SOC 2 and ISO 27001 Compliant Data Rooms: Who Actually Holds What (2026)
Co-founder and CEO at Peony. I built the data room platform with a background in document security, file systems, and AI. Founded Peony in 2021 in San Francisco.
I'm Deqian Jia, co-founder of Peony. I've been through our own SOC 2 Type II audit — sat with the auditors, wrote the control narratives, watched the test-results tables come back — so this post is written from the inside of that process, not from a marketing page. It is also written because the question keeps landing in my inbox in almost the same words: "Which data rooms are actually SOC 2 and ISO 27001 compliant?" — usually from someone with an LP questionnaire open in another tab and a deadline.
The frank answer is that "compliant" is doing a lot of quiet work in that sentence. There is a wide gap between a vendor that claims a certification on a landing page and one that hands you the report. There is a wider gap between a vendor's corporate ISO 27001 certificate and its data center's ISO 27001 certificate — the second certifies a building, not the software you are about to trust with a deal. So rather than write another explainer that tells you SOC 2 is "a security framework" and leaves you where you started, I opened all fourteen vendors' own security, trust, and compliance pages and wrote down, verbatim, what each one states — then built the matrix below.
Quick answer: Verified on each vendor's own public page in August 2026, only 2 of 14 data room vendors — Datasite and Box — publicly state both a SOC 2 Type II attestation and a corporate ISO 27001 certificate in their own name. Most of the other twelve hold one but not the other: several state SOC 2 without naming a Type; several present ISO 27001 as data-center or AWS inheritance rather than a corporate certificate; one states ISO 27001 is "in progress," and one enterprise VDR states no SOC 2 claim on its security page at all. This is a verification dataset ordered by how vendors state their claims — not a ranking of who is "best." Peony's own row concedes the gap plainly: SOC 2 Type II, and no ISO 27001.
I run Peony, a data room company, and I want to be plain about where we sit in this matrix from the first paragraph: we hold SOC 2 Type II and we do not hold ISO 27001. We say so on our own security page rather than blur the line, and I say it again here because the honest "no" is the whole point of a verification post. A matrix that quietly flatters the author is worthless to the person filling out the DDQ. What follows is the data, then five things you can do with it: read the matrix, tell Type I from Type II, actually read a SOC 2 report, obtain the evidence, and answer the fund/LP questions.
Which virtual data rooms are certified to ISO 27001 and SOC 2?
As of August 2026, Datasite and Box are the two data rooms that publicly state a SOC 2 Type II attestation and a corporate ISO 27001 certificate in their own name, verified on each vendor's own page. Everyone else in this set holds a subset or states it more loosely. Before the table, one framing that makes the whole thing readable: certification claims fall into three classes, and half the confusion in this market comes from vendors and buyers treating them as one.
- Own-audit, Type stated. The vendor states its own SOC 2 with the Type spelled out (Type II), or its own ISO 27001 certificate in its corporate name. This is the strongest, most citable class.
- Own-audit, Type not stated. The vendor states SOC 2 (sometimes "SOC 2 & SOC 3 Certified") but does not name a Type on the public page. The claim is probably real; the evidence you can cite is weaker until you see the report cover.
- Inherited-from-AWS (or data-center-level). The vendor presents ISO 27001 (or SOC 2) as something its cloud host or data center holds — "hosted on ISO 27001-compliant servers," or an ISO certificate scoped to "data centers." This is the inherited-badge trap: a data center's ISO 27001 certifies the building, the racks, and the cloud provider's own controls — it says nothing about the vendor's application, access management, key handling, or personnel processes. Naming this class precisely is the single most useful thing this post does.
Here is the matrix. Every cell is the vendor's own wording as published on the source page in the last column, verified August 2026.
| Vendor | SOC 2 (Type?) | ISO 27001 | Other frameworks | Evidence access |
|---|---|---|---|---|
| Peony | SOC 2 Type II (explicit) | No — states "no ISO 27001 certification today" | HIPAA, GDPR, CCPA; public sub-processor list | Self-serve report + DPA in-product (Deal Team plan, $64/admin/month) — no request form |
| iDeals | "SOC 2 & SOC 3 Certified" (no Type stated) | Yes — 27001 + 27017 + 27018 + 27701, each with an ungated "Download certificate" link | HIPAA "verified by a 3rd party"; GDPR | Ungated certificate downloads (best-in-field) |
| Datasite | SOC 2 Type II "on an annual basis" | Yes — since 2007; + 27017 + 27018 + 27701; first VDR certified to ISO/IEC 42001 | GDPR; HIPAA not on compliance page | Stated; nothing downloadable |
| Intralinks | SOC 1, SOC 2, SOC 3 (logos, no Type stated) | Yes — 27001 + 27701; ENS (Spain) | GDPR + Data Privacy Framework; HIPAA not stated on trust page | Stated; nothing downloadable |
| Firmex | SOC 2 Type 2, audited annually | Data centers only — ISO 27001:2022 (not Firmex corporate) | Downloadable HIPAA certificate; GDPR | Downloadable HIPAA cert; SOC 2 stated |
| Ansarada | No SOC 2 claim on its security page | Yes — 27001 "for over 10 years" | GDPR | Stated (ISO); no SOC 2 claim to evidence |
| DealRoom | SOC 2 Type II (Security TSC) | In progress — "ISO 27001 certification is in progress" | FIPS 140-2 validated HSMs | NDA-gated report portal (trust.dealroom.net) |
| SecureDocs (Onit) | SOC 2 Type 2 (for SecureDocs itself) | AWS data-center level only | — | Stated; site now 301s to onit.com |
| CapLinked | "Independently assessed to meet SOC 2 standards" (no Type) | AWS inheritance — "hosted on ISO 27001-compliant servers" | HIPAA/HITECH; still cites EU-US Privacy Shield (invalidated 2020) | Stated; nothing downloadable |
| Digify | AWS inheritance only (lists AWS's certs) | Yes, corporate — ISO 27001:2022 for Digify itself | HIPAA/GDPR not stated on security-features page | Stated; nothing downloadable |
| ShareVault | SOC 1/2/3 (no Type stated) | Yes — 27001:2022 (page also cites :2013 in one spot) | ISO/IEC 42001:2023; HIPAA, GDPR, CCPA, PCI DSS, NIST 800-53 | Stated; nothing downloadable |
| Box | SOC 1 (SSAE 18) Type II + SOC 2 Type II + SOC 3 | Yes — 27001 + 27017 + 27018 + 27701 | FedRAMP High; HIPAA/HITECH; GDPR | NDA-gated trust center |
| Dropbox | SOC 1/2/3 (no Type stated on trust page) | Yes — 27001 + 27017 + 27018 + 27701 + 22301 + ISMAP | HIPAA/HITECH; GDPR | NDA-gated trust center |
| Google Workspace | Page not machine-readable on our date — commonly holds SOC 1/2/3 | Commonly holds 27001/17/18/701 (caveat visible) | — | Security page fully JS-rendered; not verifiable by our static fetch this pass |

How to read this table
Read it by column, not by row rank — this is not a leaderboard. The SOC 2 column tells you whether the vendor states its own attestation and whether it names a Type; treat "no Type stated" as a prompt to ask for the report cover, not as a red flag on its own. The ISO 27001 column is where the inherited-badge trap lives: "corporate" means the certificate is in the vendor's own name (Datasite, Box, Intralinks, Digify, iDeals, Ansarada, Dropbox, ShareVault); "data centers only" or "AWS inheritance" means the certificate covers the hosting layer, not the vendor's application (Firmex's ISO covers its data centers; CapLinked and SecureDocs present ISO at the AWS/data-center level). Those are meaningfully different assurances, and an LP who knows the difference will ask which one you mean.
The Evidence access column is the one buyers skip and then regret. A claim you cannot verify is a claim you cannot cite in a DDQ. The spread here is real: iDeals lets you download the certificates with no gate; Peony serves the SOC 2 report and DPA self-serve inside the product; DealRoom, Box, and Dropbox put the report behind an NDA-gated portal; and a large middle group states the claim with nothing downloadable at all. None of that makes a vendor non-compliant — plenty of excellent programs gate their reports — but it changes how much lead time you need before you can answer the question.
Two rows deserve a plain-spoken footnote. CapLinked's security page still cites the EU-US Privacy Shield as a transfer mechanism. Privacy Shield was invalidated by the Court of Justice of the EU in the Schrems II ruling in July 2020; citing it on a live security page in 2026 is a five-year-stale claim, and it is the kind of thing a European counterparty's counsel will flag. I state that factually, not as a gotcha — stale copy happens — but if you are relying on that page for a transfer answer, use the current EU-US Data Privacy Framework analysis instead. And Google Workspace's security page is fully JavaScript-rendered, so our static verification fetch could not read it on our date; the row is marked with that caveat rather than filled in from memory. Workspace commonly holds SOC 1/2/3 and ISO 27001/27017/27018/27701, but I did not machine-verify it this pass, so I will not present it as verified.
Who offers SOC 2 and ISO 27001 compliant data rooms for funds?
For a fund answering an LP DDQ, the two vendors that most cleanly satisfy a "both SOC 2 Type II and corporate ISO 27001" requirement, verified August 2026, are Datasite and Box — Datasite states a SOC 2 Type II attestation on an annual basis and has held ISO 27001 since 2007 (adding 27017, 27018, 27701, and, notably, being the first data room provider certified to ISO/IEC 42001 for AI management), and Box publishes SOC 1/2/3 with Type II plus ISO 27001/27017/27018/27701 in its trust center. If your LP names both certifications explicitly and wants them in the vendor's own name, those are the rows that answer without asterisks.
But "for funds" almost never means "buy the vendor with the most logos." It means: can I answer the questionnaire truthfully, obtain the evidence, and not create a residency or scope problem for my LPs? On that reading the picture is more useful than a two-name shortlist:
- If the DDQ requires SOC 2 Type II with an obtainable report, most of the field qualifies on the claim, but the evidence axis separates them. iDeals is the standout for transparency — it offers ungated ISO 27001/27017/27018/27701 certificate downloads directly on its security page, which is genuinely the best certificate-access experience of the fourteen. Peony serves the SOC 2 Type II report and DPA self-serve in-product on the Deal Team plan; DealRoom, Box, and Dropbox will give you the report under an NDA.
- If the DDQ requires corporate ISO 27001 specifically, confirm whose name is on the certificate. Datasite, Box, Intralinks, Dropbox, iDeals, Ansarada, ShareVault, and Digify state ISO 27001 in their own corporate name. Firmex's ISO 27001:2022 covers its data centers, and CapLinked and SecureDocs present ISO at the AWS/data-center level — those are inheritance, not a corporate certificate, and an LP who asks precisely will want to know that.
- If the DDQ is US-centric and cares most about operating effectiveness, a current SOC 2 Type II with a readable report usually clears the bar without ISO at all. That is the lane most funds are actually in.
One row that surprises people every time: Ansarada, a well-known enterprise VDR, states no SOC 2 claim anywhere on its security page as of our August 2026 check — it leads with ISO 27001 "for over 10 years" instead. That is not a knock on Ansarada's security; it is a reminder that the absence of a claim on a public page is itself information you should record in your matrix, and a prompt to ask the vendor directly rather than assume. (If you are weighing Ansarada against the field, the Ansarada alternatives breakdown maps the same security claims against pricing and fit.)
And to close the loop on my own product, since a fund reading this will reasonably ask: Peony holds SOC 2 Type II and does not hold ISO 27001. If your LP's questionnaire hard-requires corporate ISO 27001, Peony is not the row that answers it, and I would rather you know that now than three weeks into a diligence process. What Peony offers instead is the evidence axis — the report and DPA are self-serve, with no request form and no NDA gate on the Deal Team plan — which is its own kind of answer to "can you actually get it." More on that in the evidence section.
SOC 2 Type I vs Type II — and why "SOC 2 certified" is technically wrong
For procurement, the only SOC 2 distinction that changes your risk posture is Type I vs Type II, and it is a distinction about time. A Type I report is a point-in-time examination: an auditor evaluates whether the service organization's controls are suitably designed as of a single date. It answers "on this day, were the right controls in place on paper?" A Type II report covers a review period — typically six to twelve months — and evaluates whether those same controls operated effectively throughout that window. It answers the question that actually matters for a data room holding a live deal: "did access reviews, encryption, logging, and change management actually run, consistently, over time?"
For a VDR, insist on Type II. A room where nothing is uploaded is trivially secure; the assurance you are buying is that the controls hold up while a deal is live and dozens of counterparties are logging in. A Type I tells you the design existed on one day. A Type II tells you it worked for a year. When a vendor's page says "SOC 2" with no Type — and several in the matrix do (iDeals, Intralinks, CapLinked, ShareVault, Dropbox by their public wording) — that is not evidence the report is a Type I; it is simply unstated, and your move is to ask for the report cover, which names the Type explicitly. Most of these vendors do produce Type II reports; you just want to see it rather than infer it.
Now the precision beat, because a careful LP or security reviewer will notice if you get it wrong: SOC 2 is an attestation, not a certification. It is produced under the AICPA's attestation standards (SSAE 18) by a licensed CPA firm that examines a service organization's controls against the Trust Services Criteria — Security (the mandatory common criteria), Availability, Confidentiality, Processing Integrity, and Privacy — and issues an opinion. There is no certificate and no accredited "SOC 2 body." ISO 27001, by contrast, is a certification — issued by an accredited certification body against the ISO/IEC 27001 standard, with a defined scope and a Statement of Applicability. The practical difference for you: for SOC 2 you ask for a report; for ISO 27001 you ask for a certificate and the SoA.
Here is the honest part. The entire industry — vendors, buyers, and yes, our own site's shorthand — routinely writes "SOC 2 certified." It is technically imprecise, and it is so widely used that fighting it in every sentence would make this post unreadable. So I will define it correctly once, here, and then use "attestation" where precision matters and tolerate "certified" as the shorthand everyone understands elsewhere. If you are writing a DDQ answer or an SSP, use the precise words: SOC 2 attestation (Type II) and ISO 27001 certification. If you are talking to a vendor's sales team, "SOC 2 certified" will be understood and no one will correct you.
How to actually read a SOC 2 report (from the inside of Peony's own Type II)
When the report finally lands — the real one, not the badge — most people open it, see 60 to 100 pages, and skim the first two. Here is how to read it in the order that surfaces the things you actually care about, drawn from sitting through Peony's own Type II. A SOC 2 report has four parts, and they are not equally important to a buyer.
- The independent auditor's opinion. This is the CPA firm's letter, and it is the first thing to read, not the last. You want the word unqualified (sometimes phrased as the controls being fairly presented and operating effectively). A qualified opinion means the auditor found something material worth calling out; a qualified opinion is not automatically disqualifying, but it is a "read the exceptions carefully and ask questions" signal. Confirm the Type (II) and the review period dates here too.
- Management's assertion. A short statement from the vendor's management asserting that the system description is accurate and the controls are suitably designed and operating. It is the vendor putting its name on the claim. Useful for confirming scope, rarely where surprises hide.
- The system description. The vendor's narrative of what the system is, what it does, the infrastructure, the people, and the controls in place. This is where you confirm that the report actually covers the product you are buying — not a parent company, not a different service line. Read the scope boundary carefully; a report can be genuine and still not cover the thing you thought it did.
- The controls, tests of controls, and results. This is the long section, and it is where the truth lives. For each control, the auditor lists the test performed and the result — and this is where exceptions hide. An exception is an instance where the control did not operate as intended during the period. A report can carry a handful of exceptions and still be a strong report if management responded appropriately; a report with no test-results detail at all is not really giving you assurance. Read the test-results tables, not just the opinion letter — a vendor summary that says "we passed SOC 2" is not a substitute for the exceptions column.
The part almost everyone misses is the complementary user entity controls (CUECs) — sometimes a dedicated section, sometimes threaded through the controls table. CUECs are the controls that you, the customer, must run for the vendor's controls to actually protect you. The vendor's SOC 2 assumes you are doing your part; if you are not, the report's assurance does not extend to your usage. In plain terms: the vendor secures the room, but you are responsible for who you hand keys to and whether you take them back.
For a data room specifically, here is a runnable 6-item CUEC checklist — the customer-side controls a VDR's SOC 2 almost always assumes you operate:
- Offboard your own users promptly. When a banker, advisor, or counterparty leaves the deal, you remove their access. The vendor cannot know your deal roster changed.
- Enforce your own MFA/2FA policy. Turn on and require two-factor authentication for your admins and users; the platform offers it, but enabling and mandating it is on you.
- Manage permissions and least privilege. Set folder- and document-level access to the minimum each viewer needs, and review it as the deal evolves. Over-permissioning is a customer control failure, not a vendor one.
- Protect your credentials and admin accounts. Strong, unique passwords; no shared logins; guard the admin seat especially, since it can change everyone else's access.
- Review your own access logs and alerts. The room produces the audit trail; you are expected to actually look at it and act on anomalies (unexpected downloads, logins from odd locations).
- Configure sharing controls to your risk level. Watermarking, download restrictions, link expiry, screenshot protection, NDA gates — the platform provides them; deciding which to enforce for a given room is your control to operate.
I put this checklist here because it is the most common way a "SOC 2 compliant data room" still ends up in an incident: the vendor's controls held, and the customer never revoked a departed advisor's access. Reading the CUEC section is how you find your half of the job.
Claiming vs evidencing: the evidence-access taxonomy
A certification claim and a certification you can obtain are different assets, and the gap between them is where DDQ timelines go to die. I sorted the fourteen vendors by how you actually get the evidence, because that is the axis a buyer feels, and it is the one most comparison content ignores entirely.
- Ungated certificate downloads — the best-in-field experience. iDeals does this best, and it deserves plain credit: its security page offers direct, ungated "Download certificate" links for ISO 27001, 27017, 27018, and 27701. No form, no NDA, no sales call — you click and you have the artifact. If more vendors did this, posts like mine would be shorter. (Note that iDeals moved this content to
idealsvdr.com/virtual-data-room-security/; the older/securityURL now 404s.) - Self-serve report in-product — no request form. Peony serves the SOC 2 Type II report and the DPA directly inside the product on the Deal Team plan ($64/admin/month), with no request form — which, in this set of fourteen, is a distinct model. Most vendors make you ask a human; the report sits behind a self-serve wall you already have credentials for. I mention it because it is the evidence-axis answer to Peony's ISO gap: you cannot get a certificate we do not hold, but you can get the report we do hold without waiting on anyone.
- NDA-gated portals. DealRoom (trust.dealroom.net), Box, and Dropbox put the report behind a trust portal that requires an NDA or account before it releases documents. This is a completely legitimate, common posture — plenty of mature programs gate their reports — but budget a day or two of legal turnaround before you can cite the artifact.
- Stated, but nothing downloadable. The largest group states the claim on a public page with no artifact attached: Datasite, Ansarada, CapLinked, Digify, ShareVault, and SecureDocs. For these, "verify the claim" means emailing the vendor and asking for the current report or certificate directly. That is where the template below earns its keep.
One category note worth keeping in your matrix: DealRoom states its ISO 27001 is "in progress." "In progress" is not "held," and the distinction deserves to be named plainly — a certification that is being pursued is a roadmap item, not an assurance you can rely on today. Record it as in-progress, not as a yes, and re-check before you sign.
When the evidence lives behind an email, the thing to ask for is not just the report but a bridge letter — a short statement from the vendor's management (not the auditor, who will not attest to a period it has not audited) covering the gap between the end of the last audit window and today. If a SOC 2 Type II period ended, say, four months ago, the report technically speaks only to that window; a bridge letter attests that no material control changes have occurred since. Here is a copy-paste template you can send:
Subject: SOC 2 Type II report + bridge letter request
Hi [name],
We're evaluating [product] for a live diligence process and need to complete a vendor security review. Could you please share:
- Your current SOC 2 Type II report (we're specifically confirming Type II and the review-period end date),
- A bridge (gap) letter covering the period from the end of that review window to today, and
- Your ISO 27001 certificate and Statement of Applicability, if held in [vendor]'s own corporate name (not a data-center or cloud-host certificate).
If any of these are gated, an NDA is fine — please send it over and we'll turn it around same day.
Thanks, [you]
That single email resolves most of the ambiguity in this whole space: it forces the Type to be stated, the freshness to be covered, and the ISO scope (corporate vs inherited) to be disclosed. If a vendor cannot produce a bridge letter or dodges the ISO-scope question, that is a data point too.
The fund and LP-DDQ angle: exact wording and how to answer it
The anchor persona for this whole post is the fund ops or IR person with an LP due diligence questionnaire open, because "for funds" is in the query and because the DDQ is where all of this abstraction turns into a box you have to fill. LP operational DDQs (the ILPA-style templates most funds see) phrase the data-room question in a few recognizable ways:
"Is the fund's data room / document portal SOC 2 and/or ISO 27001 certified? Provide the current report(s) and describe data residency."
or, more granularly:
"For any third-party system used to store investor or portfolio data, provide: (a) SOC 2 Type II report or ISO 27001 certificate, (b) date of last audit, (c) data hosting location and cross-border transfer mechanism."
Here is how to answer it truthfully, mapped to the vendor tiers in the matrix rather than to a single recommendation:
- If you use a both-certs vendor (Datasite, Box): answer "yes" to both, attach the SOC 2 Type II report (via the vendor's trust portal / NDA) and the corporate ISO 27001 certificate, and state the last-audit date from the report cover. Clean.
- If you use a strong-SOC-2, obtainable-evidence vendor (Peony, iDeals, DealRoom, Firmex): answer "SOC 2 Type II — yes; report available [self-serve / on request / NDA portal]." For ISO 27001, answer precisely: "corporate ISO 27001 — no" for Peony and Firmex-corporate, or "ISO 27001 certificates available for download" for iDeals, or "in progress" for DealRoom. Do not paper over the ISO answer; a precise "no, and here's the strong SOC 2 instead" reads as more credible to an experienced LP than a vague "we're compliant."
- If you use a vendor whose ISO is inherited (CapLinked, SecureDocs, and any AWS-inheritance claim): never write "ISO 27001 certified" on the DDQ. Write the true thing: "hosted on ISO 27001-certified infrastructure (AWS); the vendor's own corporate ISO 27001 is not stated." An LP who catches an inherited badge presented as a corporate certificate will trust the rest of your answers less.
Then there is the data residency sub-question, which the fan-out version of this query asks explicitly ("...and data residency options"). Here is the one-paragraph answer for Peony, per our site canon, that you can adapt:
Peony's standard plans host data in the US (AWS
us-east-1) and rely on Standard Contractual Clauses for EU personal data — a legitimate, common arrangement for cross-border diligence, backed by a DPA and a publicly listed set of sub-processors (AWS, Vercel, Cloudflare, Stripe). For buyers who require data to remain in-region as a matter of policy or counterparty mandate, custom UK or EU data residency, bring-your-own-key (BYOK), and self-hosted deployment are available on Peony's Enterprise plan. So the standard plans are US-hosted with contractual transfer safeguards; the in-region requirement is an Enterprise conversation.
The reason to write residency as its own paragraph is that an LP DDQ increasingly treats hosting location and transfer mechanism as a distinct line from certification — a vendor can hold every certificate you want and still host in a region your side letter forbids. Answer certification and residency separately, and you will pre-empt the follow-up.
How do you compare data room vendors on ISO 27001 and SOC 2?
Compare on three axes at once — claim strength, evidence access, and scope/residency — never on a single "is it certified" checkbox, because a single checkbox is exactly how buyers end up with an inherited badge on their DDQ. This is also, per our data, the query that currently lands on generic listicles and gets a weak answer; here is the concrete method the matrix above is built to support.
Axis 1 — Claim strength. For SOC 2: does the vendor state a Type? Type II beats an unstated Type beats Type I for a live-deal room. For ISO 27001: is it a corporate certificate in the vendor's own name, or inherited from the data center or cloud host? Corporate beats data-center-scoped beats "hosted on ISO-compliant servers." And treat "in progress" (DealRoom's ISO wording) as a roadmap item, not a held certificate. This axis is a two-column spreadsheet entry per vendor, and it is where most of the real signal is.
Axis 2 — Evidence access. Can you obtain the artifact, and how fast? Rank the four modes by lead time: ungated download (iDeals) → self-serve in-product (Peony) → NDA-gated portal (DealRoom, Box, Dropbox; budget legal turnaround) → stated but nothing downloadable (Datasite, Ansarada, CapLinked, Digify, ShareVault, SecureDocs; email required). A claim you cannot cite by your DDQ deadline is functionally weaker than one you can, regardless of how strong the underlying program is.
Axis 3 — Scope and residency. What does the certificate actually cover — the corporation or a single data center — and where does the data sit? A Firmex ISO that covers data centers is a different assurance than a Datasite ISO that covers the corporation, even though both say "ISO 27001." And residency (US us-east-1 with SCCs vs in-region UK/EU hosting) is a separate question from certification entirely, so give it its own column.
Put those three axes into your RFP compliance sheet as columns — SOC 2 (Type) | ISO 27001 (corporate/inherited/in-progress) | Evidence mode | Residency — copy the matrix rows straight in, then send every shortlisted vendor the bridge-letter email above to convert claims into artifacts. That is the whole method: don't compare the badges, compare the evidence you can actually hold, and record the scope precisely enough that a skeptical LP or acquirer's counsel can't poke a hole in your answer. If you want the broader multi-framework context beyond these two certs, the document sharing compliance guide covers how SOC 2 and ISO 27001 sit alongside HIPAA, GDPR, and the rest for operators; for the defense-contractor CUI layer specifically, CMMC-compliant file sharing owns that lane, and ITAR-compliant data rooms cover export-controlled material.
A methodology note (so you can re-run this yourself)
Every claim in this post traces to a vendor's own public page, read on our verification date in August 2026. I checked security, trust, and compliance pages directly — for example Peony's security page, idealsvdr.com/virtual-data-room-security/, datasite.com/en/resources/faqs/compliance, intralinks.com/trust, firmex.com/virtual-data-room/security/, ansarada.com/data-room/transactions-security, dealroom.net/trust/overview, caplinked.com/security/, digify.com/features/security/, sharevault.com/security/, box.com/trust, and dropbox.com/business/trust. Where a page was JavaScript-rendered and not readable by a static fetch (Google Workspace's security page this pass), I flagged the row rather than fill it from memory. Where a URL had moved (iDeals's old /security, SecureDocs's domain now 301-redirecting to onit.com/products/clm/securedocs/), I noted the redirect.
Two disciplines make this dataset trustworthy and easy to challenge. First, I recorded each cell in the vendor's own words — "SOC 2 & SOC 3 Certified," "in progress," "hosted on ISO 27001-compliant servers" — rather than translating it into a claim the vendor did not make. Second, I did not add a single vendor fact from anywhere but those pages; if a vendor does not state a Type, the cell says so instead of guessing. Vendor pages change, certifications lapse and renew, and reports roll over annually — so treat this as a snapshot with a date stamp, not a permanent record, and re-verify the specific rows that matter to your deal before you rely on them.
That is also why Peony's own security page states the SOC 2 Type II and the ISO 27001 "no" in the same breath, and why the report and DPA are self-serve on the Deal Team plan rather than gated behind a form: the fastest way to be trusted on a security claim is to make the evidence easy to get and to concede the gaps out loud. Peony serves 6,800+ customers on that posture, and the flat "no" on ISO 27001 has cost us fewer deals than blurring the line ever would have. If corporate ISO 27001 is a hard requirement for your LPs, this matrix names the rows that hold it; if a strong, obtainable SOC 2 Type II is what you actually need, that is a lane Peony is built for — and, 6,800+ customers in, an obtainable report has mattered more to buyers than the length of a badge list.
Related reading
- Best Datasite alternatives — cheaper rooms with comparable security, and the canonical source for how these cert claims map to pricing and fit.
- Best Ansarada alternatives — including the note that Ansarada states no SOC 2 claim on its security page.
- Document sharing compliance guide — SOC 2 and ISO 27001 in the wider multi-framework picture (HIPAA, GDPR, and more).
- CMMC-compliant file sharing — the defense-contractor CUI layer that sits next to, not inside, this certification question.
- ITAR-compliant data rooms — export-controlled material and the residency questions that come with it.
- Top 10 virtual data room providers and top 10 secure file-sharing tools — the broader landscape these fourteen vendors sit within.
You might also like
Jul 16, 2026
Data Room Security Questionnaire: How to Evaluate Any VDR Vendor (2026)
May 15, 2026
Third-Party Due Diligence: The 5-Jurisdiction Framework for 2026 (Post-FCPA Pause)
Apr 10, 2026
I Tested 7 Cannabis Data Rooms (What Regulators Accept) in 2026

