Security and data handling

Deal data deserves plain answers, not badges.

This page states exactly how DataRoomBuilder handles your information today — what runs in your browser, what is gated, and what we deliberately do not claim yet.

The live builder

Your index never leaves your machine.

Index processing happens in your browser

When you upload an Excel or CSV index to the builder, it is parsed locally on your machine. The folder tree and ZIP skeleton are generated client-side — the index file is not sent to our servers.

Only folder names, never deal documents

The builder works from a request list or folder index. It never needs — and never asks for — your confidential deal documents to produce a data-room structure.

No account required for the builder

You can use the live index-to-folder builder without creating an account or handing over contact details.

Portal & admin

Access is gated by default.

Portal access via scoped share links

Client portal engagements are reached through tokenised share links. Tokens are stored as httpOnly cookies scoped to a single engagement — one client's link never opens another client's workspace.

Admin routes fail closed

Operational admin pages sit behind a session gate. In production, if the gate is not explicitly configured, admin routes reject all requests rather than defaulting open.

Workspaces are kept out of search engines

All portal and admin routes are served with noindex/nofollow headers so client workspaces never appear in search results.

Hardened session checks

Session tokens are compared using constant-time comparison, and admin sessions expire automatically.

BYO-cloud: your documents stay in your storage.

The VDR layer being built connects to cloud storage you already control — starting with Google Drive via OAuth — rather than asking you to migrate confidential documents into yet another vendor silo. Connectors are in development and clearly labelled as foundations, not finished features.

Live today

In-browser index-to-folder builder, downloadable templates, and the access controls described above.

In development

Client IRL portal and BYO-cloud connectors (starting with Google Drive via OAuth) are foundations under active build — labelled as such across the site.

Not yet claimed

We do not currently hold SOC 2 or ISO 27001 certification, and we won't imply otherwise. Formal audits are on the roadmap as the platform layer matures.

Trust center

Your documents never leave your cloud. There is no second copy to breach.

Traditional data rooms copy your most sensitive documents onto the vendor's servers — a second copy, a second audit trail, a second place that can be breached, and a copy that outlives the deal. Data Room Builder is a control plane over storage you already own (Google Drive, OneDrive/SharePoint, Dropbox, Box, S3). We hold encrypted access tokens and metadata — never a copy of your data room.

Blast radius, quantified

A worst-case compromise of DRB exposes encrypted OAuth tokens and metadata — not a lake of client documents, because DRB holds no document lake. The sensitive corpus stays in your tenant, under your existing controls.

Revoke us in one click

Withdraw DRB's access from your own cloud admin console and every connection is cut instantly — independent of us. When a deal closes there is no vendor to delete your data from, because there was never a copy to delete.

Your residency, unchanged

Data lives in the tenant and region you already chose. DRB adds no new residency surface — your existing GDPR and data-sovereignty posture applies without change.

Controls we run today

  • Named admin accounts with enforced two-step (email OTP) verification
  • Idle and absolute session timeouts; login brute-force lockout
  • Per-participant, individually-revocable access links (no shared room password)
  • Revoking a participant instantly cuts further access — expiring, single-use download grants and their live-view sessions stop working at once (already-downloaded copies can't be recalled)
  • Role, group and folder/file-level permissions with clean-team (deny-all) support
  • Secure in-browser viewer with per-viewer dynamic watermarking (identity · IP · time)
  • Uploads scanned before they reach your cloud; SHA-256 integrity hash on every file
  • Full audit trail (views, downloads, permission changes) with exportable evidence pack
  • TLS 1.2+ in transit; OAuth tokens encrypted at rest; security headers (HSTS, CSP)
  • Server-side authorization and record-ownership checks on every document action

Honest compliance posture

We describe controls we actually operate. Data Room Builder is built to a SOC 2-ready architecture and designed around SOC 2 / ISO 27001 control families; formal certification is on the roadmap and we will publish attestations when independently audited — we do not claim certificates we do not hold.

  • AI governance: the AI assistant is provider-agnostic; your documents are never used to train models, and access is permission-scoped and audited.
  • Sub-processors: Vercel (hosting), Supabase (metadata). Documents remain with your chosen storage provider.
  • Responsible disclosure: published at /.well-known/security.txt with an explicit safe-harbour.
  • SOC 2-ready architecture and ISO/IEC 42001-aligned AI governance — control mapping available on request.

Questions answered directly

Want detail on data handling before a live deal?

Test the builder with a non-sensitive index, or ask us anything about the security model and the BYO-cloud roadmap. See also what is live versus planned.

Try the builder
Security & Data Handling | Data Room Builder