently deletes the account and owned organizations. Stored files are cleaned up as part of that process.

Deleting your account in Settings permanently deletes the account and owned organizations. Stored files are cleaned up as part of that process.

After a trial, access is limited for about a month. If you don’t upgrade in that window, the account and its content are deleted. Upgrading to Core in that window preserves your rooms.

After a trial, access is limited for about a month. If you don’t upgrade in that window, the account and its content are deleted. Upgrading to Core in that window preserves your rooms.

Yes. A Data Processing Addendum and subprocessor information are available on request.

Yes. A Data Processing Addendum and subprocessor information are available on request.

Security or diligence questions?

Need technical information, a DPA, subprocessor details, or help evaluating Pageform for sensitive workflows?