State of M&A Data Rooms — Q2 2026 Read the report →

MCP Data Rooms in 2026: Which Vendors Ship, What AI Agents Can Do, and the Permission Test That Decides It

Co-founder and CEO at Peony. I built the data room platform with a background in document security, file systems, and AI. Founded Peony in 2021 in San Francisco.

I'm Deqian Jia, co-founder of Peony, a data room company used by 6,800+ customers. I spend most of my time on the part of our product that decides who — and, increasingly, what — is allowed to read a confidential document.

Today one of the largest data room providers published a long essay on the Model Context Protocol in M&A. It is a thoughtful piece. It is also telling in what it leaves out: the same company shipped an MCP server back in April, and the essay never mentions it. That gap is the story of this whole category right now. In 2026, "AI in the data room" stopped being a chatbot feature and became an infrastructure question — and the market split cleanly into vendors who ship an MCP connection and vendors who talk about the future of AI in deals.

This post is the factual map. Who actually ships an MCP server, what an AI agent can really do with your deal documents today, and the one test that decides whether any of it is safe on a live deal — a test that has nothing to do with which model is "smartest." I rank nothing here; for a ranked buyer comparison, that lives in our AI data room listicle. This is the landscape, reported straight.

Quick answer: MCP (the Model Context Protocol) is an open standard that lets an AI assistant connect directly to a data room, so agents like Claude, ChatGPT, or Copilot can work with deal documents in place instead of files being pasted into a chatbot. By August 2026, four VDRs publicly ship MCP — Datasite, iDeals, DealRoom, and Peony (owner-side) — while Ansarada, Firmex, CapLinked, Digify, ShareVault, and SecureDocs have no public MCP claim. The deciding test is not model quality — it is permissions. The MCP spec itself says hosts "must obtain explicit user consent" and then concedes "MCP itself cannot enforce these security principles at the protocol level." Enforcement falls to whoever runs the room. So the question that decides an agent connection on a confidential deal is: can the agent see only what the connecting user can, and is every action audited?

Last updated: August 2026

What is MCP, and why did it change data rooms in 2026?

MCP is an open standard for connecting AI models to data and tools, and it changed data rooms because it turned "let an AI read my documents" from a copy-paste habit into a governed connection. Anthropic introduced it in November 2024, describing it as "an open standard that enables developers to build secure, two-way connections between their data sources and AI-powered tools" (Anthropic, November 25, 2024). Before MCP, "AI in the data room" mostly meant a person dragging a PDF into ChatGPT. MCP replaced that with a connector: the assistant reaches the room directly, and the room — if it is built for it — governs what the assistant can do.

What makes MCP more than one vendor's idea is that the rest of the industry lined up behind it fast. OpenAI adopted it in March 2025 — Sam Altman wrote that "people love MCP and we are excited to add support across our products" (TechCrunch, March 26, 2025). Google DeepMind followed in April 2025, with Demis Hassabis calling MCP "a good protocol and it's rapidly becoming an open standard for the AI agentic era" (TechCrunch, April 9, 2025). Then in December 2025 Anthropic donated MCP to the Linux Foundation's new Agentic AI Foundation, where "it will join goose by Block and AGENTS.md by OpenAI as founding projects," with support from Google, Microsoft, AWS, Cloudflare, and Bloomberg — and the foundation was careful to note that MCP's "governance model will remain unchanged" (Anthropic, December 9, 2025). By that date the ecosystem had "more than 10,000 active public MCP servers" and "97M+ monthly SDK downloads."

For a deal team, the upshot is simple: MCP is not a proprietary bet that might disappear. It is the connective tissue the whole AI industry agreed on, which is exactly why it started showing up in virtual data rooms this year — and why the question "does my VDR support it?" became worth asking.

Why does MCP turn "AI in the data room" into an infrastructure question?

Because a chatbot feature lives inside one product, but a connection standard lives between products — and the moment an outside agent can reach your room, the design question stops being "is the AI good?" and becomes "what is the AI allowed to do, and who enforces that?" A built-in Q&A box is a feature you toggle. An MCP server is a door in the wall of your data room, and doors are infrastructure: they need locks, a log of who came through, and a rule about which rooms each key opens.

This is why the interesting part of an MCP data room is not the model. Frontier models are broadly comparable and improving on the same curve; whichever assistant your team already uses will do a competent job reading a contract. What differs enormously between vendors is the enforcement layer — whether the room binds the agent to the connecting user's permissions, whether it audits every AI action, and whether it commits to not training on your documents. Those are properties of the room, not the model.

The market's own language gives this away. When Datasite's August 2026 essay says "Trust starts with permissions. If a user cannot access a document in the data room, AI should not use that document," it is conceding the whole point: the value is not the connection, it is the permission model behind it. I agree with that sentence completely — I just notice that the essay makes the argument in the abstract while the same company's shipped April server, which actually does this, goes unmentioned. The category has split into ships and talks, and even the talks are, quietly, arguing for the ships.

Which virtual data rooms actually ship an MCP server in 2026?

Four VDRs publicly ship or have announced MCP connectivity as of August 2026 — Datasite, iDeals, DealRoom, and Peony. One more, Intralinks, describes a connectivity layer in a comparison guide but without a dated announcement. Six well-known rooms have no public MCP claim at all. Here is the ships-vs-talks map, held to one evidentiary standard: what each vendor's own page actually says, sourced so you can check it yourself.

VendorMCP statusWhenWhat the agent can do (per the vendor)Source
DatasiteShipsAnnounced Apr 28, 2026Connects Claude, ChatGPT, Copilot, and Blueflame AI; "create, permission, and organize" VDRs and "access and analyze live VDR content without moving a single document"; claims to be "the first VDR provider to offer MCP-based connectivity" (its claim)datasite.com
iDealsShipsIn 2026Bridges Claude, ChatGPT, and Copilot; agents "search, analyse, and take action directly inside Ideals"; "AI operates within your existing access rights"; "every action is captured in a full audit trail"idealsvdr.com/mcp
DealRoomShips~May 2026Connect "ChatGPT, Claude, Copilot, or any other AI tools"; can "write findings back automatically" and "create or update DealRoom records"; positions itself as "the Only MCP Built for Buyer-led M&A" (its positioning)dealroom.net/mcp
PeonyShips (owner-side)Available todayOwner-side MCP server: read a room's contents and push artifacts into it from an AI client like Claude; a counterparty's agent querying your room directly is not what this server does yetAgent-ready data room
IntralinksClaim (no dated release)No date foundA comparison guide describes "DealCentre MCP… a secure connectivity layer" with "permission-aware AI access tied directly to existing user roles" and "comprehensive audit trails"; no dated press release found, and "DealCentre" is also Datasite's product-line name — treat carefullyintralinks.com guide
Ansarada, Firmex, CapLinked, Digify, ShareVault, SecureDocsNo public MCP claim found as of August 2026

A few honest notes on this table. Datasite's "first VDR provider" line is a claim, not a settled fact — the label is contested and I report it without endorsing it. The iDeals page carries no launch date, so I say "in 2026" rather than guess a month. The Intralinks row is deliberately a "claim" not a "ship": the language exists in a guide, but no dated announcement backs it, and the "DealCentre" name collides with Datasite's own brand, so I would confirm it with Intralinks directly before relying on it. And the absence row is itself a finding — for a buyer, "we could not find a public MCP claim from Ansarada, Firmex, CapLinked, Digify, ShareVault, or SecureDocs as of August 2026" is a useful fact, not a gap in my research.

Peony's row is held to exactly the same standard as everyone else's: the agent-ready data room page says what our owner-side server does and, just as plainly, what it does not do yet. I am not going to inflate our row to win a table I built. For where each of these platforms ranks against the others on M&A diligence — with pricing, model coverage, and the bring-your-own-model distinction — read the ranked AI data room comparison; this post ranks nothing.

How do I connect a data room to Claude (or ChatGPT/Copilot) via MCP?

You install the room's MCP server as a connector in your AI client, authenticate as yourself, and the assistant can then work with the room under your existing permissions. That is the mechanical answer, and it is genuinely that simple on the vendors that ship it. But the mechanical steps are not where the work is — the work is answering the four questions your IT or security reviewer will raise before they approve the connection. Settle these first and the setup is a configuration task, not a leap of faith.

  • Token audience — is the token issued for this server? The MCP security guidance is blunt: a server "MUST NOT accept any tokens that were not explicitly issued for the MCP server" (MCP security best practices). Passing a token minted for something else is a named anti-pattern, and proxy servers introduce a "confused deputy" risk. Ask the vendor how the connection is authenticated and whether tokens are server-specific.
  • Scopes — is it least-privilege? The same guidance says to "implement a progressive, least-privilege scope model." An agent that only needs to read should not be granted the ability to change permissions. Ask what the connection can do by default and whether you can narrow it.
  • Audit trail — does the AI show up in the log? Every AI action should land in the same audit trail as human document views, attributed to the connecting user, so counsel can reconstruct exactly what the agent read and did. iDeals states "every action is captured in a full audit trail." Ask whether a connected model is a tracked actor or an unattributed read.
  • Training on data — is there a no-training commitment? Confirm in writing that content the agent touches is not used to train the vendor's or a third party's models. iDeals states "Your deal data is not used to train Ideals or third-party models." Ask for the same clarity from any vendor.

Those four questions are the reviewer's checklist, and they are the same whether you connect Claude, ChatGPT, or Copilot. The client differs; the security posture does not. If a vendor answers all four plainly — server-specific tokens, least-privilege scopes, one audit trail, no training — you can hand the connection to your security team with confidence. If the answer is "we support AI," you have not gotten an answer to any of the four, which is itself informative.

Why is the permission test — not model quality — what actually decides it?

Because the MCP specification mandates consent and then admits it cannot enforce it, which means the entire burden of safety lands on whoever runs the room. This is the load-bearing fact of the whole category, and it is worth quoting the spec directly. The MCP specification states that "Users must explicitly consent to and understand all data access and operations" and that "Hosts must obtain explicit user consent before invoking any tool." And then, in the same breath: "While MCP itself cannot enforce these security principles at the protocol level, implementors SHOULD [build] robust consent and authorization flows."

Read those two sentences together and the design conclusion is unavoidable. The protocol asks for consent, least-privilege, and control — and openly concedes it has no power to make anyone honor them. So the question "is this MCP data room safe?" reduces to "does the room enforce what the protocol only requests?" That is why model quality is a distraction. The smartest model in the world, connected to a room that does not bind it to your permissions, is a liability; a competent model connected to a room that enforces the user's access rights and audits every action is safe. The enforcement lives in the room, not the model.

There is one genuinely new risk MCP adds over a human viewer, and it deserves naming plainly: prompt injection. OWASP ranks it the number-one risk for LLM applications — "Manipulating LLMs via crafted inputs can lead to unauthorized access, data breaches, and compromised decision-making" (OWASP Top 10 for LLM Applications). A malicious instruction hidden inside a document a bidder uploads can try to make a connected agent act against the room's owner. Security researcher Simon Willison crystallized the shape of this danger as the "lethal trifecta": access to private data, "exposure to untrusted content," and "the ability to externally communicate in a way that could be used to steal your data." As he puts it, "if your agent combines these three features, an attacker can easily trick it into accessing your private data and sending it to that attacker." In a data room — which is, by definition, full of private data and untrusted uploads from counterparties — the practical defense is to break the trifecta: scope the agent's reach, and keep a human on any action that discloses or moves data outside the room.

Datasite's own August essay reaches the same conclusion from the other direction, which is worth crediting: it says "MCP is not a magic button. It does not make every system instantly clean, connected, or ready for AI," and "Trust starts with permissions. If a user cannot access a document in the data room, AI should not use that document." That is the permission test, stated by a competitor. When the ships and the talks agree that permissions decide everything, you can take it as settled.

What can an AI agent actually do inside a data room today?

The honest range runs from read-only search at one end to writing records back at the other, and it varies by vendor — so the useful move is to pin down which specific verbs each agent supports rather than accept "it does AI." Here is what the vendors say in their own words.

At the read-and-analyze end, iDeals says an agent can "search, analyse, and take action directly inside Ideals", and Datasite says teams can "create, permission, and organize" data rooms and "access and analyze live VDR content without moving a single document outside of Datasite's secure platform." At the write end, DealRoom is the most action-oriented of the group: it says its connection can "write findings back automatically" and "create or update DealRoom records" — the agent does not just read the room, it changes it.

Peony's shipped server sits deliberately at a defined point on that range, and I will state its scope exactly as our agent-ready data room page does. It is owner-side: you can read a room's contents and push artifacts into it from an AI client like Claude — build a pitch deck in Claude, install the Peony MCP, and push it straight into the data room. What it does not do yet is the other direction — a counterparty's agent querying your room directly under its permissions. That is where the category is heading, and I am not going to overstate a roadmap or attach a date to it. Inside a Peony room, the always-available machine-readable path today is permission-aware AI document Q&A (Business, $30/admin/month) and AI auto-indexing (Data Room, $52/admin/month), where the AI answers from your documents, respects each viewer's permissions, cites the source, and logs every query — and connecting an external LLM directly to a room, every AI query logged in the same audit trail as a human viewer, is a Peony Enterprise capability.

The practical takeaway: the verbs that matter are search, summarize, answer, organize, and write-back. Ask each vendor precisely which of those its agent can do, and — critically — which are read-only versus permissioned to change the room. An agent that can write records is more useful and more dangerous than one that can only read, and you want to know which you are approving.

What does 'agent-ready' or 'AI-native' actually mean — and are they the same thing?

They are three names for one underlying idea. "Agent-ready" (the term I use), "AI-native" (a coinage some competitors prefer), and "MCP-enabled" all point at the same three capabilities: documents structured so a machine can read them (text-extractable or OCR'd files, descriptive names, an index), an AI that answers from those documents under the room's permissions and audit trail, and, increasingly, an MCP connection so an outside assistant can reach the room directly. The label is marketing; the capabilities are what you are buying.

So when you hear any of the three, translate it back to the capabilities and run the permission test on it. A room can call itself "AI-native" in a headline and still fail all three — flat image scans a machine cannot read, an AI with no concept of your permission model, no audit trail on AI actions. And a room can ship a quiet MCP server, never use the trendy adjective, and pass every one of them. The words are interchangeable and roughly meaningless on their own; the questions behind them — can a machine actually read the documents, does the AI respect permissions, is every action audited — are what separate a real agent-ready room from a repositioned one. Peony describes its version as an agent-ready data room, and I would hold our page to exactly that test too.

The demand is real and measurable, which is why every serious VDR is now answering the MCP question rather than ignoring it. Bain's 2026 M&A report found that "45% of executives used AI tools in M&A in 2025, more than double the prior year," and that "about one-third of dealmakers are systematically using AI in M&A or are redesigning processes for it" (Bain, January 27, 2026). Adoption more than doubling in a single year is not a fad curve; it is a step change, and it is why the "ships vs talks" split matters — buyers are actively choosing tools, not just reading about them.

The reason they are adopting is that the payoff shows up in the two numbers deal teams care about most: time and cost. McKinsey found that generative AI is "cutting deal timelines by 10% to 30% and reducing costs by roughly 20%" (via CFO Dive, February 18, 2026). A diligence process that runs 10–30% faster at roughly 20% lower cost is a material advantage on any deal, which is exactly why an internal AI mandate is now a common trigger for a VDR switch. The demand curve is real; the open question — the one this post is about — is which rooms can meet it safely, and that comes back, again, to the permission test.

What should we ask a VDR vendor about its MCP or AI-agent support?

Ask six questions, get the answers in writing, and hand the sheet to your security reviewer. These map directly to the MCP specification's own security guidance and to the permission test, and they are the difference between "we support AI" and a connection you can actually defend on a live deal.

  1. Do you ship an MCP server today, and which assistants does it connect — Claude, ChatGPT, Copilot, others? (Shipping today versus "on the roadmap" is the ships-vs-talks line.)
  2. Does the agent inherit each user's existing permissions, enforced at the infrastructure level rather than as a prompt instruction the model could ignore?
  3. Is every AI action logged in the same audit trail as human document views, attributed to the connecting user?
  4. What is your data-retention and model-training policy for content the agent touches?
  5. Is the access token issued specifically for your MCP server, and does the connection follow a least-privilege scope model?
  6. Can the agent write to or change the room — create folders, set permissions, write records — or is it read-only, and can I control that?

A vendor that answers all six plainly has earned your security review. One that deflects to "enterprise-grade AI" has told you something too. For the deeper decision framework on pointing an external model at deal files — training, hallucination, scope, and audit — my longer treatment is should you connect ChatGPT to your data room, and for the specific security-questionnaire angle, see our data room security questionnaire.

Where does Peony stand on all of this?

Peony ships an owner-side MCP server today, and I will describe it with the same honesty I would demand of any vendor in the table above — including its limits. The agent-ready data room page lays out our position in three deliberately separated layers, because conflating "what ships now" with "where this is heading" is exactly how AI-readiness pitches mislead.

The shipped capability is a room whose AI answers from the documents. On Peony Business ($30/admin/month), AI document Q&A lets reviewers ask questions and get answers grounded in the files you uploaded, scoped to each viewer's permissions, with the source cited so they can open the document and verify. On Peony Data Room ($52/admin/month), AI auto-indexing and AI room generation turn a raw upload into a structured, navigable room. Advanced Q&A is on Deal Team ($64/admin/month, minimum 4 admins). And the protocol layer already ships: our owner-side MCP server lets you read a room's contents and push artifacts into it from an AI client like Claude. All rates are flat — only admins are billed, and viewers are always free, so a 40-person buyer team asking questions adds nothing to the bill.

The honest limit, stated as plainly as the capability: our shipped server is owner-side. It does not yet let a counterparty's agent query your room directly under its permissions — that is the direction the whole category is moving, and I am not attaching a date to it. Connecting an external LLM directly to a room, with every AI query logged in the same audit trail as a human viewer, is a Peony Enterprise capability (Enterprise also covers connect-your-own-model/BYOK and SAML SSO). On the security posture: Peony is SOC 2 Type II certified; it does not hold ISO 27001. And the last layer is our own practice — peony.ink publishes an llms.txt index and literal .md variants of every page, so an AI assistant can read the site natively as structured text; median room setup is 4 minutes 19 seconds. To be precise about scope, that llms.txt practice is how we publish our public marketing site — it is not a claim that the Peony product serves an llms.txt index for your customer rooms. 6,800+ customers run their deal and fundraising rooms on Peony, and the through-line across every layer is the one this whole post argues: the room stays the enforcement layer, and it audits the AI.

Frequently asked questions

What is an MCP data room?

An MCP data room is a virtual data room that exposes a Model Context Protocol (MCP) server, so an AI assistant like Claude, ChatGPT, or Copilot can connect to the room and work with its documents directly — search, summarize, answer questions, sometimes create or organize folders — instead of a person exporting files and pasting them into a chatbot. MCP is an open standard Anthropic introduced in November 2024 to build "secure, two-way connections between their data sources and AI-powered tools," and by late 2025 it had been adopted by OpenAI and Google and donated to the Linux Foundation. In a data room, the important detail is not that an agent can read documents — it is that the agent operates under the room's permissions and audit trail, so it can only touch what the connecting user is already allowed to see, and every action is logged. The room stays the enforcement layer; MCP is just the wire the assistant reaches it through.

Which virtual data rooms actually ship an MCP server in 2026?

As of August 2026, four VDRs have publicly shipped or announced MCP connectivity: Datasite (server announced April 28, 2026, connecting Claude, ChatGPT, Copilot, and Blueflame AI), iDeals (MCP server bridging Claude, ChatGPT, and Copilot, in 2026), DealRoom (connecting ChatGPT, Claude, Copilot, or any other AI tools, around May 2026), and Peony (an owner-side MCP server available today). Intralinks describes a "DealCentre MCP" connectivity layer in a comparison guide, but I could not find a dated press release for it, and "DealCentre" is also the name of Datasite's product line, so treat that claim carefully. No public MCP claim was found as of August 2026 for Ansarada, Firmex, CapLinked, Digify, ShareVault, or SecureDocs. Datasite claims to be "the first VDR provider to offer MCP-based connectivity" — that is its claim, and the label is contested, so I report it rather than endorse it. For a ranked buyer comparison of these platforms, see our AI data room listicle; this post reports the landscape and does not rank.

How do I connect a data room to Claude or ChatGPT via MCP?

You install the data room's MCP server as a connector in your AI client (Claude, ChatGPT, or Copilot), authenticate as yourself, and the assistant can then work with the room under your existing access rights. The mechanics vary by vendor, but the security questions your IT team will ask are the same everywhere, and they are the ones worth settling first: (1) Token audience — is the access token issued specifically for this MCP server, or is a token minted for something else being passed through? The MCP security guidance says a server "MUST NOT accept any tokens that were not explicitly issued for the MCP server." (2) Scopes — does the connection follow a least-privilege model, or does it grant the assistant more than the task needs? (3) Audit trail — does every AI action land in the same log as human document views, attributed to the connecting user? (4) Training on data — is there a written commitment that your documents are not used to train the vendor's or a third party's models? iDeals, for example, states "Your deal data is not used to train Ideals or third-party models" and that "AI operates within your existing access rights." Get those four answers in writing and the connection is a configuration task, not a leap of faith.

Is it safe to give an AI agent access to deal documents?

It can be, but the safety comes from where the enforcement lives, not from the agent being clever. The MCP specification is explicit that hosts "must obtain explicit user consent before invoking any tool" — and then concedes that "MCP itself cannot enforce these security principles at the protocol level." That single pairing is the whole story: the protocol asks for consent and least-privilege, but it cannot make anyone honor them, so enforcement falls to whoever runs the room. A safe MCP data room enforces the room's permissions on the AI (the agent sees only what the user could open), keeps a no-training commitment, and logs every AI action in the same audit trail as human views. The new risk MCP adds over a human viewer is prompt injection: OWASP ranks it the number-one risk for LLM applications, and a malicious instruction hidden in a document can try to make an agent act against you. Security researcher Simon Willison's "lethal trifecta" names the dangerous combination — private data, untrusted content, and the ability to communicate externally — so the guardrails that matter are scoping the agent's reach and keeping a human on any action that discloses or moves data.

Can an AI agent see documents the user can't access?

On a well-built MCP data room, no — and this is the single most important question to ask a vendor, because MCP does not answer it for you. The protocol is a connection standard; it has no opinion about your permission model. Whether an agent can see a document the connecting user cannot is decided entirely by how the room enforces permissions on the AI. The vendors that ship MCP say their agent inherits the user's rights: iDeals states "AI operates within your existing access rights," and Datasite says its connector lets teams work with live content without moving documents outside its platform, under existing access controls. On Peony, the same rule holds — a connected model can only reach what the connecting user is permitted to see, so a strategic buyer's assistant can never pull an answer out of a document meant only for the PE bidder. When you evaluate a vendor, insist that permission-awareness is enforced at the infrastructure level, not as a prompt instruction the model could ignore.

Will our deal documents be used to train the model?

That depends entirely on which path you use, and it is the fear worth settling in writing. If someone on either side exports files and pastes them into a consumer chatbot, the content of an uploaded file can be used to train models by default on some consumer tiers unless the user opts out — and you have no way to see, let alone set, which tier your counterparty's junior analyst is on. An MCP connection to a data room that commits to no-training closes that gap: iDeals states plainly that "Your deal data is not used to train Ideals or third-party models." On Peony, AI features run under a zero-retention posture against the model the customer connects — documents are processed to answer the question and are neither retained beyond the session nor used to train a model another company could later query. The rule to insist on with any vendor: your confidential deal documents are used to answer your questions and for nothing else. If a vendor cannot state its retention and training policy plainly, treat that as the answer.

What can an AI agent actually do inside a data room today?

It depends on the vendor, and the honest range runs from read-only search to writing records back. At the read end, iDeals says an agent can "search, analyse, and take action directly inside Ideals"; Datasite says teams can "create, permission, and organize" data rooms and "access and analyze live VDR content without moving a single document." At the write end, DealRoom says its connection can "write findings back automatically" and "create or update DealRoom records." Peony's shipped server is owner-side: you can read a room's contents and push artifacts into it from an AI client like Claude — for example, build a pitch deck in Claude, install the Peony MCP, and push it straight into the room. What the category is still building toward is the other direction — a counterparty's agent querying your room under its permissions. The verbs that matter are search, summarize, answer, organize, and write-back; ask each vendor precisely which of those its agent can do, and which are read-only versus permissioned to change the room.

What should we ask a VDR vendor about its MCP or AI-agent support?

Ask six questions, and get the answers in writing. (1) Do you ship an MCP server today, and which assistants does it connect (Claude, ChatGPT, Copilot, others)? (2) Does the agent inherit each user's existing permissions, enforced at the infrastructure level rather than as a prompt instruction? (3) Is every AI action logged in the same audit trail as human document views, attributed to the connecting user? (4) What is your data-retention and model-training policy for content the agent touches? (5) Is the access token issued specifically for your MCP server, and does the connection follow a least-privilege scope model? (6) Can the agent write to or change the room — create folders, set permissions, write records — or is it read-only, and can I control that? These six map to the MCP specification's own security guidance (explicit consent, least-privilege scopes, and tokens issued for the server) and to the permission test that actually decides whether an agent connection is safe on a live deal. A vendor that answers all six plainly is one you can hand to your security reviewer; a vendor that answers "we support AI" and stops has not answered the question.

What is an 'agent-ready' or 'AI-native' data room?

These are three marketing labels — "agent-ready" (our term), "AI-native" (a competitor coinage), and "MCP-enabled" — for the same underlying capabilities: documents structured so a machine can read them (text-extractable or OCR'd files, an index, descriptive names), an AI that answers from those documents under the room's permissions and audit trail, and, increasingly, an MCP connection so an outside assistant can reach the room directly. The label matters less than the three questions behind it: can a machine actually read the documents, does the AI respect permissions, and is every action audited? A room can call itself "AI-native" and still fail all three; a room can ship a quiet MCP server and pass them. When you hear any of these terms, translate it back to the capabilities and the permission test, and judge the room on those. Peony describes this as an agent-ready data room, and the informational version of the whole landscape is this post.

  • Agent-Ready Data Room — the product page: what Peony's owner-side MCP server and permission-aware AI actually do, with the honest limits stated
  • Best AI virtual data rooms for M&A due diligence — the ranked buyer comparison this post defers all rankings to: assistive vs agentic vs bring-your-own-model
  • Should you connect ChatGPT to your data room? — the deeper decision framework on pointing an external model at deal files: training, hallucination, scope, and audit
  • Data room security questionnaire — the reviewer's checklist for approving any data room, MCP connection included
  • AI document Q&A — the shipped, permission-aware Q&A capability inside a Peony room, the deep dive
  • Pricing — AI document Q&A on Business ($30/admin/month); AI auto-indexing and room generation on Data Room ($52/admin/month); connect-your-own-model on Enterprise. Viewers always free.