Index processing happens in your browser
When you upload an Excel or CSV index to the builder, it is parsed locally on your machine. The folder tree and ZIP skeleton are generated client-side — the index file is not sent to our servers.
This page states exactly how DataRoomBuilder handles your information today — what runs in your browser, what is gated, and what we deliberately do not claim yet.
The live builder
When you upload an Excel or CSV index to the builder, it is parsed locally on your machine. The folder tree and ZIP skeleton are generated client-side — the index file is not sent to our servers.
The builder works from a request list or folder index. It never needs — and never asks for — your confidential deal documents to produce a data-room structure.
You can use the live index-to-folder builder without creating an account or handing over contact details.
Portal & admin
Client portal engagements are reached through tokenised share links. Tokens are stored as httpOnly cookies scoped to a single engagement — one client's link never opens another client's workspace.
Operational admin pages sit behind a session gate. In production, if the gate is not explicitly configured, admin routes reject all requests rather than defaulting open.
All portal and admin routes are served with noindex/nofollow headers so client workspaces never appear in search results.
Session tokens are compared using constant-time comparison, and admin sessions expire automatically.
The VDR layer being built connects to cloud storage you already control — starting with Google Drive via OAuth — rather than asking you to migrate confidential documents into yet another vendor silo. Connectors are in development and clearly labelled as foundations, not finished features.
Live today
In-browser index-to-folder builder, downloadable templates, and the access controls described above.
In development
Client IRL portal and BYO-cloud connectors (starting with Google Drive via OAuth) are foundations under active build — labelled as such across the site.
Not yet claimed
We do not currently hold SOC 2 or ISO 27001 certification, and we won't imply otherwise. Formal audits are on the roadmap as the platform layer matures.
Trust center
Traditional data rooms copy your most sensitive documents onto the vendor's servers — a second copy, a second audit trail, a second place that can be breached, and a copy that outlives the deal. Data Room Builder is a control plane over storage you already own (Google Drive, OneDrive/SharePoint, Dropbox, Box, S3). We hold encrypted access tokens and metadata — never a copy of your data room.
A worst-case compromise of DRB exposes encrypted OAuth tokens and metadata — not a lake of client documents, because DRB holds no document lake. The sensitive corpus stays in your tenant, under your existing controls.
Withdraw DRB's access from your own cloud admin console and every connection is cut instantly — independent of us. When a deal closes there is no vendor to delete your data from, because there was never a copy to delete.
Data lives in the tenant and region you already chose. DRB adds no new residency surface — your existing GDPR and data-sovereignty posture applies without change.
We describe controls we actually operate. Data Room Builder is built to a SOC 2-ready architecture and designed around SOC 2 / ISO 27001 control families; formal certification is on the roadmap and we will publish attestations when independently audited — we do not claim certificates we do not hold.
Questions answered directly
Test the builder with a non-sensitive index, or ask us anything about the security model and the BYO-cloud roadmap. See also what is live versus planned.