There is a particular kind of frustration that belongs to experienced freelancers. Your best six projects are the ones you cannot show. The enterprise design system, the internal tool that saved a client two headcount, the ghostwritten book with someone else's name on it, the payments flow you rebuilt for a bank. What remains publishable is the early, small, slightly embarrassing work — and so your portfolio quietly represents you as a weaker professional than you are. This guide is the practical version of the answer. Not a plugin tutorial, and not a shrug. There is a lot you can almost always describe under a strict confidentiality agreement, there is a way of writing it that persuades a buyer, and there are a few things you should never publish regardless of how much you want the next job. A plain note before anything else. We are not lawyers and none of this is legal advice. Confidentiality agreements differ enormously — in what they cover, how long they last, and whether they allow anything at all to be described publicly. The only document that tells you what your obligations are is the one you signed, so read it, and get proper advice when the work or the client is significant. Everything below is about how to present work responsibly, not a claim about what any particular agreement permits. NDAs are the normal case, not a special problem It helps to stop treating confidentiality as an unlucky exception. Once you work above a certain level, almost everything is covered by something. Agencies pass client NDAs down to subcontractors. Enterprises have a standard mutual agreement that gets signed before the kickoff call. Startups ask for one because their investors told them to. Ghostwriting is confidential by definition. Which means the person reading your portfolio is very likely working under the same constraints. Hiring managers at large companies, agency principals, and founders who have raised money all recognise a redacted case study on sight, because their own teams produce them. A page that says "client name withheld" reads as normal professional behaviour, not as evasion. What does read badly is the absence of anything. A portfolio with three thin projects and a vague line about "extensive enterprise experience" asks the reader to take a great deal on faith. The goal is not to break your agreement. It is to stop letting it make you invisible. Confidentiality, non-disclosure and plain client discretion are three different things People use "NDA" as shorthand for all of them, and the differences matter when you are deciding what to publish. A signed non-disclosure agreement is a contract. It defines confidential information, says what you may do with it, and usually survives the end of the project by a stated number of years. Read the definition clause first — it is the part that decides whether the existence of the relationship is itself confidential, which is the single most important question for your portfolio. A confidentiality clause inside a services contract does the same work in fewer words, and is much more common than a standalone NDA. If you have ever signed a client's master services agreement, you have almost certainly agreed to one. Our guide to freelance contract essentials covers where it usually sits and what a portfolio-rights clause should say alongside it. Then there is information protected whether or not you signed anything. Trade secret law exists independently of contracts: under US federal law, a trade secret is information whose owner has "taken reasonable measures to keep such information secret" and which "derives independent economic value" from not being generally known (18 U.S.C. § 1839). Unreleased products, pricing models and internal metrics can fall in that category without a single document changing hands. And finally there is client discretion — no legal obligation at all, just a client who would rather you did not broadcast that they outsourced this. That is a relationship question, not a legal one, and it is usually solved by asking. What you can almost always describe Here is the reframe that makes the rest of this workable. Most confidentiality agreements are written to protect the client's information: their data, their plans, their unreleased work, their customers. Very few of them are written to protect your professional history, your methods, or your judgement — and those are the things a prospective client is actually buying. A rough map, not a ruling. Your own agreement is the only thing that decides which side each row falls on. Your role and the shape of the engagement are yours. "Sole product designer on a six-month engagement, reporting to the Head of Product" describes your working life, not the client's secrets. So is your process: how you run discovery, how many rounds of testing you do, how you hand off to engineers. Buyers care about this more than you think, because it tells them what working with you will feel like. The class of problem is nearly always describable too. "Users were abandoning a regulated identity check partway through" says something real without exposing a single number or screen. Outcomes can often survive as relative figures — "roughly a third fewer drop-offs" — where the absolute numbers would be off-limits. If in doubt, describe the direction and drop the magnitude. Writing a redacted case study that still persuades The mistake is writing the redacted version as a shorter, sadder version of the real one. It should be a different document with a different centre of gravity: the specifics move from what was built to how you worked. The same six parts as any case study, with the identifying detail removed from each and nothing else thinned out. Notice what is missing from that structure: images. Visual work under NDA is the hardest case, because a screenshot leaks everything at once. Blurring is not redaction — it is often reversible in spirit, since layout, product surface and brand are still legible. Better to show nothing than to show something you would have to defend. What you can show instead is process artefact you own and can genuinely abstract: a journey map with the client's labels replaced, a wireframe redrawn at low fidelity, a diagram of the system's shape with proprietary components named generically. Redraw rather than blur, and only when you are confident the redraw carries no confidential detail. The rest of the writing rules are the ordinary ones — the structure in our guide to writing a portfolio case study applies unchanged. Problem, constraint, what you did, what happened. Redaction removes nouns; it does not excuse you from having a narrative. Anonymising a client without sounding fictional "A big client in the finance sector" is worse than useless. It is the sentence someone writes when they have nothing, and readers know it. Anonymity is only credible when it is specific about everything except identity. Replace the name with a description that a knowledgeable reader could place. "A Series B fintech with about forty staff, operating in three European markets." "A NHS trust's outpatient booking team." "A US logistics company doing roughly nine figures in annual revenue." Each of those tells a prospect whether you have worked at their scale, which is the actual question behind "who have you worked with". Three details usually do it: sector, stage or size, and the constraint that made the work hard. Regulation, legacy systems, a distributed team across five time zones, a hard external deadline. Constraints are rarely confidential and they are the most persuasive thing on the page, because they are what your prospective client is worried about. Say plainly why the name is missing — one clause, no apology. "Client name withheld under NDA." Readers fill silence with the least flattering explanation available, and the least flattering explanation for a nameless project is that you are inflating your involvement. One caution: check whether the combination is identifying. "A Series B fintech" is safe; "the only UK Series B fintech doing cross-border payroll, 2025" names them as surely as a logo would. Asking for permission properly, and exactly what to ask for Most freelancers never ask, and assume the answer is no. In our experience it is often yes, in a narrower form than you hoped and a more useful form than you expected — but only when the request is small, specific and easy to approve. Ask the person who can actually say yes. That is usually your day-to-day contact's manager, or for larger organisations, someone in marketing or legal. Ask at the right moment too: the week after a successful launch, when the client is pleased and the work is fresh, not eighteen months later out of nowhere. Ask for one of these, in descending order of what you would like and ascending order of how likely you are to get it: Named credit with images. The full case study, client named, screenshots included. Named credit, no images. You may say you worked with them and describe the work in words. Logo on a client strip only. Their mark on your site, no project detail attached. Anonymous case study with approved wording. They review the text; the name stays out. A testimonial instead. A quote with a name and title attached to it, which is often easier for a client to approve than a case study, and sometimes carries more weight. Put the request in writing, offer to send the exact wording for approval before publishing, and give them a way to say a partial yes. Then keep the approval email — that is your record. The same approach that works for asking clients for testimonials works here: make it a two-minute decision rather than a project. Better still, handle it before the work starts. A portfolio-rights clause in your own contract — "the supplier may describe the engagement in general terms in its portfolio, subject to the client's prior written approval of the wording" — turns an awkward later request into a routine one. Share-on-request, and its honest downsides The standard advice is to put the sensitive work behind a password. It is worth being clear-eyed about what a gate actually achieves. The realistic options are all variations on one idea: the public page describes the work, and the detail goes to named individuals on request. A PDF you send by email after a short conversation. A private link to a document you can revoke. A slide deck you walk someone through on a call and do not leave behind. A line on your contact form that says more detail is available to serious enquiries. Their downsides are real. Every gate adds friction at exactly the moment someone was interested, and a proportion of people will simply not bother. Gated pages also do nothing for you in search. And — this is the part the plugin tutorials skip — a password does not make sharing lawful. If your agreement prohibits disclosure, giving the password to a stranger who emailed you is still disclosure. A gate controls who sees the material; it does not change what you were permitted to show. Where it genuinely helps is control: you know who asked, you can decline, and you can tailor what you send. For a walkthrough on a call, it is often the best answer available. Bunfolio does not offer password-protected pages or private links, so if you want a gate you will be sending files or links yourself. Our own view is that most freelancers are better served by a strong public redacted case study plus a "detail on request" line, rather than by a locked page nobody knocks on. What never goes in, no matter how good the work was A short list, and it is short on purpose. These are the ones where the potential loss is not proportionate to the gain. Anything with real customer or user data in it. Screenshots of production dashboards, exported spreadsheets, session recordings, support tickets. Even with names blurred, this is other people's personal information and it is not yours to publish. Unreleased products, features or branding. Publishing a launch before the client does can cause commercial damage measured in a great deal more than your fee. Internal documents. Strategy decks, research reports, roadmaps, pricing models, board material — regardless of whether you wrote them. Credentials and infrastructure detail. Environment names, endpoints, architecture diagrams with real hostnames, anything in a screenshot's address bar. Named clients who have said no. Once you have asked and been declined, publishing anyway ends the relationship and your referrals from it. Ghostwritten work attributed to yourself. If the deal was that the byline is theirs, the byline is theirs — describe the engagement, not the piece. The test we use: if the client's legal team saw this page, would they be annoyed, or would they be alarmed? Annoyed is a conversation. Alarmed is the end of your work in that sector, because the people who hire freelancers for confidential work all talk to each other. What confidentiality costs you in search, and how to make it up Be honest about the trade-off. Case studies naming real companies and real products attract search traffic; "a Series B fintech" does not rank for anything. Gated material is worse still — content behind a login or sent as a PDF contributes nothing to your site's visibility, and if you block a page in robots.txt you cannot even reliably keep it out of the index, because Google's crawler never sees the noindex rule it needs to obey (Google Search Central). So build your visibility on the parts that are not confidential. Write about your methods and the problem space: how you run a discovery sprint for a regulated product, what breaks in enterprise design systems, how to write a technical spec someone will actually read. This material ranks, demonstrates judgement, and contains nobody's secrets. Our portfolio SEO guide covers the mechanics. Then lean on the proof that survives redaction. Testimonials with real names and titles. A logo strip, if permitted. Speaking, open-source work, published writing, community answers. Referrals matter disproportionately in confidential fields, precisely because the public evidence is thin — which is another way of saying your existing clients are your distribution. And keep the redacted pages themselves indexable. There is no reason a page about your process should be hidden because the project behind it is. A template for an NDA-safe project entry Here is a complete invented example you can copy the shape of. The client, the numbers and the wording are all fictional — do not reuse the figures. Reducing abandonment in a regulated onboarding flow Client: A Series B fintech, approximately 40 staff, operating in three European markets. Name withheld under NDA. Role: Sole product designer, six-month engagement, 2025. Reported to the Head of Product; worked alongside two engineers and a compliance lead. The problem. New customers had to pass an identity check before they could move money. A large share of them started the check and never finished it, and the team could see where people stopped but not why. What I did. Twelve interviews with recently signed-up customers and four with the support team. Mapped the flow against the compliance requirements to separate what was legally required from what had accumulated. Two rounds of prototypes, tested with eight participants each, then a phased rollout behind a flag. Constraints. Every screen change needed compliance sign-off, and the underlying verification vendor could not be replaced within the timeline. Outcome. Completion of the check improved by roughly a third over the eight weeks after launch, and support contacts about verification fell noticeably. Detail available on request, with the client's permission. Reference: Available on request. Four or five entries at this quality will do more for you than a dozen thin ones — the same principle as choosing how many projects to put on a portfolio website. If you are a designer, our UX designer portfolio guide goes deeper into the narrative structure this shape rests on. On tooling: entries like this are plain text, which is the point. In Bunfolio they live in the Case Studies manager and render into the Portfolio section of your site, but the format does not depend on us — it works in a PDF, a Notion page or anything else. Frequently asked questions Can I show client work under NDA if I remove the logo and change the colours? Usually not, and this is the most common mistake. Recolouring a screenshot does not anonymise it — layout, copy, product surface and unreleased features all remain visible to anyone who knows the sector. Describe the work in words instead, or redraw an abstracted diagram you are confident carries nothing confidential. Does an NDA expire? Many have a stated term, often a few years after the engagement ends, and some are perpetual for defined categories of information. Trade secrets can be protected for as long as they stay secret. Read your agreement, and if it has genuinely expired, ask the client anyway before publishing — the relationship outlives the clause. Should I write "NDA" on the page at all? Yes, once, briefly. "Client name withheld under NDA" costs you five words and prevents the reader assuming the project is exaggerated or invented. What does not work is a portfolio where every entry is a mystery and the explanation is repeated six times. Is it safe to show the real work in an interview or on a screen share? That depends entirely on your agreement, and plenty of them prohibit exactly this. A private setting is not an exception written into the contract. If a prospective client asks to see confidential material, the professional answer — "I can't show you that one, but I can walk you through how I approached it" — tends to reassure rather than disappoint, because it tells them you will treat their work the same way. My whole portfolio would be redacted. Is that survivable? It is common in enterprise and ghostwriting work. Compensate with the things that are not confidential: testimonials with real names, a clear description of your process, public writing about your field, and a personal project or two you own outright. If you are starting from very little, our guide to getting your first freelance clients covers building evidence from scratch. Can I present the work as a "concept" or "unsolicited redesign" instead? Only if it genuinely is one — built independently, from public information, with no confidential material behind it. Passing off real client work as a concept is worse than staying quiet: it is a disclosure with a false label on it, and it misrepresents your involvement at the same time. How we put this guide together To repeat the point at the top: we are not lawyers and this is not legal advice. Nothing here describes what your agreement permits, because we have not read it and only you can. Where confidentiality obligations are involved, the sensible order is to read the document, then ask the client, then publish — not the other way round. Two claims in this piece are sourced rather than asserted. The definition of a trade secret as information kept secret by reasonable measures and deriving independent economic value from that secrecy is the US federal definition at 18 U.S.C. § 1839. The point that a noindex rule cannot work on a page blocked in robots.txt — because the crawler never reads the rule — comes from Google Search Central's documentation. Everything else is our judgement, formed from working with freelancers building portfolios on Bunfolio and from the patterns we see in what does and does not persuade buyers: the six-part redacted structure, the permission ladder, the "sector, stage, constraint" rule for anonymising a client, and the recommendation to favour a public redacted case study over a gated page. We have deliberately not quoted a statistic about how many freelance projects fall under NDA, because we could not find a figure traceable to a primary source, and an invented one would be worth less than saying so. Every example in this guide — the fintech, the onboarding flow, the improvement figures, the redacted copy — is invented for illustration. Related reading: how to write a portfolio case study, freelance contract essentials, and how to ask clients for testimonials.