Trust & security

The security you can verify, stated plainly.

Most data-room trust pages are a wall of badges. This one is written for the person who actually reviews vendors: it names the mechanisms that are built and running, and it’s honest about the certifications that are not here yet.

What is built

Real mechanisms, in the product today

Each of these runs in the code, not in a roadmap slide.

Forensic watermarking

Every page in the viewer is stamped with the viewer’s email, IP address, and a timestamp. A second, sub-pixel layer encodes the session so a cropped or rotated screenshot still traces back to a person.

In-browser viewer · no local file handoff

Page-level audit

The audit records the pages a user actually reads — gated on genuine on-screen visibility, not merely loaded into the viewer. Views, searches, downloads, and questions are written append-only and can be exported.

Append-only · exportable

Permission trimming

Bidder groups get their own view of the tree, down to the individual document. The same filter runs before search results return and before any document reaches the assistant — so nothing leaks a file a user can’t open.

Enforced before content is served

Mandatory two-factor

There is no open sign-up — accounts are created by the deal team’s administrators, and a second factor is required at sign-in, not an optional setting an administrator can leave off.

Admin-provisioned · 2FA required

Encrypted storage

Documents and metadata are encrypted at rest and in transit on AWS infrastructure. Residency routing keeps a region’s documents, indexes, backups, and AI inference inside that region for the regions we run.

AWS · region-scoped

AI that stays inside the room

Document content is never sent to shared or public model endpoints and is never used to train a vendor’s model. The assistant only sees what a user is already permitted to see, and cites what it reads.

No training · citation-grounded

Being straight with you

Mechanisms are not the same as certifications

A control that runs in production and a third-party attestation that it runs are different things. We won’t blur them. Here is exactly where the formal side stands.

Start a free trialSee plans & pricing

Reviewing us for a deal? We share our current control status, infrastructure-provider reports, and pentest posture under NDA on request.

On the roadmap

DataRooms.com has not completed its own SOC 2 audit. Formal certification is in motion, and we’ll date it here when the report exists rather than imply it early.

On the roadmap

DataRooms.com does not present a product-level ISO certificate. Our infrastructure providers hold their own attestations; those are provider evidence, not a DataRooms certification.

Not enabled

Support for protected health information is off. It stays off until the provider and customer agreements, logging, and incident procedures behind it are in place.

Shared under NDA

Independent penetration testing is scheduled. When it completes, the findings and remediation evidence go to reviewers under NDA — they will not be summarized into a marketing claim here.