How it plays out on a deal
A data room is a channel into many organizations at once. A single infected file uploaded by a seller, or by a bidder into a drop folder, could reach every reader. Scanning on upload is a simple control that removes that path.
It is common but not universal, and vendors rarely advertise it. The questions are whether every upload is scanned, what happens to a flagged file and whether the administrator is told.
What to check in a review or demo
- 1Whether every upload is scanned, including bidder uploads and Q&A attachments.
- 2What happens to a flagged file and who is notified.
- 3Whether scanning is mentioned in the vendor's security documentation or audit scope.
Read alongside
- Bulk uploadUploading many files and folders at once, typically by dragging a whole directory into the browser, with the folder structure kept intact.
- Penetration testingA hired security team tries to break into the platform with the owner's permission, then reports the holes it found so they can be closed.
- SOC 2An attestation from a licensed CPA firm, under AICPA rules, that a software company's security controls are designed well (Type I) or also worked over several months (Type II).