You can't stop a screenshot. You can make it carry a name.
Every family office and trading desk sends the same kind of document: holdings, valuations, counterparties — to a handful of named people, by e-mail, as an attachment that instantly stops being yours. The honest starting point is that a browser cannot prevent capture; only DRM video and native apps can, and neither is a quarterly report. So the goal changes from prevention to attribution and evidence — the data-room approach. Walk the gate below, open the report, and then try to take it away.
Honest-AI note. There is no model on this page, and no server either — the entire gate runs in your browser: the allowlist decision, a six-digit code with a ten-minute life and three attempts, the session, the watermark and the audit trail. The one-time code is shown to you rather than e-mailed, for obvious reasons. Everything else behaves as the real one does, including the parts that are deliberately unhelpful to a stranger.
The gate
A one-time code was requested for .
What just happened, honestly. Selecting, copying, right-clicking and dragging are blocked inside the report, and it blurs when the window loses focus. None of that stops a phone camera pointed at your screen — and the tiled stamp behind this text is the reason that doesn't matter as much as it used to. Every leaked image names one person.
Audit trail
Plain-language key (allowlist, one-time code, session, watermark, integrity probe)
- Allowlist
- The list of domains and named individuals permitted to open this particular report. It is the only setting that changes from one report to the next.
- One-time code
- Six digits sent to the address being claimed, valid ten minutes, three attempts. It is what turns a claimed identity into a verified one.
- Session
- The short-lived proof that this browser belongs to a verified person. The report is served only on the strength of it — never on the strength of the URL.
- Watermark
- The viewer's verified address and view time, tiled across the page. Forensic, not preventive: it answers "who had this?" after the fact.
- Integrity probe
- A check that the published file still matches the hash registered when it was released. It must be served the raw file — so protection is injected only on the authenticated path, never on the probe.