Most data room leaks are not hacks. Nobody breaks the encryption. Someone on a bidder team forwards a PDF to a colleague who is not under the NDA, or takes a phone photo of a customer list, or a seller accidentally gives round-one bidders the folder meant for the preferred buyer.
That changes how you should evaluate security. Encryption and data centre certifications are important, but in this market they are close to universal. The features that separate a safe process from a messy one sit closer to the user.
Virtual data room security features are the platform controls that decide who can enter the room, what each person can do with each document, and what record is kept of it. Below, each one is mapped to the leak it actually prevents.
What can go wrong in a data room, and what stops it?
Start with threats, then choose controls. This table covers the leak paths we see most often in practice.
| Leak path | How it happens | Control that stops or limits it | Strength |
|---|---|---|---|
| Stolen or shared password | Bidder shares a login with a colleague | Two-factor authentication, single sign-on, IP or device limits | Strong |
| File forwarded outside the deal | Downloaded PDF emailed onward | View-only mode, document rights management with remote revoke | Strong |
| Screenshot or phone photo | Reviewer captures a screen | Dynamic watermark naming viewer and time; screen-capture blocking where offered | Deterrent only |
| Wrong group sees wrong folder | Admin sets permissions too wide | Group-based permissions, permission preview, staged release | Strong if tested |
| Former bidder keeps access | Group not disabled after dropout | One-click group revoke, access expiry dates | Strong |
| Sensitive text left in a document | Unredacted salaries or customer names | Built-in redaction, or redaction before upload | Strong |
| Dispute over what was disclosed | No record of who saw what | Full audit trail with page-level views, exportable archive | Evidentiary |
| Platform breach | Attack on the vendor | Encryption at rest and in transit, ISO 27001 and SOC 2 controls, penetration testing | Vendor-dependent |
Notice that only the last row depends mainly on the vendor’s infrastructure. Everything else depends on features you switch on and configure.
Leak paths and the controls that stop them
Which controls protect the front door?
Access control decides who gets in at all.
Two-factor authentication is the floor. A password alone is not enough for a room holding a company’s crown jewels. Current US federal guidance on digital identity, NIST SP 800-63B, treats multi-factor authentication as the baseline for higher-assurance access, and that is the right mental model for a deal room. Check whether the room can enforce it for every user, not just offer it.
Single sign-on matters when large firms bring dozens of reviewers. It lets a bank or fund authenticate through its own identity provider, so when someone leaves the firm their access goes with them. It is less important for a founder-led sale with five outside users.
Session and access limits, such as expiry dates on an account, IP allow-lists and automatic logout, close the gaps left by people who drift away from a deal.
Which controls protect the document itself?
Once someone is in, the question becomes what they can do with each file.
- Granular permissions. Rights set per group and per folder, ideally per file: hidden, view, print, download original, download protected PDF.
- View-only mode. Documents render in the browser with no download option. This is the single most effective control against onward forwarding.
- Dynamic watermarks. The viewer’s name, email, IP address and timestamp overlaid on every page, generated at view time. They do not stop a photo, but they make it traceable, and reviewers know it.
- Document rights management. Downloaded files stay encrypted and check back with the room before opening. Revoke access and the file stops opening, even on the reviewer’s laptop.
- Redaction. Removing names, figures or clauses before a group sees them. Built-in tools save time and keep the original intact for later waves.
- Fence or spotlight view. Some rooms show only a strip of the page at a time to defeat screen capture. Useful for the most sensitive material, tiresome for everything else.
Which controls give you evidence afterwards?
The audit trail records logins, views, time per page, downloads, prints, Q&A activity and admin changes. It does two jobs. During the deal it shows which bidders are engaged. After signing it is the record of what was disclosed, which matters for warranty claims.
Two questions to ask: can you export the full log, and is it included in the archive you receive at the end? A log you cannot take with you is of limited use in a dispute two years later.
Which providers offer which controls?
Here is how the leading rooms compare on the controls above, using our provider data. A “No” means the feature is not listed for that provider in our data at the time of writing; confirm with the vendor, because products change.
| Control | Ellty | iDeals | Datasite | Intralinks | Firmex | Drooms | Box | DocSend |
|---|---|---|---|---|---|---|---|---|
| Two-factor authentication | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| Single sign-on | No | Yes | Yes | Yes | No | No | Yes | No |
| Dynamic watermarking | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Document rights management | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| Built-in redaction | No | Yes | Yes | Yes | Yes | Yes | No | No |
| Audit trail | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| ISO 27001 | No | Yes | Yes | Yes | Yes | Yes | Yes | No |
| SOC 2 | Infrastructure | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
A pattern is clear. The enterprise deal rooms cover the whole column. General file-sharing tools such as Box are strong on identity and certification but lack document rights management in our data. DocSend is built for tracked sharing of pitch material rather than full diligence. Ellty matches the enterprise rooms on two-factor login, dynamic watermarking, document rights management and the audit trail; in our data it does not offer single sign-on or built-in redaction, and lists SOC 2 at the infrastructure level rather than an ISO 27001 certificate.
For full scoring across all 18 providers, see the rankings or individual reviews.
What do the certifications actually prove?
They prove a vendor’s own security programme was examined by an independent auditor. They do not prove your room is configured well.
ISO/IEC 27001 certifies that an organisation runs an information security management system meeting the standard, within a stated scope. A SOC 2 report from the AICPA framework gives an auditor’s opinion on controls relevant to security and, optionally, availability, confidentiality, processing integrity and privacy. Type I looks at design on a single date; Type II looks at operation over a period.
Two vendors can both say “SOC 2” and mean different things. One report may cover the whole application and its staff; another may cover only the cloud hosting layer underneath. Ask for the report under NDA and read which systems and entities are in scope.
Where personal data is involved, the GDPR asks controllers and processors to apply measures “appropriate to the risk”, naming encryption, confidentiality and regular testing in Article 32. A vendor’s certifications help you show you chose a processor responsibly; your configuration shows the rest.
How do you test security features during a trial?
A trial is the only way to see whether controls work the way the sales deck says. Most providers in our rankings offer one; Ellty’s free trial runs 14 days. Use it like this.
Create two outside groups
Set up Bidder A with view-only rights on one folder and Bidder B with download rights on another. Invite a colleague's personal email to each.
Check what each group sees
Log in as each mock bidder. Confirm that hidden folders are invisible, not just locked, and that the folder count and file names do not leak.
Inspect the watermark
Open a document as Bidder A. Check that the watermark shows the viewer's name and time on every page, and that it survives printing to PDF.
Download, then revoke
As Bidder B, download a protected file. Revoke the group from the admin side and try to reopen the downloaded file. Note what happens.
Force two-factor
Turn on mandatory two-factor and confirm a new user cannot reach any document until it is set up.
Export the audit trail
Pull the activity report. Check it shows views by page and time, downloads and permission changes, and that you can export it in a usable format.
If a vendor does not offer a trial, ask for a sandbox room during the demo and run the same tests with the sales engineer watching.
See how every room scores on security, which counts for 25% of our total, alongside deal features and ease of setup.
Compare the rankingsWhich features are worth paying extra for?
It depends on what is in the room.
- For a seed or Series A raise, two-factor, watermarks and an audit trail are enough. Spend the savings elsewhere.
- For a competitive sale, add view-only mode, rights management and staged permissions. These are the controls that stop a losing bidder walking away with your customer list.
- For a large PE process or regulated target, add single sign-on, built-in redaction and a full SOC 2 Type II report on the application. Your counterparties’ IT teams will ask.
- For healthcare targets in the US, also confirm whether the vendor will sign a HIPAA business associate agreement before any protected health information comes near the room. In our data, Box and Citrix ShareFile list HIPAA among their certifications.
What security mistakes do sellers make most often?
- Giving every bidder the same permission group to save time.
- Leaving download on by default and meaning to change it later.
- Forgetting to disable a group when a bidder drops out.
- Uploading unredacted salary files “just for the advisers”.
- Never exporting the audit trail before the room is closed.
None of these is a platform failure. All of them are avoidable with a few minutes of setup, which our five-day setup guide walks through.
Frequently asked questions
Are virtual data rooms encrypted?
Established providers encrypt data in transit and at rest as standard. Encryption protects against interception and storage breaches; it does not stop an authorised user misusing a document, which is why permissions and watermarks matter.
Can a data room stop screenshots?
Not reliably. Some rooms block screen-capture tools or use a fence view, but a phone camera defeats both. Dynamic watermarks make any captured image traceable to the viewer, which is the practical deterrent.
Is ISO 27001 or SOC 2 more important?
Neither is strictly better. ISO 27001 certifies the management system; a SOC 2 Type II report tests how specific controls operated over time. Many enterprise buyers ask for both. Check the scope of each.
What happens to downloaded files after I revoke access?
It depends. With document rights management, protected files stop opening once access is withdrawn. Without it, a downloaded file is outside your control, so use view-only mode for sensitive folders.
Do I need single sign-on for my data room?
Only if you expect large institutional teams. For founder-led raises and smaller sales, enforced two-factor authentication gives most of the benefit.
