A watermark tells you — and the reader — where a copy came from. A visible one (DRAFT, CONFIDENTIAL, the client’s name across the page) deters casual forwarding; an invisible per-copy mark tells you which copy travelled. Cloaking does something else: it adds hidden text only machines read, so a copy uploaded to an AI tool gives it a noisy, unreliable read while your client sees exactly what you wrote. Neither replaces the other. For a draft going to one person, cloaking alone is usually enough; for a proposal going to a committee you often want all three — and a contract under all of it.
| Method | What it does | Who sees it | What it deters | What defeats it | Effort |
|---|---|---|---|---|---|
| Visible watermark | Prints DRAFT / CONFIDENTIAL / a name behind every page | Everyone | Casual forwarding; a draft passed off as final | Cropping, retyping, a photo; AI extractors read past it | Two clicks in Word |
| Invisible per-copy mark | Tags each copy so you can tell which one travelled | Nobody in normal reading | Nothing up front — attribution afterwards | Retyping; OCR from a photo or scan | Automatic in Sunda Cloak; or a manual version code |
| Cloaking | Adds hidden decoys only machines read; an uploaded copy is a noisy read | Nobody in normal reading; anyone who shows hidden text | Casual, one-click AI ingestion of the file | Copy-paste, screenshots, PDF export, hidden-text-stripping extractors, AI inside the editor | One click per file |
Visible watermarks: for people, not machines
A visible watermark is the oldest tool in the box and still earns its place. In Word it is Design → Watermark: pick DRAFT or CONFIDENTIAL, or type a custom text such as “Prepared for Acme — not for distribution”. Two clicks, no cost.
- Deters casual forwarding. A page stamped with a client’s name is awkward to send on; a DRAFT stamp stops a work-in-progress being quoted as final.
- Sets expectations visibly. Everyone who opens the file sees its status.
What it does not do is anything about AI. It sits behind the page as a graphic or header text; the extractor that feeds an AI tool pulls the body text and carries on. It is also easy to crop out of a screenshot or lose in a retype. A sign on the door, not a lock.
Invisible per-copy marks: knowing which copy travelled
An invisible per-copy mark is watermarking for attribution. It stops nothing; it lets you answer one question afterwards — which copy is this? — so you can talk to the right person rather than everyone.
- The manual way. Send each recipient a slightly different file: a reference code in the footer, a custom watermark text per person. Note who got which. Visible, free, surprisingly effective.
- The automatic way. Sunda Cloak adds an invisible per-copy mark to every cloaked copy, using zero-width characters inside the text rather than anything on the page. Because it lives in the text, it is designed to travel with the visible words when someone copies and pastes them — unlike the cloaking decoys, which Word leaves out of the clipboard. Retyping or OCR removes it, and it occasionally nudges a line or page break, so proofread the cloaked copy like any deliverable.
If you also want to hear when an AI tool looked, the opt-in tripwire adds one hidden reference link per copy. It fires only if a tool actually follows that link, and many never do — a hit is a clear signal, silence is no information. More in Can you tell if someone used AI on your document?
Cloaking: making the file a poor input
Cloaking is the newer job: it changes what an AI tool gets when someone drags the file in. Sunda Cloak makes a copy of your .docx, .odt or .rtf on your own device and adds hidden text only machines read: around a dozen look-alike decoy values beside each real figure, URL, email and name; whole decoy paragraphs that some extractors prefer over the content Word shows; and hidden steering notes. Nothing is removed or masked — the real words stay byte-perfect — and the visible page is unchanged. How the protection works goes through each layer and what gets through anyway.
The honest shape of it: cloaking protects one path — the file itself uploaded into an AI tool whose reader ingests hidden text. Readers that strip hidden text recover the original, leaving fragmented, less trustworthy facts rather than absence. Copy-paste out of Word, screenshots and vision models, a PDF export (which drops hidden text) and an AI inside the editor bypass it entirely. It raises the cost of a casual “summarise this and do the same for our other region”; it is not a complete defense.
Hidden is not secret. A recipient who turns on Word’s formatting marks or “show hidden text” will see the decoys and can delete them. One more reason to tell your client the file is protected; it reads as a professional norm, like watermarked design comps.
Which one, when
- Wide circulation (board packs, a report for a whole team). Visible watermark with the client’s name and the status. You want everyone to see it.
- Attribution (several recipients; you want to know which copy moved). A per-copy mark — a manual version code, or Sunda Cloak’s automatic invisible one. Add the tripwire for a chance of hearing about AI use.
- Methodology and drafts (your frameworks, your working, early versions). Cloak the outgoing copy; this is where a one-click “turn this into a template” hurts most. See protecting your methodology as a consultant.
- Proposals before a contract is signed. All three: a visible watermark so it cannot be quoted as a finished deliverable, a per-copy mark so you know whose copy travelled, and cloaking so a quick upload to compare bids is a noisy read. See sending a proposal before the contract is signed.
Order of operations: watermark in Word first, then cloak the finished file — cloaking keeps the formatting, watermark included. Keep your master uncloaked; cloak the copy that leaves.
What none of these does
- A visible watermark does nothing against AI tools; extractors read the body text and move on. It is for people.
- A per-copy mark only tells you which copy travelled, after the fact. It prevents nothing, and retyping or OCR removes it.
- Cloaking is defeated by copy-paste out of Word, screenshots, PDF export, extractors that strip hidden text, and AI inside the editor. A determined person with the file has your text.
- How well cloaking works depends on how a given AI tool reads files, and providers change their pipelines; expect months, not years, from any technique. The tripwire fires only when a tool actually follows the hidden link; silence proves nothing.
- All of it is a deterrent against casual AI reuse — not a guarantee, and never a substitute for a contract.
Frequently asked
No. A visible watermark is a picture or text laid over the page; the extractor that feeds an AI tool pulls out the body text and carries on. A watermark is for people — it tells them where the copy came from. Making the file a poor input for an AI tool is a different job, and that is what cloaking is for.
Yes. In Word, go to Design → Watermark and pick DRAFT or CONFIDENTIAL, or choose Custom Watermark and type your own text — the client's name, a date, or a short reference code. A slightly different custom text per recipient gives you a simple, free per-copy mark that anyone can see.
Not a visible one. Sunda Cloak adds an invisible per-copy mark to every cloaked copy, and, if you turn the tripwire on, one hidden reference link per copy. If you want a visible watermark as well, use Word's Design → Watermark on the file before you cloak it — the two sit happily together.
A visible watermark does not — it sits behind the page, not in the text, so it is not on the clipboard. Sunda Cloak's invisible per-copy mark is designed to travel with the visible text when it is copied and pasted, which is what makes it useful for attribution. The cloaking decoys do not: Word leaves hidden text out of the clipboard, so a copy-paste into a chat window is clean text.