Why the NDA gate tells you nothing
Put any two of these products side by side and the self-serve NDA row is a pair of ticks. The feature you are most likely to shop on is the one that cannot help you choose.
The differences come later. An NDA gate is one decision, made once. Running a trust center lasts longer than that. People leave companies. Deals go quiet. A document gets replaced. Someone asks who has your SOC 2 today. These seven separate a gate from an access-control system, and most cannot be answered from a pricing page. Ask them in a demo.
Seven questions to ask
| Ask this | Why it matters | A weak answer sounds like | DeliverTrust |
|---|---|---|---|
| Can manual review be turned on for one document but not the rest? | Your SOC 2 report and your penetration-test results are not equally sensitive. One mode makes you gate everything at your most sensitive file. | "Yes, you can require approval" - without saying whether it is all-or-nothing. | A per-document toggle. Off is instant. On sends the request to a queue to approve or reject. |
| How many notification destinations, and how many people per destination? | A request nobody sees is a deal sitting still. The usual failure is one inbox, and that person is away. | "You get an email when someone requests access." One channel, one inbox. | Email, Slack and webhook, each with multiple recipients. |
| Can you revoke one person without deleting the document or resetting a shared link? | The cleanest test of the lot. Access granted is not access owed forever, and people leave the company that was evaluating you. | "You can unpublish it" or "rotate the link" - both of which hit everyone. | Yes, per visitor. |
| Can you edit an existing grant in place? | A reviewer needs one more document, or a few more weeks. If the only moves are grant and revoke, every change starts over and muddies your own trail. | "Just revoke it and have them request again." That is starting over. | Yes, edited in place rather than torn down and rebuilt. |
| Show me who has access to this document right now. | A log tells you what happened. Current state is a different question, and rebuilding it out of past events gets it wrong. | "It is all in the activity log." A log is history, not current state. | A per-resource view: who, when, and how they got in - for documents and gated pages. |
| Are administrative actions logged, or only visitor activity? | Who approved, who revoked, who changed a gate. That is the half you need when the question is about your own team rather than a visitor. | "You can see every download." That is the visitor half only. | Both, in one audit log. |
| Which numbers change the invoice? | Usage pricing charges you more for doing the thing you bought it to do. Watch documents, access requests, viewers and admin seats. | "It depends on your usage - let us put a quote together." The answer is yes. | None. $50/month per tenant, with documents, pages and requests unlimited. |
Who should pick something else
SimpleTrustPortal is cheaper than we are and publishes its price. Pick it if sticker price decides and a simpler document-sharing portal is enough.
Vanta or Drata bundle a Trust Center into the compliance platform. If you are already buying that, adding ours pays twice for the same layer.
UpGuard Trust Exchange has a free tier: one trust center, with no custom domain and no watermarked downloads. Pick it if a trust page at no cost matters more than those two, or if you already run UpGuard's risk platform. Both sit behind its paid tier.
Current pricing for all of them, each figure linked to its source, is in the Trust Center buyer's guide.
The bottom line
Comparing these products on whether they have an NDA gate is like comparing cars on whether they have doors. Ask the seven. The field narrows fast.