Trust & security
The security you can verify, stated plainly.
Most data-room trust pages are a wall of badges. This one is written for the person who actually reviews vendors: it names the mechanisms that are built and running, and it’s honest about the certifications that are not here yet.
What is built
Real mechanisms, in the product today
Each of these runs in the code, not in a roadmap slide.
Forensic watermarking
Every page in the viewer is stamped with the viewer’s email, IP address, and a timestamp. A second, sub-pixel layer encodes the session so a cropped or rotated screenshot still traces back to a person.
In-browser viewer · no local file handoff
Page-level audit
The audit records the pages a user actually reads — gated on genuine on-screen visibility, not merely loaded into the viewer. Views, searches, downloads, and questions are written append-only and can be exported.
Append-only · exportable
Permission trimming
Bidder groups get their own view of the tree, down to the individual document. The same filter runs before search results return and before any document reaches the assistant — so nothing leaks a file a user can’t open.
Enforced before content is served
Mandatory two-factor
There is no open sign-up — accounts are created by the deal team’s administrators, and a second factor is required at sign-in, not an optional setting an administrator can leave off.
Admin-provisioned · 2FA required
Encrypted storage
Documents and metadata are encrypted at rest and in transit on AWS infrastructure. Residency routing keeps a region’s documents, indexes, backups, and AI inference inside that region for the regions we run.
AWS · region-scoped
AI that stays inside the room
Document content is never sent to shared or public model endpoints and is never used to train a vendor’s model. The assistant only sees what a user is already permitted to see, and cites what it reads.
No training · citation-grounded
Being straight with you
Mechanisms are not the same as certifications
A control that runs in production and a third-party attestation that it runs are different things. We won’t blur them. Here is exactly where the formal side stands.
Reviewing us for a deal? We share our current control status, infrastructure-provider reports, and pentest posture under NDA on request.
DataRooms.com has not completed its own SOC 2 audit. Formal certification is in motion, and we’ll date it here when the report exists rather than imply it early.
DataRooms.com does not present a product-level ISO certificate. Our infrastructure providers hold their own attestations; those are provider evidence, not a DataRooms certification.
Support for protected health information is off. It stays off until the provider and customer agreements, logging, and incident procedures behind it are in place.
Independent penetration testing is scheduled. When it completes, the findings and remediation evidence go to reviewers under NDA — they will not be summarized into a marketing claim here.