State of M&A Data Rooms — Q2 2026 Read the report →
Peony LogoPeony

Private Credit Data Room: The 2026 Guide for Direct Lending Funds

Co-founder at Peony. Former M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries investor at Target Global. I write about investors, fundraising, and deal advisors from the deal-side perspective I spent years in.

Private Credit Data Room: How Direct Lending Funds Run Fundraising, Deals, and LP Reporting (2026)

Last updated: August 2026

Quick answer: A private credit data room isn't one room — it's three. A direct lending fund runs a fundraise room (open for the raise, structured to answer the ILPA DDQ), a stream of per-deal underwriting rooms (one per credit facility, cloned from a template every few weeks), and a permanent LP reporting room (quarterly cadence). The mistake is treating a fund like a private equity deal shop: PE opens two to four rooms a year, but a direct lender underwrites 10 to 25 facilities, answers heavy LP diligence, and reports quarterly — so the data room has to be architected, and priced, for velocity. This guide maps the three rooms, the folder structures, how to collect borrower financials without email, and the per-deal-vs-flat-rate cost math that decides which platform survives 20 rooms a year.

I'm Sean Yu, co-founder of Peony, a data room company serving 6,800+ customers with $26.3B in client assets flowing through the platform — a growing share of them credit funds. That cohort runs from Epsilon Direct Lending, an Australian non-bank lender writing senior-secured loans to middle-market companies, to Creation Capital, a South African private credit manager serving the underbanked middle corporate market, to Eagle Pointe Capital, a Laguna Beach boutique that pairs lower-middle-market M&A advisory with private credit — plus pre-launch managers standing up their first fundraise room on the free plan. The pattern I see across all of them is that a private credit fund isn't a deal shop, it's a document factory. A PE firm might open three or four rooms in a year and close them; a mid-market direct lender opens a room for the Fund III raise, then a fresh underwriting room every few weeks for each new facility, while reporting to LPs every quarter. Same word — "data room" — completely different operating tempo. Get the architecture wrong and you either drown in disconnected accounts or get destroyed on per-deal pricing.

This is the operator's playbook for that tempo: the three rooms a fund actually runs, what goes in each, the folder template you clone per deal, how to pull borrower financials out of email, how LP access and quarterly reporting should work, and the cost math that separates a platform built for velocity from one built to bill you per room. It sits next to the equity-side guides — best data rooms for private equity for the vendor landscape and data room for investors for the general fundraise room — but private credit is its own animal, and the differences are the whole point.

One note on the numbers: market sizes and cadences here are cited from primary sources and hedged where the source hedges. Loan-agreement mechanics like borrowing-base and compliance-certificate timing are market conventions that vary deal by deal — I flag them as "commonly" and "typically." Always run your actual terms past counsel.


Why is a private credit fund's data room problem different from private equity's?

Because a direct lending fund runs on velocity and cadence, while a PE firm runs on discrete, occasional deals. That single difference reshapes everything downstream — how many rooms you open, how they're structured, and how you should be paying for them.

A private equity firm closes a handful of platform deals a year. Each one gets a data room that lives for the length of the transaction and then goes quiet. The rhythm is lumpy and low-frequency. A direct lending fund's rhythm is the opposite: it's continuous. Consider the scale of the activity — KBRA's assessed universe alone covered 2,416 unique middle-market sponsored borrowers in 2025, accounting for more than $1 trillion of direct-lending debt (that's KBRA's surveilled coverage, not the whole market, but it signals the volume). A single mid-market fund inside that universe might underwrite 10 to 25 new facilities a year, carry 25 to 40 active positions, answer institutional LP diligence during a raise, and produce quarterly reports the entire time. It's a factory line, not a series of one-off events.

That tempo creates three problems a PE-oriented setup handles badly. First, room velocity: you need to stand up a clean, well-structured deal room every few weeks, which means a saved template you clone — not a room you rebuild from scratch each time. Second, isolation at scale: every borrower's confidential financials have to be walled off from every other borrower's, so you need dozens of separate rooms that still live under one administrative roof. Third, and most painful, pricing: a platform that bills per deal is fine when you do three deals a year and murderous when you do twenty. The rest of this guide is organized around solving those three at once. The fund that treats its data room like a PE firm's — one room, rebuilt ad hoc, priced per deal — pays for it in both hours and dollars.

What are the three rooms a direct lending fund actually runs?

A direct lending fund runs three functionally distinct rooms — the fundraise room, the per-deal underwriting rooms, and the LP reporting room — and they have different readers, different contents, different lifespans, and different failure modes. Conflating them is the root cause of most data room pain at a credit fund. Here's the map, and it's the single most useful frame in this guide.

One fund, three rooms

RoomWho reads itWhat lives in itLifespan & cadenceWhat kills you in email
The fundraise roomProspective institutional LPs, their consultantsFirm & team, track record with loss/recovery data, strategy, LPA/PPM/side letters, DDQ answersOpen for the raise (often 12–18 months), then archivedSide letters and track record forwarded to the wrong LP; no view analytics
The deal (underwriting) roomsYour deal team, borrower, sponsor, advisersCredit agreement, borrower financials, collateral/liens, QoE, your internal credit memoOne per facility, cloned from a template every few weeksBorrower financials as inbox attachments; version chaos; no isolation per deal
The LP reporting roomCommitted LPs (your existing investors)Quarterly reports, capital account statements, K-1s, capital call & distribution noticesPermanent; quarterly cadence for the life of the fundK-1s and capital accounts emailed to 60 LPs; no record of who opened what

One fund, three rooms: the private credit data room architecture

The reason this frame is load-bearing: each room fails differently, so each needs different controls, but they should all run on one platform so your team, branding, permissions, and folder templates live in a single place. The fundraise room's failure mode is leakage and going blind on LP interest — you fix it with watermarking and view analytics. The deal rooms' failure mode is chaos and cross-contamination — you fix it with a cloned template and per-room isolation. The LP reporting room's failure mode is emailing sensitive statements to a large distribution list with no audit trail — you fix it with a permanent, permissioned room and per-viewer logs. Same platform, three configurations. The next four sections take each room in turn, starting with the raise.

What goes in the fundraise room for institutional LP due diligence?

The fundraise room is structured around what an institutional LP diligences before committing to a direct lending fund — and for a credit fund, that means leading with loss and recovery data, not just headline returns. An equity LP reads for upside; a credit LP reads for downside protection and consistency, so your realized losses, default rates, and recoveries are the first thing a serious allocator wants to see.

Direct lending dominates where the institutional money is going: Preqin reports it was the hottest strategy in 2024, securing 77.4% ($152.7bn) of total private-debt capital raised. That concentration means LPs have seen a lot of direct lending decks, and they diligence with a template. The pool is still growing — Moody's projects global private credit will reach $4 trillion by 2030, as reported by Pensions & Investments — so the template is not getting shorter. The practical spine is the ILPA Due Diligence Questionnaire (DDQ 2.0, released November 2021), which ILPA describes as "intended to standardize the key areas of inquiry posed by investors during their diligence of managers." If you map your fundraise folders to the DDQ's sections, you preempt most of the request list before it arrives.

A fundraise-room structure that works:

  • Firm & team — GP bios, ownership, the GP commitment, and organizational depth (LPs want to know the credit committee isn't one person).
  • Track record — the full loan-by-loan history with realized losses, default and recovery rates, and vintage performance. For credit, consistency and downside beat a single strong number.
  • Strategy — target borrower profile, sourcing engine, sector and geographic focus, position sizing, and leverage policy.
  • Fund terms — the LPA, PPM, subscription documents, fee and waterfall structure, and a side-letter policy.
  • Risk, valuation & monitoring — how illiquid loans are valued, the covenant-monitoring process, and portfolio-level risk limits.
  • Operations & service providers — fund admin, auditor, legal counsel, custodian, and the most recent audited financials.
  • Compliance, ESG & DEI — regulatory registrations, the compliance manual, and the ESG/DEI policies the DDQ now asks about.

Two structural notes. Stage the disclosure — the teaser and terms can be open, but the detailed track record and LPA should unlock after an NDA or a qualifying call. And keep the VC fund data room checklist and the general data room for investors guide handy — the fund-formation scaffolding overlaps, even though the credit-specific loss/recovery emphasis is yours alone.

What folder structure works for a per-deal underwriting room?

The underwriting room is built from one template folder tree that you clone for every facility — that's the whole trick to running deal rooms at velocity. You design the structure once, save it as a template, and each new borrower gets a fresh, identically-organized room in minutes instead of a from-scratch rebuild that invites inconsistency.

A folder tree that works for direct lending underwriting:

  • 01 Company & Business — business overview, org chart, management bios, key customers and suppliers.
  • 02 Financials — audited statements, interim and monthly management accounts, the financial model, and projections.
  • 03 The Loan — term sheet, credit agreement, and (for asset-based facilities) the borrowing base and its supporting schedules.
  • 04 Collateral & Security — UCC and lien searches, security agreements, guarantees, appraisals, and asset schedules.
  • 05 Legal & Corporate — formation documents, cap table, material contracts, litigation, and permits.
  • 06 Sponsor & Equity — sponsor overview, the equity contribution, and the sponsor's track record (for sponsored deals).
  • 07 Diligence Reports — quality of earnings, legal, insurance, and environmental reports.
  • 08 Underwriting — your internal credit memo, rating rationale, and committee materials — permission-restricted to the deal team only.
  • 09 KYC / AML — borrower and beneficial-owner identity, sanctions screening, and entity documents.

Three rules make this durable. Number the folders so sort order stays stable no matter what gets uploaded. Lock folder 08 — your internal credit memo and committee materials should never be visible to the borrower or the sponsor, and per-folder permissions enforce that. And save the tree as a template so opening facility number 21 is a two-minute clone, not an afternoon. On Peony, AI auto-indexing classifies a bulk upload straight into this structure, so when a borrower dumps forty files you're not sorting them by hand. For the infrastructure-credit edge case — GPU clusters, data centers, and asset-backed compute financing where the collateral and offtake documents dominate — see GPU cluster financing data room. And for the startup-borrower cousin of this room, where a venture lender underwrites a venture-backed company, see venture debt data room.

How do you collect borrower financials without email?

You make it a request, not an email — a secure upload link to a specific folder that the borrower fills without needing an account. This is the single highest-leverage operational fix for a credit fund, because a fund with 35 active positions is collecting recurring reporting from 35 borrowers on overlapping cadences, and email cannot survive that volume.

The cadence is relentless by design. A borrowing-base certificate is prepared by the borrower and submitted to the lender periodically, usually monthly on asset-based facilities. A covenant compliance certificate is commonly due quarterly — sample credit-agreement language cited by Holland & Knight calls for it "within 45 days after the end of each fiscal quarter," though actual terms vary deal by deal. Multiply monthly borrowing-base certificates and quarterly compliance certificates across dozens of borrowers and you have a continuous inbound stream. Run it through email and you get the three failures email always produces: version chaos (which of five attachments is the current model), a security hole (covenant spreadsheets sitting in inboxes indefinitely), and no audit trail (no clean record of who submitted what, when).

Request-based collection fixes all three. You send the borrower's controller a link to a named folder; they upload directly with no login; the files land classified, access-controlled, and logged. Automated reminders chase the stragglers so you're receiving instead of nagging. That's exactly what Peony's file collection does — request links, no-login uploads, reminders — and the deeper how-to lives in collect documents from clients securely. I'm keeping this section short on purpose, because the depth belongs in those two pages; the takeaway for room architecture is simply: recurring borrower reporting is a collection workflow, not an inbox.

How should LP access and quarterly reporting work?

LP access should be granular and staged, and reporting should run through a permanent, permissioned room rather than an email blast. These are two sides of the same discipline: an LP should only ever see what they're entitled to at the stage they're at, and every document they touch should be logged.

On access, "who can see the room" is never a yes/no switch — it's a matrix. During the raise, one prospective LP might get the full room while another sees only the teaser and terms until an NDA is signed; no LP should ever see another LP's side letter or your deal team's internal notes. The controls that enforce this: per-user and per-group permissions, view-only rendering with dynamic watermarking (the viewer's own email stamped on every page, which turns a leak into a traceable event), download disabled on the most sensitive files, and staged disclosure that unlocks the detailed track record or LPA only after a qualifying step. Because viewers are free on Peony, inviting 60 prospective LPs into a staged fundraise room adds nothing to your bill.

On reporting, once LPs are committed they need quarterly reports, capital account statements, K-1s, and capital-call and distribution notices — and these should live in the permanent LP reporting room, not land in 60 inboxes. Two reasons. First, security and auditability: capital account statements and K-1s are exactly the documents you don't want floating in email, and a room gives you a clean record. Second, you learn who actually engages — the platform logs which LP opened which report and how long they spent, so re-up conversations start from data instead of guesswork. The industry is moving toward standardized reporting here: ILPA released an updated Reporting Template v2.0 and a new Performance Template on January 22, 2025, recommending (not mandating) that the new templates "be implemented beginning Q1 of 2026." Aligning your quarterly package to those templates makes the room easier for LPs to consume. For the mechanics of turning a quarterly package into a shareable, trackable view, see share an interactive LP report and the broader LP reporting guide.

How much does a private credit data room cost — per-deal vs flat-rate?

The cost is decided by the pricing model, not the sticker price — and for a fund opening 20 rooms a year, per-deal pricing and flat-rate pricing produce wildly different bills for the same usage. This is the economics point that the persona feels most acutely, so here's the arithmetic laid out plainly.

Legacy enterprise VDRs were built for per-deal M&A, where a bank opens one big room for one big transaction. Their pricing reflects that: Datasite runs a median of roughly $68,000/year per Vendr, and traditional providers frequently quote per-room, per-page, or per-project. For an investment bank doing a handful of large deals, that's tolerable. For a direct lending fund opening a new room every few weeks, per-deal pricing scales linearly with your deal count — the busier you are, the more it costs, which is exactly backwards for a document factory.

A flat-rate seat model inverts the curve. Here's the comparison at a realistic 20 rooms a year:

ApproachHow it's pricedCost at 20 rooms/year
Legacy per-deal VDR (e.g. Datasite)Per room / per page / per projectDatasite median ≈ $68,000/year per Vendr; per-deal quotes stack up with each new room
Peony Data Room plan$52/admin/month, unlimited rooms, viewers free4 admins × $52 × 12 = ≈ $2,496/year for unlimited rooms
Peony Deal Team plan$64/admin/month (min 4 admins), unlimited rooms4 admins × $64 × 12 = ≈ $3,072/year, adds API access + Advanced Q&A + Advanced Redaction

The arithmetic is the argument. On Peony's Data Room plan, four admins running unlimited rooms with unlimited storage is about $2,496 a year — and it's the same number whether you open two rooms or forty, because you pay per seat, not per deal. The Deal Team plan at $64/admin/month (minimum four admins) is the step up when you need API access to wire the platform into your systems, the Advanced Q&A module for structured LP or borrower questions, or Advanced Redaction. Viewers and guests are always free on both, so every LP and every borrower's controller costs nothing. The structural takeaway: per-deal pricing scales with your deal count; flat-rate pricing scales with your headcount — and for a fund whose whole job is opening rooms, the headcount curve is the one you want. For a fuller vendor-by-vendor breakdown, see the virtual data room cost guide.

Where does Peony fit — and where it doesn't?

Peony is the secure document layer across all three rooms — the platform where you run the fundraise room, clone per-deal underwriting rooms, and host the permanent LP reporting room — but it is deliberately not your portfolio-monitoring or covenant-analytics system, and it's not a loan-agency platform. Being clear about that line is how I'd want a prospective customer to evaluate us, so here's the honest map.

Where Peony fits the three-room architecture cleanly: it's a flat-rate platform ($52/admin/month on the Data Room plan) with unlimited rooms, so opening deal 21 costs nothing extra; AI auto-indexing turns a borrower's bulk upload into a clean folder tree; permissions are granular per file and per folder with dynamic watermarking; file collection pulls borrower financials in via no-login request links; and full per-viewer audit logs tell you which LP read which report. On security, it's SOC 2 Type II with AES-256 encryption at rest and TLS 1.3 in transit — the baseline an institutional LP or a borrower's counsel expects before they'll touch the room. Across 6,800+ customers and $26.3B in client assets, that document-layer job is what we do.

Where Peony does not fit — and where you should use a specialist:

  • Portfolio monitoring & covenant analytics. Once a loan is on the books, tracking covenant compliance, spreading financials, and valuing the position is a job for a dedicated system. Allvue positions itself around "private debt, credit, and direct lending software." Chronograph automates portfolio-company data collection, analytics, and valuations for investors. And S&P's iLEVEL is a private-markets portfolio-management platform built for exactly this monitoring work. Peony holds the documents securely; those platforms do the ongoing analytics on the data inside them.
  • Loan agency & syndication at bank scale. Administering a syndicated facility — agency, waterfall calculations, lender-of-record servicing — is specialist infrastructure, not a data-room job. Use the loan-servicing and agency platforms built for it.

The clean division of labor: Peony is the room where documents live, move, and get controlled across fundraising, deals, and LP reporting; the analytics and servicing platforms are where the numbers inside those documents get monitored and administered. A well-run credit fund uses both, and knowing which tool does which is half the battle. For the folder-level blueprint that generalizes beyond credit, see the data room folder structure guide and the private credit solution page.


Sources

Frequently asked questions

We open 20 diligence rooms a year — what's the best data room setup for a private credit fund?

Set it up as one platform running three room types, not one room. A direct lending fund runs a fundraise room, a stream of per-deal underwriting rooms (one per facility, cloned from a template every few weeks), and a permanent LP reporting room. The setup that works is a single flat-rate platform where you open unlimited rooms from a saved folder template, so opening deal number 21 costs the same as deal number 1. The economics are the whole game: legacy per-deal VDR pricing punishes a fund that opens 20 rooms a year, while a flat-rate seat model doesn't. On Peony, the Data Room plan is $52/admin/month with unlimited data rooms and unlimited storage, and viewers are free — so 20 rooms a year costs the same as two. Build one template folder tree, clone it per deal, and keep the fundraise and LP rooms permanently open alongside.

Do we need a separate data room for every credit facility, or one fund-level platform?

Both — a separate room per facility, on one fund-level platform. Each facility needs its own isolated room: the borrower's financials, the credit agreement, and the underwriting memo for Facility A must never be visible to anyone looking at Facility B, and each room has its own access list, watermarks, and audit trail. But you do not want 20 disconnected accounts. You want one platform where your team, permissions, branding, and folder template live once, and every new facility is a fresh room cloned from that template in minutes. The wrong model is a per-deal VDR that bills per room — that's where a fund opening 20 rooms a year gets destroyed on cost. The right model is a flat-rate platform with unlimited rooms under one login, so isolation lives at the room level while cost and your template live at the fund level. Isolate the deals; centralize the platform.

What goes in a private credit fundraise data room for institutional LP due diligence?

Structure it around what an institutional LP diligences before committing to a direct lending fund. The core sections: the firm and team (bios, track record, GP commitment, ownership); the strategy (target borrowers, sourcing, sector focus, position sizing); the track record with loss and recovery data — realized losses, default rates, and recoveries matter more than gross IRR alone; sample deals showing underwriting discipline; the fund terms (LPA, PPM, side letters, fees, waterfall); risk, valuation, and monitoring policies; operations, service providers, and the audit; and compliance, ESG, and DEI. The ILPA Due Diligence Questionnaire (DDQ 2.0, November 2021) is the practical spine — it is, in ILPA's words, "intended to standardize the key areas of inquiry posed by investors during their diligence of managers." Map your fundraise folders to the DDQ sections and you preempt most LP requests. See data room for investors for the general fundraise-room structure this builds on.

Why are LP DDQs so much heavier for private credit funds now?

The honest framing is that LP diligence has become increasingly standardized and formalized, and standardized diligence is thorough diligence. The clearest evidence is the ILPA Due Diligence Questionnaire (DDQ 2.0), which exists to "standardize the key areas of inquiry posed by investors during their diligence of managers" — when a shared template exists, LPs work through every section rather than a few. For a credit fund, that means deep questions on loss and recovery history, valuation methodology for illiquid loans, borrower concentration, covenant discipline, and leverage. The market's growth is part of why: the global private credit market has reached roughly $3.5 trillion in AUM per the ACC/AIMA December 2025 report, which means more first-time allocators asking more questions. The takeaway isn't that DDQs "got heavier" as a measured fact — it's that diligence is standardized enough that you should structure your room to answer the whole DDQ up front.

What folder structure works for a direct lending underwriting room?

Use one template folder tree, cloned per facility. A structure that works: 01 Company & Business (overview, org chart, management); 02 Financials (audited and interim statements, monthly management accounts, the model); 03 The Loan (term sheet, credit agreement, security and guarantees, borrowing base if asset-based); 04 Collateral & Security (UCC/lien searches, appraisals, asset schedules); 05 Legal & Corporate (formation docs, material contracts, litigation); 06 Sponsor & Equity (sponsor overview, equity contribution, cap table); 07 Diligence Reports (QoE, legal, insurance, environmental); 08 Underwriting (your internal credit memo and model — restricted to the deal team); 09 KYC/AML. Number the folders so sort order is stable, keep folder 08 permission-restricted, and save the whole tree as a template so opening the next facility takes minutes, not hours. On Peony, AI auto-indexing sorts a bulk upload into this structure so you're not dragging files one by one.

How do we collect borrower financials securely instead of over email?

Stop treating it as email and start treating it as a request. Instead of asking a borrower's controller to "send over the Q3 financials," you send a secure upload link to a specific folder; they upload directly — no account, no login on their end — and the files land classified and access-controlled in the deal room. That fixes the three things email breaks: version chaos (which of five attachments is current), security (covenant data sitting in an inbox forever), and the audit trail (who sent what, when). For a fund tracking borrowing-base certificates monthly and compliance certificates quarterly across dozens of positions, request-based collection with automated reminders is the difference between chasing and receiving. Peony's file collection does exactly this — request links, no-login uploads, reminders — and the deeper playbook lives in collect documents from clients securely. Route recurring borrower reporting through a request workflow, not your inbox.

How do we give LPs access to the fundraise room without exposing everything?

Use granular, per-file and per-folder permissions with staged access, not one shared link. In a fundraise room, not every prospective LP should see everything at once, and no LP should see another LP's side letter or your internal notes. The controls that matter: per-user or per-group permissions so you can grant one LP the full room and another only the teaser and terms; view-only rendering with dynamic watermarking (the viewer's email stamped on every page) to deter leaks; disable download on the most sensitive files; and staged disclosure where the operating agreement or detailed track record unlocks only after an NDA or a qualifying call. The point is that "access to the room" is never binary — it's a matrix of who sees which document at which stage. On Peony, permissions are set per file or per folder and viewers are free, so inviting 60 prospective LPs adds no cost.

Can we see which LPs actually opened our fund documents?

Yes — that's one of the strongest reasons to use a real data room instead of a shared drive. A proper platform logs every view: which LP opened the room, which documents they read, how long they spent on each page, whether they downloaded anything, and when they last returned. For a fundraise, that turns a black-box process into a readable signal. An LP who spent twenty minutes on the track record and the LPA is a live conversation; one who opened the teaser once and never came back is not. Page-level analytics also show which documents get scrutinized — if every LP lingers on the loss-and-recovery data, you know what the next conversation is about. This is table stakes on Peony: full per-viewer, per-document audit logs on every plan, exportable for your IR records. See share an interactive LP report for turning that into a shareable LP-facing view.

How much does a data room cost for a private credit fund — and how does per-deal pricing compare to flat-rate?

It depends entirely on the pricing model, and for a fund the model matters more than the sticker. Legacy enterprise VDRs are built for per-deal M&A: Datasite runs a median of roughly $68,000/year per Vendr, and traditional providers often quote per-room or per-page. That math punishes a fund opening 20 rooms a year. A flat-rate seat model inverts it: on Peony's Data Room plan, it's $52/admin/month with unlimited data rooms and unlimited storage — four admins is about $2,496/year for as many rooms as you open. The Deal Team plan is $64/admin/month (minimum four admins) when you need API access, the Advanced Q&A module, or Advanced Redaction. Viewers and guests are always free, so LPs and borrowers cost nothing. The structural point: per-deal pricing scales with your deal count; flat-rate pricing scales with your headcount, and for a document factory that's dramatically cheaper.

Is SharePoint or Dropbox enough for a credit fund's deal files?

For internal storage, fine — for a fundraise room or a borrower-facing deal room, no. SharePoint and Dropbox are file-sync tools, not diligence platforms, and they're missing the controls a credit fund needs the moment an external party is involved. There's no dynamic per-viewer watermarking, no reliable view-only rendering that survives download attempts, no page-level analytics telling you which LP read which document, no clean audit trail an auditor or LP will accept, and permissioning is coarse and easy to misconfigure — the accidental "anyone with the link" share is exactly how a confidential borrower file or an LP's side letter leaks. They also don't give a borrower's controller a no-login upload link to a specific folder. A real data room adds watermarking, granular permissions, full audit logs, and request-based collection. Keep Dropbox for internal drafts; run anything an LP, borrower, or auditor touches in a purpose-built room like Peony.