How it plays out on a deal
AES-256 appears on nearly every data room security page. It is a sound choice and not a differentiator. Breaches rarely come from breaking the cipher; they come from stolen passwords, misconfigured permissions and people forwarding files.
So when a vendor leads with its encryption standard, the better follow-up questions are about everything around it: login controls, key handling, audit coverage and independent attestation of how the system is run.
What to check in a review or demo
- 1Whether AES-256 covers primary storage, backups and any cached previews.
- 2How keys are stored and who can use them.
- 3Which independent report confirms the encryption claims.
Read alongside
- Encryption at restScrambling stored files, backups included, so that anyone who walks off with a disk or a backup set gets unreadable data unless they also hold the keys.
- Encryption in transitProtecting data while it moves between a user's device and the provider's servers, normally with TLS, so it cannot be read or altered on the way.
- Customer-managed keys (CMK)An option in which the client, not the provider, controls the encryption keys for its data, often through its own cloud key service.
- Two-factor authentication (2FA)A login that needs a second proof of identity besides the password, such as a code from an authenticator app, a text message or a hardware key.