Guide
Data room security: permissions, watermarking, certifications
Updated
Every provider in this market says it is secure. The useful questions are which controls are in the product, which certification is claimed, and whose certificate it is.
Permissions: down to what level?
The phrase "granular permissions" covers a wide range. Firmex describes control "from site, to project, down to the folder, and even document level". Virtual Vaults publishes permissions to document level, buyer groups and roles, and clean team and non-clean team separation, which matters in a competitor sale. Drooms describes setting permissions down to document level to edit or view. Datasite describes staged disclosure logic with permissions applied per buyer, and AI responses scoped to each buyer's access level. Ask to see the permission matrix on a demo, not the marketing sentence.
Watermarking, and who names it
- Dynamic or custom watermarks stated: CapLinked (custom dynamic watermarks), Ideals (dynamic customisable watermarks), Ansarada (custom watermarks, download blocking, per-document expiry), Onehub (document watermarks on the Data Room Edition), SecureDocs (watermarking, disableable per role by an administrator).
- Not named on the pages we read: Virtual Vaults, Firmex, DealRoom and Datasite. Firmex instead describes digital rights management that disables save, print, copy and share, document lock-down to a specific IP and computer, remote revocation and document expiry, which addresses the same risk differently.
- The point of a watermark is attribution after a leak, not prevention. A dynamic watermark carrying the viewer's identity and timestamp is what makes a screenshot traceable. A static logo does not.
Certifications, as stated by each provider
| Provider | Certifications stated on the page we read |
|---|---|
| Admincontrol | ISO 27001, SOC 2 Type II, GDPR, Cyber Essentials Plus, G-Cloud 14 |
| Ideals | SOC 1/2/3, ISO 27001, GDPR, HIPAA, PCI DSS |
| Drooms | ISO 27001 and ISO 27018, TUV certified, GDPR |
| Virtual Vaults | ISO 27001:2022 certified, GDPR compliant |
| Ansarada | ISO 27001 certified, GDPR compliant |
| CapLinked | SOC 2 / SSAE 18 Type II, 256-bit encryption at rest and in transit |
| Firmex | SOC 2 Type 2 (security, availability, confidentiality), HIPAA certificate, annual penetration testing |
| SecureDocs | SOC 2 Type 2 audit; its AWS data centres are ISO 27001 certified |
| DealRoom | SOC 2 compliance, described as SOC 2 Type 2 |
| Datasite Diligence | ISO/IEC 42001 for AI governance; ISO 27001 and SOC 2 not stated on this page |
| Onehub | None named; the pricing page says "Enterprise-Grade Security" |
This table records what each provider states, not what we have verified. Certification claims can and should be checked: ask for the certificate, the scope statement and the issuing body, and for a SOC 2 report ask whether it is Type 1 or Type 2 and what period it covers.
Three ways a certification claim can mislead
- It is the host's, not the provider's. SecureDocs is straightforward about this, noting that AWS data centres are ISO 27001 certified. That is AWS's certification. It says nothing about the application sitting on top.
- The scope is narrow. An ISO 27001 certificate applies to a defined scope. A certificate covering a head office and not the product is worth reading carefully.
- Compliant is not certified. "SOC 2 compliance" and "a completed SOC 2 Type 2 audit" are different statements. Firmex's wording is the clearest here: audited annually against the security, availability and confidentiality trust services criteria.
Where the data sits
For a UK or European deal this can matter more than the certificate. SecureDocs states its AWS data centres are in the United States, Ireland and Germany, and that you can choose US or European hosting. Virtual Vaults publishes a choice of storage location as a plan feature. Drooms describes itself as made in Germany with data sovereignty as a selling point. Admincontrol states Cyber Essentials Plus and G-Cloud 14, both UK schemes. If your deal involves regulated data or a public sector counterparty, ask where the data rests, not just how it is encrypted.