How it plays out on a deal
Every reputable data room encrypts traffic, and modern browsers show warnings when a site does not. The useful details are the protocol versions accepted, whether older and weaker versions are switched off, and whether email links and mobile apps follow the same rules.
A buyer's IT team can check much of this independently with public testing tools before signing, which is quicker than waiting for a vendor questionnaire to come back.
What to check in a review or demo
- 1Which TLS versions are accepted and whether older ones are disabled.
- 2Whether file uploads, mobile apps and API calls use the same encryption.
- 3Whether the provider's security page states this clearly or only in a questionnaire.
Read alongside
- Encryption at restScrambling stored files, backups included, so that anyone who walks off with a disk or a backup set gets unreadable data unless they also hold the keys.
- AES-256The Advanced Encryption Standard with a 256-bit key, a widely used symmetric cipher that most data rooms cite for encrypting stored files.
- API accessA documented programming interface that lets other systems create rooms, move files, manage users or pull reports from the data room automatically.
- Mobile appA native phone or tablet application for reading documents, answering questions and checking activity in the data room, as opposed to using the website in a mobile browser.