Dec 28, 2025 7 min read· by SendMe Team

How Lawyers Should Share Contracts in 2026

Email attachments aren't due-diligence-grade. Here's the workflow that solicitors at modern firms are converging on.

Walk into any law firm in 2026 and you'll still see contracts moving by email attachment. Outlook still chugs along, and the partners trained on paper before Outlook are reluctant to learn anything new. But the cost of email-based contract sharing has been rising. State bar associations in three U.S. states now publish 'cybersecurity duty' guidance that explicitly identifies email attachments as inadequate for sensitive materials. Here's the workflow modern firms are adopting.

Why email attachments are inadequate

Email attachments have no expiry, no access logging, and no recall. Once sent, a contract draft can be forwarded indefinitely. If a paralegal accidentally cc's a wrong address, the only remedy is a sheepish follow-up email asking the wrong recipient to 'please delete'. This is not a thing you can rely on in a privilege-or-malpractice scenario.

The four-layer modern workflow

  • Drafting in a secure, access-controlled platform (the firm's DMS — iManage, NetDocuments, or a self-hosted equivalent).
  • Sharing with external parties via an expiring transport with password protection and access logging.
  • Signing through a dedicated e-sign platform (DocuSign, Adobe Sign, or court-recognised local equivalents).
  • Archiving the signed copy in the matter file inside the DMS, not in personal inboxes.

Step-by-step for an external draft share

When sending a draft to opposing counsel:

  • Export the latest from your DMS as a watermarked PDF (watermark = client matter number + recipient name).
  • Upload to a transport service like SendMe with password protection and 24-hour expiry.
  • Send the code by email; send the password by a different channel (phone call, secure messenger).
  • Log the share in the matter management system — sent to whom, when, expiry, password (or that one was used).

Why watermarking matters

If a draft leaks, watermarking lets you trace which recipient had the leaked copy. Modern PDF watermarking is non-destructive (recipients can read normally) but every copy has a unique fingerprint embedded in metadata and as a subtle visual watermark. Off-the-shelf tools that do this: Adobe Acrobat Pro, Foxit PhantomPDF, or the more sophisticated DRM platforms like Vera or DocSend.

What this does for compliance

  • Demonstrates 'reasonable care' under most bar associations' competence and confidentiality rules.
  • Provides an audit trail for clients who ask 'who has seen this draft?'
  • Limits exposure under data-breach notification laws — an expired SendMe link is, for all practical purposes, not a 'retained' file.
  • Reduces the surface area of e-discovery in litigation — fewer copies, fewer places to subpoena.

What this does for client relationships

Clients increasingly ask their counsel about cybersecurity practices, especially clients with their own InfoSec teams. Being able to say 'we use an expiring-transport workflow with passwords and watermarking, integrated with our DMS' is the right answer in 2026. It's also genuinely correct — not just compliance theatre.

What this DOESN'T do

This workflow doesn't prevent malicious leaks by the receiver. If the partner across the table from you decides to email a screenshot of your draft to a journalist, no software stops them. But it does make accidental leaks much less likely, and it does give you a fighting chance of tracing intentional ones.

workflowcompliance
Try it

Send your next file the right way.

No sign-up. 6-digit code. Auto-expiry. Optional password.

Start sending