State of M&A Data Rooms — Q2 2026 Read the report →

Data Room Security: The Feature Checklist Behind "Secure" (2026)

Co-founder and CEO at Peony. I built the data room platform with a background in document security, file systems, and AI. Founded Peony in 2021 in San Francisco.

I run Peony, a data room company. Every VDR site says "enterprise-grade security" or "bank-level encryption" somewhere on the homepage, and almost none of them say what that phrase actually includes. After building this stack for 6,800+ customers, here is what "secure" breaks down into feature by feature -- what each control does, what it does not do, and where the honest limits are that most vendor marketing skips.

What Does Virtual Data Room Security Actually Include?

A secure virtual data room is a stack of independent controls, not one feature you can point to. A room can have strong encryption and still leak a document to the wrong person, because encryption protects data in storage and in transit -- it says nothing about who is allowed to open the file once it arrives. The five controls that actually determine whether a room is secure, in the order a deal team typically needs them:

  1. Encryption -- data unreadable to anyone without the key, at rest and in transit. Table stakes; every credible vendor has this.
  2. Granular permissions -- who can see which folders, files, and actions (view, download, print), enforced per person or per group, not just "in the room or not."
  3. Dynamic watermarking -- a visible, per-viewer identity stamp on every page, so a leaked page traces back to a person.
  4. Audit trail -- an immutable, exportable record of every view, download, and access attempt, with timestamp, IP, and device.
  5. Instant revocation -- the ability to cut off a specific person's or group's access the moment you decide to, without touching anyone else's.

Miss any one of these and the room has a real gap. A room with granular permissions but no audit trail can restrict access but can't prove who accessed what if a dispute comes up later. A room with watermarking but no revocation can trace a leak after the fact but can't have prevented the leaker from re-downloading the file five more times before you noticed.

Is a Secure Data Room Different From an Encrypted Cloud Drive?

Yes, and the difference is who the room assumes is on the other end of the link. Cloud storage -- Google Drive, Dropbox, OneDrive -- is built for internal collaboration: people on your team, who you already trust, working on a shared file. A data room is built for the opposite case: an external party, someone who might be evaluating three competing options at once, who you need to give access to without giving them the run of everything. That difference shows up as a specific feature gap. Generic cloud storage does not do per-viewer watermarking, does not log page-level view time, and "revoke" usually means changing a link's permission on a folder you already know the recipient has downloaded. Our full VDR guide breaks down the complete list of what a data room adds on top of file storage.

What Do Granular Permissions Actually Control?

"Permissions" is the vaguest word in data room marketing, so here is what it means at the feature level. A real permission system controls three separate things, independently: which folders or files a person can see at all, what they can do with what they can see (view only, download, print), and whether that access is scoped to them individually or to a group they belong to. The reason group-level scoping matters: in a competitive process with multiple bidders, you are not managing permissions person by person -- you are managing them by bidder group, so that Bidder A's team all gets the same Phase 1 folder and Bidder B's team gets theirs, and no one on either team can see that the other group exists. On Peony's Data Room plan ($52/admin/month), permissions are set per folder and per group, with locked allow/block lists restricting exactly which email domains can even request access -- not just what they see once they're in.

What Does a Dynamic Watermark Actually Prove?

A dynamic watermark embeds the viewer's identity -- typically their email, IP address, and a timestamp -- directly into the rendered page, server-side, at the moment they view it. That's the important mechanical detail: it is not a static "CONFIDENTIAL" stamp added once at upload. It's generated per viewer, per view, which is why it survives a screenshot or a photo of the screen taken with a phone -- the mark is part of the page image itself, not an overlay a screen-capture tool can strip out. What it proves, if a page turns up somewhere it shouldn't, is exactly whose copy leaked. What it does not do is stop the leak from happening -- it is a deterrent and a forensic trail, not a physical barrier. Peony's dynamic watermarks are included on the Data Room plan ($52/admin/month); DocSend keeps dynamic watermarking behind its Advanced plan at $250/month ($150/month billed annually) -- roughly three times what a solo admin pays for Peony's Data Room plan ($75/month, or $52 billed annually) -- and most free-tier sharing tools do not offer per-viewer watermarking at all.

What Does an Audit Trail Need to Capture to Be Useful?

An audit trail is only useful if it can answer a specific question after the fact: who saw what, when, and what did they do with it. That means logging, at minimum, every view, every download, every print attempt, the timestamp, the viewer's IP address, and their device -- and it means the log has to be exportable, because the person who needs it (your counsel, an auditor, a compliance officer) is usually not the person who was watching the room in real time. A log that only lives inside the vendor's dashboard and can't be pulled out as a file is a weaker version of the same feature. On Peony, every view, download, and access attempt is logged with timestamps, IP addresses, and device details. The room-wide activity log (views, sessions and downloads) exports as a CSV from the Analytics tab, filterable to a single viewer, and a full audit-trail copy is available on request after a deal closes -- the record a SOC 2 Type II review or a post-closing dispute would ask for.

What Does Instant Revocation Actually Do?

Revocation removes access going forward, at the level you choose -- a single link, a single person, or an entire group -- the moment you act. On Peony, that takes one click and takes effect immediately: the document becomes inaccessible without the recipient doing anything or being notified in advance. What revocation cannot do, and no vendor's revocation feature can do, is un-download a file. If someone downloaded a PDF to their laptop before you revoked their access, that copy still exists on their laptop -- revocation stops future access to the live room, it does not reach back into a device you don't control. This is the honest limit that watermarking exists to cover: revocation handles "stop this from continuing," watermarking handles "prove who it was if it already happened."

Where Do Compliance Certifications Fit In?

Certifications are a separate layer from the product features above -- they're a third party's attestation that your security process, not just your product, holds up. Here is Peony's actual status, stated plainly rather than blurred: Peony is SOC 2 Type II-ready, with a formal Type II audit in progress through Sprinto -- not yet completed, so not yet certified. Peony does not hold ISO 27001 certification today. Data is encrypted with AES-256 at rest and TLS 1.3 in transit. Data is processed in the United States (AWS us-east-1 region), with a Data Processing Agreement available for UK/EEA transfers under Standard Contractual Clauses; Enterprise plans can add custom UK/EU data residency. A standard DPA and security documentation are available self-serve on the Deal Team plan ($64/admin/month). If a vendor's marketing page just says "SOC 2 compliant" with no Type I/II distinction and no mention of whether the audit is complete, that is the question to ask before you trust the badge -- our data room security questionnaire guide has the full verification process and a 20-question template you can send to any vendor, Peony included.

Honest Limits: What "Secure" Does Not Mean

Even well-built secure data rooms have limits, and no feature on this list, including the ones Peony sells, does everything a marketing page implies. Stated plainly:

  • Screenshot protection blocks OS-level screen capture in the browser -- it does not stop someone from pointing a second phone's camera at their screen. Nothing built into a browser can.
  • Watermarking deters and traces leaks; it does not prevent them. A determined leaker with a camera can still get a page out, watermark and all -- the mark just means you'll know who did it.
  • Revocation stops future access; it cannot un-download a file already saved locally. If the document already left the room before you revoked access, that copy is out of the room's control.
  • "SOC 2 Type II-ready" is not "SOC 2 Type II certified." They mean different things, and any vendor -- including us -- should be specific about which one applies.

A security stack that's honest about these limits is more trustworthy than one that implies it has none.

Frequently Asked Questions

Is a secure data room the same thing as an encrypted cloud drive?

No. Encryption is one control among several, not the whole product. An encrypted Google Drive or Dropbox folder protects data in transit and at rest, but it was not built for the case where you are sharing with people outside your organization who may have competing interests -- other bidders, other investors, opposing counsel. A secure data room adds per-viewer permissions, per-page watermarking, an exportable audit trail, and instant revocation on top of encryption, because in a deal the question is never just "is this file encrypted" -- it's "who saw page 14, when, and can I cut them off right now." Our full comparison of VDRs vs. cloud storage covers this in more depth.

Does dynamic watermarking actually stop someone from leaking a document?

No, and any vendor who implies otherwise is overselling it. A dynamic watermark stamps the viewer's identity -- email, IP, timestamp -- onto every rendered page, server-side, so it survives a screenshot, a print, or a phone photo of the screen. It does not physically prevent someone from capturing the page; it makes the capture traceable back to a person. That is a deterrent, not a lock. The value is that most leaks are not sophisticated -- someone forwards a PDF or takes a screenshot without thinking -- and a visible, personal watermark on every page changes that calculation before it happens.

What is the actual difference between SOC 2 Type I and Type II?

Type I checks whether a vendor's security controls are designed correctly at a single point in time -- a snapshot. Type II checks whether those controls actually operated effectively over an observation window, typically 3-12 months -- evidence, not a design review. Type II is the one that matters for a real security review, and it's also the one every vendor is slower to get because it requires months of operating history before the audit can even start. If a vendor's site just says "SOC 2" with no Type I/II distinction, ask which one -- and whether the audit is complete or still in progress. Our data room security questionnaire guide walks through how to verify a report is current and covers the right scope.