Small businesses handle more sensitive information than they sometimes realise: customer exports, pricing, payroll reports, proposals, supplier terms, investor updates and internal dashboards. The company may have only a few people, but the information still moves through employees, contractors, clients and professional advisers.

A useful sharing plan does not need to become a fifty-page policy. It needs to help people make consistent decisions before information leaves.

Start with three simple categories

Create categories that ordinary colleagues can actually use:

Internal: routine information intended for the team but unlikely to cause meaningful harm if forwarded.

Confidential: customer, employee, commercial or operational information that should go only to named people.

Restricted: particularly sensitive information such as credentials, pre-announcement figures, legal strategy or high-risk personal data.

The labels matter less than agreement about what they mean. Give real examples from your own business.

Decide how each category may be shared

Internal information may be acceptable in the normal company workspace. Confidential files might require named recipients, recipient-linked copies and a clear retention period. Restricted data may need a controlled portal, approval before export and a prohibition on ordinary email attachments.

ExactMark adds accountability to two common routes:

  • The SDK protects signed-in pages inside a private Web App and links Web Sessions to known users.
  • ExactMark Imprint creates a separate, recipient-linked image or PDF for each person receiving a file.

Neither replaces encryption, authentication, backups or staff training. They provide evidence for the point where authorised access becomes a screenshot or shared copy.

Give ownership to a real person

Someone should own the sharing rules, even if security is not their full-time job. In a small company this may be the founder, operations lead or technical owner.

That person should know:

  • Which Web Apps contain sensitive information.
  • Who can create recipient-linked copies.
  • Who may upload and review evidence.
  • How access is removed when someone changes role or leaves.
  • Who needs to be contacted if information surfaces.

Use workspace roles so colleagues receive only the tools necessary for their job. A developer setting up the SDK does not automatically need access to evidence or recipient records.

Make individual distribution the default

Group attachments are convenient but poor for attribution. Where a document is sensitive enough to protect, generate one Imprint copy for each recipient and send it individually.

Use real recipient names, keep email details accurate and avoid vague records such as “Client copy”. If a recipient forwards their copy internally with permission, decide whether the additional person should instead receive a newly generated copy.

Plan the first hour after a leak

Write a short response checklist before it is needed:

  1. Preserve the surfaced file, image, URL and surrounding context.
  2. Stop further public access without destroying evidence.
  3. Submit the best available artifact to Evidence Lab.
  4. Review confidence and candidate information.
  5. Compare the result with login or distribution records.
  6. Escalate to the appropriate legal, privacy, security or client contact.
  7. Record decisions and avoid premature accusations.

A calm checklist is far more useful than inventing a process while the business is under pressure.

Review the plan quarterly

New tools, clients and hires change how information moves. Once every few months, check active users, Web Apps, recipient records, retention choices and recent incidents. Test one controlled screenshot and one Imprint copy so you know the workflow still works.

The objective is not to make everyday work frightening or bureaucratic. It is to make deliberate sharing easy and anonymous leakage harder. For a small business, a few clear rules applied consistently are more valuable than an impressive policy nobody follows.