
A secure data room is three layers doing their jobs: platform security (encryption, isolation, backups, audited controls), file security (watermarks, download and print restrictions, activity logs), and user security (MFA, guest expiration, role restrictions). Verify each layer with evidence, not badges: the SOC 2 report, the export, the setting.
Security is three layers, and vendors blur them
Vendor security pages tend to be one undifferentiated list of reassuring words. In practice a data room's security is three separate layers, each with its own failure mode, and the useful evaluation keeps them apart:
| Layer | What it controls | How it fails |
|---|---|---|
| Platform | Encryption in transit and at rest, tenant isolation, key management, backups, the provider's own audited controls | Rarely and catastrophically. This is what SOC 2 examines |
| File | Watermarking, download and print restrictions, expiry, the activity log on each document | Quietly. A document travels and nobody can say where it went |
| User | Who is invited, what each party can see, MFA, guest expiry, offboarding | Constantly. Almost every real incident is an access mistake, not broken cryptography |
The layer that actually fails is the user layer
Encryption is table stakes and, honestly, not where deals go wrong. TLS in transit and AES-256 at rest are the industry floor, and no commercial data room loses documents because someone broke the cryptography. Documents leak because a guest was invited to the wrong folder, because access was never removed after a deal died, or because a file left the room and nobody could prove where it went.
That reframes what to interrogate. Granular permissions, at folder and at file level, are not a luxury tier; they are the control that prevents the failure that actually happens. Guest lifecycle, invitation, scope, expiry, and offboarding, is the second. In a closing, the majority of participants are guests, so guest handling is not an edge case, it is the main case.
Guests: the main case, not the edge case
A commercial closing invites the borrower, borrower's counsel, lender's counsel, title, surveyors, and appraisers. Almost none of them are your employees, and each one needs exactly one slice of the room, for a bounded period.
The controls that make that safe rather than terrifying:
- Scope at file and folder level, per partyNot per room. A borrower with room-level access eventually opens something written for the credit committee.
- Multi-factor authentication for guests, not just staffGuests hold the same documents your team does.
- Invitation and expiry with an ownerAccess that outlives the deal is the most common quiet exposure in any room.
- Inactive-guest expirationThe dead-deal problem: rooms nobody closed, guests nobody removed, documents still reachable.
- Approval on guest accessSomeone accountable decides who gets in, and that decision is on the record.
- Watermarking on anything that travelsUser, organization, and timestamp stamped into appraisals, financials, and anything a participant downloads, so confidentiality does not end at download.
Evidence beats adjectives
Every vendor says bank-grade. The word means nothing; the artifacts mean everything. Ask for four things, and treat their absence as the answer:
The SOC 2 report itself, not a badge on a website. Prodeal is SOC 2 audited annually against the AICPA standard and its Type II report is available to customers for exactly this review. The permission model demonstrated on a real structure, showing that a guest can be scoped to a single file. A live activity export, produced during the evaluation, with actors and timestamps intact. And a straight answer on where data lives, who at the provider can reach it, and what the breach-notification commitment is.
Frameworks help you ask consistently: SOC 2 for the provider's own controls, ISO 27001 for its security management system, and the NIST Cybersecurity Framework as a vocabulary for the conversation. None of them is a substitute for reading the report.
Security and the audit trail are the same feature
The activity log is usually filed under reporting, but it is a security control: it is how a permission model proves it worked. Scoping access is the claim; the log is the evidence. When a security review or an examiner asks who could see the borrower's financials and who actually did, the answer should be a report you export in a minute.
This is why, for lenders, security is not a separate evaluation from the closing workflow. The same record that satisfies an examiner sampling a two-year-old file is the record that answers a security question today, which is the argument for the closing, the documents, and the audit record living in one system rather than three.
Questions lenders ask
- What makes a virtual data room secure?
- Three layers doing their jobs: platform (encryption in transit and at rest, isolation, backups, independently audited controls), file (watermarking, download restrictions, per-document activity logs), and user (per-party scoping, MFA, guest expiry, offboarding). The user layer is where real incidents happen.
- Is encryption the most important data room security feature?
- No. Encryption is the floor, and no commercial room loses documents to broken cryptography. Documents leak through access mistakes: a guest invited to the wrong folder, access never removed after a dead deal, or a file that traveled with nothing stamped on it. Granular permissions and guest lifecycle matter more.
- What should I ask a data room vendor about security?
- Ask for artifacts, not adjectives: the SOC 2 report itself, a demonstration of file-level scoping for a guest, a live activity export with actors and timestamps produced during the evaluation, and a straight answer on data location, provider access, and breach notification.
- How should guest access be handled in a closing?
- As the main case, since most participants in a closing are external. Scope each party at folder and file level, require MFA for guests, put an owner and an expiry on every invitation, expire inactive guests, and approve access on the record.
- Does SOC 2 mean a data room is secure?
- It means the provider's controls were independently examined against a standard, which is necessary and not sufficient. Read the report rather than the badge, and evaluate the layers it does not cover, chiefly your own permission and guest hygiene. Prodeal is SOC 2 audited annually and its Type II report is available to customers.