Guide

Data room security: permissions, watermarking, certifications

Updated

Every provider in this market says it is secure. The useful questions are which controls are in the product, which certification is claimed, and whose certificate it is.

Permissions: down to what level?

The phrase "granular permissions" covers a wide range. Firmex describes control "from site, to project, down to the folder, and even document level". Virtual Vaults publishes permissions to document level, buyer groups and roles, and clean team and non-clean team separation, which matters in a competitor sale. Drooms describes setting permissions down to document level to edit or view. Datasite describes staged disclosure logic with permissions applied per buyer, and AI responses scoped to each buyer's access level. Ask to see the permission matrix on a demo, not the marketing sentence.

Watermarking, and who names it

  • Dynamic or custom watermarks stated: CapLinked (custom dynamic watermarks), Ideals (dynamic customisable watermarks), Ansarada (custom watermarks, download blocking, per-document expiry), Onehub (document watermarks on the Data Room Edition), SecureDocs (watermarking, disableable per role by an administrator).
  • Not named on the pages we read: Virtual Vaults, Firmex, DealRoom and Datasite. Firmex instead describes digital rights management that disables save, print, copy and share, document lock-down to a specific IP and computer, remote revocation and document expiry, which addresses the same risk differently.
  • The point of a watermark is attribution after a leak, not prevention. A dynamic watermark carrying the viewer's identity and timestamp is what makes a screenshot traceable. A static logo does not.

Certifications, as stated by each provider

ProviderCertifications stated on the page we read
AdmincontrolISO 27001, SOC 2 Type II, GDPR, Cyber Essentials Plus, G-Cloud 14
IdealsSOC 1/2/3, ISO 27001, GDPR, HIPAA, PCI DSS
DroomsISO 27001 and ISO 27018, TUV certified, GDPR
Virtual VaultsISO 27001:2022 certified, GDPR compliant
AnsaradaISO 27001 certified, GDPR compliant
CapLinkedSOC 2 / SSAE 18 Type II, 256-bit encryption at rest and in transit
FirmexSOC 2 Type 2 (security, availability, confidentiality), HIPAA certificate, annual penetration testing
SecureDocsSOC 2 Type 2 audit; its AWS data centres are ISO 27001 certified
DealRoomSOC 2 compliance, described as SOC 2 Type 2
Datasite DiligenceISO/IEC 42001 for AI governance; ISO 27001 and SOC 2 not stated on this page
OnehubNone named; the pricing page says "Enterprise-Grade Security"

This table records what each provider states, not what we have verified. Certification claims can and should be checked: ask for the certificate, the scope statement and the issuing body, and for a SOC 2 report ask whether it is Type 1 or Type 2 and what period it covers.

Three ways a certification claim can mislead

  • It is the host's, not the provider's. SecureDocs is straightforward about this, noting that AWS data centres are ISO 27001 certified. That is AWS's certification. It says nothing about the application sitting on top.
  • The scope is narrow. An ISO 27001 certificate applies to a defined scope. A certificate covering a head office and not the product is worth reading carefully.
  • Compliant is not certified. "SOC 2 compliance" and "a completed SOC 2 Type 2 audit" are different statements. Firmex's wording is the clearest here: audited annually against the security, availability and confidentiality trust services criteria.

Where the data sits

For a UK or European deal this can matter more than the certificate. SecureDocs states its AWS data centres are in the United States, Ireland and Germany, and that you can choose US or European hosting. Virtual Vaults publishes a choice of storage location as a plan feature. Drooms describes itself as made in Germany with data sovereignty as a selling point. Admincontrol states Cyber Essentials Plus and G-Cloud 14, both UK schemes. If your deal involves regulated data or a public sector counterparty, ask where the data rests, not just how it is encrypted.

Questions, answered directly

Which virtual data rooms are ISO 27001 certified?

On the pages we read on 15 August 2026, Virtual Vaults (ISO 27001:2022), Admincontrol, Drooms (ISO 27001 and ISO 27018), Ansarada and Ideals all state ISO 27001 certification. SecureDocs states that its AWS data centres are ISO 27001 certified, which is the host's certification rather than its own. Always ask for the certificate and its scope.

What is dynamic watermarking and does every data room have it?

A dynamic watermark stamps the viewer's identity and often a timestamp onto each page as it is displayed, so a leaked screenshot can be traced back to a person. It is stated by CapLinked, Ideals, Ansarada, Onehub and SecureDocs on the pages we read. Virtual Vaults, Firmex, DealRoom and Datasite do not name it on those pages; Firmex instead describes digital rights management that blocks saving, printing, copying and sharing.

Start from what providers actually publish

Eleven providers, six criteria, every cell traceable to the page it came from and the date we read it.

See the comparison