Guide

Watermarking vs cloaking documents

Two different jobs that get lumped together. A watermark says where a copy came from; cloaking makes the copy a poor input for an AI tool. Here is what each one does, what defeats it, and when you want both.

7 min read Updated 22 August 2026
Short answer

A watermark tells you — and the reader — where a copy came from. A visible one (DRAFT, CONFIDENTIAL, the client’s name across the page) deters casual forwarding; an invisible per-copy mark tells you which copy travelled. Cloaking does something else: it adds hidden text only machines read, so a copy uploaded to an AI tool gives it a noisy, unreliable read while your client sees exactly what you wrote. Neither replaces the other. For a draft going to one person, cloaking alone is usually enough; for a proposal going to a committee you often want all three — and a contract under all of it.

Method What it does Who sees it What it deters What defeats it Effort
Visible watermark Prints DRAFT / CONFIDENTIAL / a name behind every page Everyone Casual forwarding; a draft passed off as final Cropping, retyping, a photo; AI extractors read past it Two clicks in Word
Invisible per-copy mark Tags each copy so you can tell which one travelled Nobody in normal reading Nothing up front — attribution afterwards Retyping; OCR from a photo or scan Automatic in Sunda Cloak; or a manual version code
Cloaking Adds hidden decoys only machines read; an uploaded copy is a noisy read Nobody in normal reading; anyone who shows hidden text Casual, one-click AI ingestion of the file Copy-paste, screenshots, PDF export, hidden-text-stripping extractors, AI inside the editor One click per file

Visible watermarks: for people, not machines

A visible watermark is the oldest tool in the box and still earns its place. In Word it is Design → Watermark: pick DRAFT or CONFIDENTIAL, or type a custom text such as “Prepared for Acme — not for distribution”. Two clicks, no cost.

What it does not do is anything about AI. It sits behind the page as a graphic or header text; the extractor that feeds an AI tool pulls the body text and carries on. It is also easy to crop out of a screenshot or lose in a retype. A sign on the door, not a lock.

Invisible per-copy marks: knowing which copy travelled

An invisible per-copy mark is watermarking for attribution. It stops nothing; it lets you answer one question afterwards — which copy is this? — so you can talk to the right person rather than everyone.

If you also want to hear when an AI tool looked, the opt-in tripwire adds one hidden reference link per copy. It fires only if a tool actually follows that link, and many never do — a hit is a clear signal, silence is no information. More in Can you tell if someone used AI on your document?

Cloaking: making the file a poor input

Cloaking is the newer job: it changes what an AI tool gets when someone drags the file in. Sunda Cloak makes a copy of your .docx, .odt or .rtf on your own device and adds hidden text only machines read: around a dozen look-alike decoy values beside each real figure, URL, email and name; whole decoy paragraphs that some extractors prefer over the content Word shows; and hidden steering notes. Nothing is removed or masked — the real words stay byte-perfect — and the visible page is unchanged. How the protection works goes through each layer and what gets through anyway.

The honest shape of it: cloaking protects one path — the file itself uploaded into an AI tool whose reader ingests hidden text. Readers that strip hidden text recover the original, leaving fragmented, less trustworthy facts rather than absence. Copy-paste out of Word, screenshots and vision models, a PDF export (which drops hidden text) and an AI inside the editor bypass it entirely. It raises the cost of a casual “summarise this and do the same for our other region”; it is not a complete defense.

Worth knowing

Hidden is not secret. A recipient who turns on Word’s formatting marks or “show hidden text” will see the decoys and can delete them. One more reason to tell your client the file is protected; it reads as a professional norm, like watermarked design comps.

Which one, when

  1. Wide circulation (board packs, a report for a whole team). Visible watermark with the client’s name and the status. You want everyone to see it.
  2. Attribution (several recipients; you want to know which copy moved). A per-copy mark — a manual version code, or Sunda Cloak’s automatic invisible one. Add the tripwire for a chance of hearing about AI use.
  3. Methodology and drafts (your frameworks, your working, early versions). Cloak the outgoing copy; this is where a one-click “turn this into a template” hurts most. See protecting your methodology as a consultant.
  4. Proposals before a contract is signed. All three: a visible watermark so it cannot be quoted as a finished deliverable, a per-copy mark so you know whose copy travelled, and cloaking so a quick upload to compare bids is a noisy read. See sending a proposal before the contract is signed.

Order of operations: watermark in Word first, then cloak the finished file — cloaking keeps the formatting, watermark included. Keep your master uncloaked; cloak the copy that leaves.

Honest limits

What none of these does

  • A visible watermark does nothing against AI tools; extractors read the body text and move on. It is for people.
  • A per-copy mark only tells you which copy travelled, after the fact. It prevents nothing, and retyping or OCR removes it.
  • Cloaking is defeated by copy-paste out of Word, screenshots, PDF export, extractors that strip hidden text, and AI inside the editor. A determined person with the file has your text.
  • How well cloaking works depends on how a given AI tool reads files, and providers change their pipelines; expect months, not years, from any technique. The tripwire fires only when a tool actually follows the hidden link; silence proves nothing.
  • All of it is a deterrent against casual AI reuse — not a guarantee, and never a substitute for a contract.

Frequently asked

No. A visible watermark is a picture or text laid over the page; the extractor that feeds an AI tool pulls out the body text and carries on. A watermark is for people — it tells them where the copy came from. Making the file a poor input for an AI tool is a different job, and that is what cloaking is for.

Yes. In Word, go to Design → Watermark and pick DRAFT or CONFIDENTIAL, or choose Custom Watermark and type your own text — the client's name, a date, or a short reference code. A slightly different custom text per recipient gives you a simple, free per-copy mark that anyone can see.

Not a visible one. Sunda Cloak adds an invisible per-copy mark to every cloaked copy, and, if you turn the tripwire on, one hidden reference link per copy. If you want a visible watermark as well, use Word's Design → Watermark on the file before you cloak it — the two sit happily together.

A visible watermark does not — it sits behind the page, not in the text, so it is not on the clipboard. Sunda Cloak's invisible per-copy mark is designed to travel with the visible text when it is copied and pasted, which is what makes it useful for attribution. The cloaking decoys do not: Word leaves hidden text out of the clipboard, so a copy-paste into a chat window is clean text.