Companies use virtual data rooms to share some of their most sensitive information with buyers, investors, lawyers, advisers, auditors, and other external parties. Financial records, contracts, intellectual property, employee information, customer data, and transaction documents may all pass through the same workspace.

Strong virtual data room security therefore requires more than encrypting stored files. Administrators need to control who can enter the room, what each participant can see, what they can do with documents, when their access ends, and how their activity is recorded.

EthosData became part of Ideals in 2024. EthosData customers now use the Ideals virtual data room platform, combining EthosData's transaction support with Ideals' permission controls, document security, reporting, infrastructure, and compliance framework. Read more about the EthosData acquisition by Ideals.

EthosData security at a glance: The Ideals platform behind EthosData combines AES-256 encryption, two-step verification, eight document permission levels, Fence View, dynamic watermarks, protected downloads, audit trails, AI-assisted redaction, data-hosting controls, and enterprise security options.

EthosData virtual data room security features

EthosData uses a layered security model. Each layer addresses a different risk, from unauthorized account access to legitimate users receiving more document access than they need.

Encryption

AES-256 encryption protects stored data, while TLS protects files during transmission between users and the platform.

Identity security

Two-step verification, email verification, password controls, session settings, and enterprise SSO help protect user accounts.

Granular permissions

Eight document permission levels let administrators control how separate user groups can interact with confidential files.

Document protection

Fence View, dynamic watermarks, encrypted downloads, and spreadsheet controls provide additional protection after access is granted.

Auditability

Detailed activity records help administrators monitor user behavior and maintain an auditable record of disclosure.

Infrastructure security

Data residency options, redundancy, backup, disaster recovery, and secure hosting support business continuity during live transactions.

Swipe left to see the full table.
Security areaEthosData / Ideals capabilityWhy it matters
EncryptionAES-256 at rest and TLS in transitProtects confidential information while stored and transferred.
AuthenticationTwo-step verification and additional identity controlsReduces reliance on passwords alone.
PermissionsEight document permission levelsLets administrators control disclosure by participant group and document.
Document protectionFence View, watermarks, protected downloads, spreadsheet controlsLimits what authorized users can do with sensitive information.
Access restrictionsAccess schedules, expiration, IP and domain restrictionsHelps restrict where, when, and for how long users can access a project.
MonitoringDetailed audit trails and activity reportingProvides visibility into user and document activity.
AI protectionAI-assisted redaction within the secured platform environmentHelps identify sensitive information before disclosure.
Enterprise controlSSO and centralized multi-project administration on applicable plansSupports consistent security across larger deal programs.

What is virtual data room security?

Virtual data room security is the combination of technical and administrative controls used to protect confidential information throughout a transaction or other sensitive business process. It includes encryption, identity verification, permissions, document-level controls, monitoring, secure infrastructure, and procedures for changing or revoking access.

A VDR differs from general-purpose cloud storage because it is designed for controlled disclosure. The objective is not simply to store a file securely. It is to control how external participants interact with that file throughout its lifecycle.

Virtual data room security is strongest when encryption, identity controls, granular permissions, document protection, and auditability work together rather than as separate features.

For a broader look at confidential file exchange, see our guide to secure file sharing for business.

Encryption of data in transit and at rest

Encryption forms the technical foundation of EthosData security. The Ideals platform protects stored files with 256-bit AES encryption and uses TLS to protect data during transmission.

These controls address separate risks. Encryption at rest protects information stored within the platform. Encryption in transit protects information while it moves between the user's device and the VDR.

However, encryption alone does not determine whether a transaction is secure. An encrypted document may still be exposed if too many users receive access, unrestricted copies are downloaded, or stale accounts remain active. EthosData therefore combines encryption with permissions, authentication, document controls, and monitoring.

Security principle: Encryption protects the underlying data, while permissions and document controls determine how that data can be used after an authorized participant receives access.

Granular permissions and access controls

Access control is one of the strongest areas of the Ideals platform behind EthosData. Administrators can organize users into groups and assign different permissions according to the information each group needs.

Ideals provides eight document permission levels:

  1. No access
  2. Fence
  3. View
  4. Encrypted
  5. PDF
  6. Original
  7. Upload
  8. Manage

This permission model is particularly useful during staged due diligence. An initial bidder group might receive access to high-level commercial information, while shortlisted parties later receive additional contracts, financial records, or operational data.

Highly sensitive material can remain restricted until the transaction reaches the appropriate stage. This supports a least-privilege approach in which users receive only the access necessary for their role.

Access schedules and expiration

Access can be limited by date and time so that participants do not remain active indefinitely. This is useful for temporary advisers, bidder groups, consultants, or other users whose involvement ends at a specific stage.

IP and domain restrictions

Administrators can restrict access by IP address or email domain. These controls add another layer when a project should be accessible only through approved corporate accounts or networks.

Two-step verification

Two-step verification requires an additional identity check beyond a password. This reduces the risk that compromised login credentials alone will provide access to a live transaction.

For more on setting up user groups and permissions during a project, see our guide to setting up a virtual data room.

Virtual data room document security features

Virtual data room document security features become important after an authorized user has entered the room. Access controls determine whether a participant can reach a document. Document controls determine what that participant can do after access has been granted.

Fence View

Partially conceals documents so only the area around the user's cursor remains clearly visible, reducing exposure during sensitive review.

Dynamic watermarks

Add user and access information to supported documents so unauthorized redistribution is more traceable.

Protected downloads

Encrypted permission lets supported files remain protected after download and allows access to be revoked in supported scenarios.

Spreadsheet controls

Supported Excel files can be viewed with formula visibility controlled, helping protect proprietary financial models and calculations.

Fence View

Fence View overlays a moving striped pattern across most of the document and reveals the area around the user's cursor. It is designed for situations where information must be reviewed without offering an unrestricted full-page view.

This can be useful for intellectual property, customer-level information, pricing schedules, sensitive contracts, or other material that should be disclosed cautiously.

Dynamic watermarks

Dynamic watermarks can include identifying information such as the participant's name, IP address, or access time. This creates accountability and can help trace the source of material if it is redistributed.

Encrypted and revocable downloads

A conventional download can weaken control because an unrestricted copy may remain available after a user leaves the process. Ideals supports encrypted downloads for compatible files. These protected files require authentication and can lose access when the administrator changes permissions, deactivates the participant, or closes the project.

Secure spreadsheet viewing

Spreadsheets frequently contain more sensitive information than their visible values suggest. Formulas can expose assumptions, pricing methodology, forecasts, or proprietary calculations.

Ideals provides formula visibility controls for supported Excel files, allowing teams to share financial information without necessarily exposing the underlying calculation logic.

For a broader look at protecting documents throughout their lifecycle, see our guide to secure document management.

Ideals virtual data room security features behind EthosData

EthosData became part of Ideals in 2024. Its customers now use the Ideals VDR platform, which means the security proposition is based on Ideals' technology rather than a separate legacy EthosData platform.

EthosData combines transaction support with the Ideals VDR platform, including eight permission levels, Fence View, dynamic watermarking, protected downloads, secure spreadsheet viewing, audit trails, AI-assisted redaction, and enterprise access controls.

The strongest Ideals virtual data room security features are particularly relevant to M&A and due diligence because they address controlled disclosure rather than simple file storage.

Eight permission levels

Control how separate participant groups view, download, upload, or manage documents.

User-view verification

Administrators can preview the data room from a user's perspective to verify what that participant can actually see.

Remote shred

Supported protected documents can have download duration controlled and access revoked after they leave the data room.

Secure spreadsheet viewer

Review supported Excel files online while controlling access to underlying formulas.

Immutable audit trails

Maintain detailed records of user actions inside the data room for monitoring and later review.

Enterprise identity controls

Enterprise plans can support centralized administration and SSO for organizations managing multiple projects.

For a deeper review of the platform behind EthosData, including its document tools, AI capabilities, pricing, and security, see our Ideals VDR review.

Audit trails and activity monitoring

Security does not stop when a user successfully logs in. Administrators also need visibility into what authorized participants do inside the project.

Ideals provides detailed audit trails and reporting that can help teams review user and document activity. This is useful during a live deal and when an organization needs to reconstruct disclosure after signing or closing.

For transaction teams, activity records can help answer practical questions such as which users entered the room, which documents attracted attention, and when particular actions occurred.

Why auditability matters: A secure process should not only restrict access. It should also create a defensible record of how confidential information was disclosed and reviewed.

Data hosting, residency, and operational resilience

Document permissions protect information at the user level, but VDR security also depends on the infrastructure underneath the project.

Ideals provides supported data-hosting locations across multiple geographic regions. This allows organizations to consider residency requirements when selecting how a project is configured.

The platform also describes redundancy, geographically remote backup, disaster-recovery measures, and 99.95% uptime. These controls matter because availability is part of transaction security. A system that protects files but becomes unavailable during a compressed due diligence process can still create significant operational risk.

Organizations with specific regulatory, contractual, or internal data-location requirements should confirm the applicable hosting location and plan configuration before the room goes live.

Security certifications and compliance

Independent certifications and assurance reporting help procurement, legal, compliance, and information-security teams assess the controls behind a VDR.

ISO/IEC 27001 ISO/IEC 27017 ISO/IEC 27018 ISO/IEC 27701 SOC 2 SOC 3 GDPR HIPAA

ISO/IEC 27001

ISO/IEC 27001 covers the establishment and operation of an information security management system.

ISO/IEC 27017

ISO/IEC 27017 provides additional guidance for information-security controls in cloud environments.

ISO/IEC 27018

ISO/IEC 27018 addresses protection of personally identifiable information processed by public cloud service providers.

ISO/IEC 27701

ISO/IEC 27701 extends information-security management into privacy information management.

Ideals also publishes SOC 2 and SOC 3 assurance information and states compliance with GDPR and third-party-verified HIPAA requirements.

Compliance check: Organizations with formal procurement requirements should confirm the current certificate, report scope, contracting entity, data location, and applicable service before relying on a certification for a specific project.

AI-enhanced virtual data room security

AI can reduce manual work during document preparation and review, but it also creates new questions around processing, permissions, and confidential information.

EthosData benefits from AI-enhanced virtual data room security through the Ideals platform. Ideals states that processing, including AI processing, takes place within its secured environment.

AI-assisted redaction

AI helps identify sensitive information that may need to be removed before documents are shared with external parties.

Controlled processing

AI functionality operates within the broader VDR security environment instead of requiring teams to export confidential files to separate tools.

Permission-aware workflows

AI features should operate within the same document-access model used by the rest of the data room.

Reduced disclosure

Redacting sensitive information before access is granted reduces the amount of confidential data exposed in the first place.

When evaluating virtual data room AI security features, buyers should consider more than the quality of the AI output. Important questions include where information is processed, which users can access AI tools, how permissions apply, and whether confidential documents leave the secured environment.

The security value of AI is not simply faster document review. It is using automation without weakening the access, infrastructure, and disclosure controls already protecting the data room.

Benefits of virtual data room security features

The practical virtual data room security features benefits extend beyond protecting files from unauthorized outsiders. In M&A and due diligence, many of the greatest risks involve legitimate participants receiving too much access or retaining information for too long.

Controlled disclosure

Release documents according to bidder group, role, or stage of the transaction.

Less unnecessary downloading

Allow participants to review information without automatically receiving unrestricted copies.

Greater accountability

Watermarks and audit trails make document access and redistribution more attributable.

Faster access changes

Adjust or revoke permissions when bidders, advisers, or other participants leave the process.

Bidder separation

Use groups and permissions to maintain separate disclosure levels inside one controlled environment.

Audit readiness

Maintain a clearer record of how information was shared throughout the transaction.

For a closer look at how these controls are applied in a transaction, see our due diligence data room guide and our page on the virtual data room for M&A.

High-security virtual data room pricing tiers

Teams comparing high-security virtual data room pricing tiers should look beyond storage allowances. The appropriate plan depends on the complexity of the transaction, administrator requirements, enterprise controls, security settings, and service level.

EthosData now follows the Ideals Core, Premier, and Enterprise plan structure.

Swipe left to see the full table.
PlanTypical fitSecurity and administration
CoreSingle, straightforward transactionStandard security including encryption, dynamic watermarks, Fence View, granular permissions, and AI-powered redaction.
PremierComplex or high-stakes transactionAdds advanced security settings, unlimited administrators, tailored storage, AI chat with documents, and dedicated Premier service.
EnterpriseOrganizations managing multiple projectsAdds multi-project management, centralized user administration, and enterprise capabilities such as SSO and API integration options.

Core already includes important document-protection controls. Premier becomes more relevant when a single deal requires advanced security settings and more administrative flexibility. Enterprise is designed for organizations that need security and user governance across several projects.

Read more: Compare current EthosData virtual data room pricing and plans.

EthosData security vs. basic file sharing

Generic cloud storage and a virtual data room may both provide encryption and account authentication. The distinction becomes clearer after an authorized external participant receives access.

Swipe left to see the full table.
RequirementBasic file sharingEthosData on the Ideals platform
PermissionsGeneral sharing rolesEight VDR document permission levels
Sensitive viewingBasic view-only controls may be availableFence View and controlled online viewing
WatermarkingVaries by platformDynamic user-linked watermarking
Downloaded filesOften difficult to control after downloadEncrypted and revocable access for supported protected files
Spreadsheet protectionStandard file accessFormula visibility controls for supported Excel files
Access expirationVariesScheduled access and automatic expiration
Bidder separationMay require separate folders or workspacesGroup-based permissions within the data room
AuditabilityGeneral activity historyDetailed transaction-focused audit trails and reporting

The security challenge in due diligence is often not keeping every external user outside the system. It is managing large numbers of legitimate document interactions without giving each participant more information than necessary.

See our guide to secure document sharing for a closer comparison of common sharing methods.

Security across the transaction lifecycle

Before the data room opens

Security is easiest to establish before external users are invited. Administrators can create user groups, define the folder structure, assign initial permissions, configure access settings, and identify documents requiring additional protection.

Starting from restrictive permissions reduces the risk of accidental overexposure when a room first goes live.

During due diligence

As buyers, advisers, lawyers, consultants, or specialists join the transaction, access can be adjusted according to their role. Activity reporting also gives administrators visibility into how the room is being used.

During staged disclosure

Highly sensitive information does not always need to be available from day one. Customer-level data, detailed pricing, intellectual property, employee information, or financial models can be released only when the process reaches an appropriate stage.

After signing or closing

Participant access can be removed once the process ends. Project archives and activity records can then support post-closing documentation, internal review, and compliance requirements.

How to evaluate virtual data room security

A long security feature list does not automatically make a VDR suitable for a sensitive transaction. Buyers should test how the controls work in realistic deal scenarios.

  • Can different bidder or adviser groups receive different document permissions?
  • How many document permission levels are available?
  • Can administrators restrict viewing without providing unrestricted downloads?
  • Can access start and expire automatically?
  • Can protected downloaded files be revoked where supported?
  • Are dynamic watermarks configurable?
  • Can highly sensitive documents use a restricted viewing mode?
  • Can spreadsheet formulas be hidden?
  • Can access be restricted by IP address or email domain?
  • Is two-step verification available?
  • Can administrators preview the room from another user's perspective?
  • Are user and document actions recorded in an audit trail?
  • Can the organization select an appropriate data-hosting region?
  • Which security certifications and assurance reports are currently available?
  • How is confidential information handled by AI functionality?
  • Which security and enterprise controls depend on the selected plan?
Important: No VDR can prevent every possible form of information capture by an authorized user. Strong security controls reduce exposure, limit common actions, create accountability, and make access easier to monitor and revoke.

Why EthosData security changed after joining Ideals

EthosData's current security proposition differs from its legacy offering because customers now use the Ideals VDR platform.

The acquisition brought EthosData customers access to Ideals' granular permission model, security controls, reporting, analytics, infrastructure, and newer AI-assisted capabilities while retaining the EthosData transaction-support model.

This is particularly relevant for M&A and due diligence. Transaction security depends not only on protecting stored files but also on managing legitimate disclosure to buyers, investors, lawyers, consultants, and other external participants.

The goal of EthosData security is not to make confidential information impossible to share. It is to make disclosure controlled, limited, traceable, and revocable wherever the technology allows.

Explore EthosData security resources

Use these guides to explore specific parts of secure document sharing, VDR administration, due diligence, and the Ideals platform behind EthosData.

Learn how encryption, authentication, permissions, secure viewing, and activity tracking protect externally shared files.

Compare common ways to share confidential documents and when stronger document controls become necessary.

See how access control, tracking, organization, and secure collaboration apply throughout the document lifecycle.

Review the platform behind EthosData, including security features, AI tools, document management, support, and pricing.

Learn how deal teams organize confidential documents, separate user groups, control access, and track activity during diligence.

See how secure disclosure, permissions, Q&A, and reporting support mergers and acquisitions.

Follow the VDR lifecycle from initial structure and permissions through active review, access management, and closure.

Compare Core, Premier, and Enterprise and see how project complexity, security requirements, and administration affect plan choice.

FAQ

Is EthosData secure?

EthosData uses the Ideals VDR platform. Its security controls include AES-256 encryption, TLS protection, two-step verification, eight permission levels, Fence View, dynamic watermarks, protected downloads, audit trails, access restrictions, and secure infrastructure.

Is EthosData part of Ideals?

Yes. EthosData was acquired by Ideals in 2024. EthosData customers now use the Ideals VDR platform together with EthosData's transaction support.

What are the most important virtual data room security features?

The most important controls include encryption, two-step verification, granular permissions, restricted document viewing, dynamic watermarking, protected downloads, audit trails, access expiration, and secure infrastructure.

What Ideals virtual data room security features are available through EthosData?

EthosData customers use the Ideals platform, including eight permission levels, Fence View, dynamic watermarks, encrypted downloads, secure spreadsheet controls, IP and domain restrictions, activity reporting, AI-assisted redaction, and enterprise controls on applicable plans.

Can EthosData prevent users from downloading confidential documents?

Administrators can assign permissions that allow users to review documents without receiving unrestricted original files. For supported formats, encrypted downloads can also require Ideals authentication and may be revoked when permissions change, a participant is deactivated, or a project closes.

What is Fence View?

Fence View is a restricted viewing mode that masks most of a document and reveals the area around the user's cursor. It is designed to reduce exposure when particularly sensitive files need to be reviewed online.

Does EthosData support two-step verification?

Yes. The Ideals platform used by EthosData supports two-step verification together with other access controls such as email verification, IP restrictions, domain restrictions, session settings, and password policies.

Does EthosData provide AI security features?

The Ideals platform includes AI-assisted functionality such as intelligent redaction. This can help identify sensitive information that should be removed before documents are disclosed to external participants.

Where can EthosData customer data be hosted?

The underlying Ideals platform provides supported data-hosting options across multiple geographic regions. Organizations with specific data-residency requirements should confirm the available location and contractual terms for their project.

What security certifications does the Ideals platform have?

Ideals publishes ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, and ISO/IEC 27701 certifications, along with SOC 2 and SOC 3 assurance information. It also states GDPR compliance and third-party-verified HIPAA compliance.

Are all EthosData security features available on every pricing tier?

Core includes standard VDR security such as encryption, dynamic watermarks, Fence View, and granular permissions. Premier adds advanced security settings, while Enterprise adds multi-project administration and enterprise capabilities such as SSO availability. See the EthosData pricing page for current plan details.

Set up your Secure Virtual Data Room with EthosData