Security

Secure data room controls for every confidential deal.

Verified identity, scoped access, revocable links, agreements, watermarking and an exportable audit record, inside the room recipients use.

Controls that compound

Security is the whole access path: identity, scope, expiry, agreement, watermark and record.

Each control answers a different question: who is opening, what they can reach, how long the link works and what record remains.

Identity

Verified recipient access.

Email gates tie activity and permissions to a recipient instead of a shared anonymous session.

See secure sharing →
Scope

Custom groups and section rules.

Give each recipient group only the sections assigned to it, with document-level exceptions where needed.

See permissions →
Time

Expiry, revoke and rotation.

End access on a schedule or immediately, without taking down the room for everyone else.

See link controls →
Agreement

NDA before gated material.

Keep the executed agreement tied to the recipient and the room access it unlocked.

See NDA flow →
Accountability

Dynamic recipient watermarks.

Render verified identity and viewing time onto sensitive page views.

See watermarking →
Record

Audit events you can export.

Keep access, verification, agreement, viewing and download events in one room history.

See the audit layer →
Access by group and section

Open the room while sensitive sections stay gated.

Custom access groups define what each audience can reach. A section can be open, gated by NDA, request-only or hidden for one group without changing the rest of the room.

Northstar Data Room · Access matrixOwner view
Northstar acquisition · Room accessSaved
Same room · different views

Buyer A permissions

Rules apply to every recipient
in this group

Data index7 documents
Open
Downloads on
No expiry
Financials12 documents
NDA required
Sep 30
Commercial9 documents
Request access
Sep 30
Legal & tax18 documents
Recipients8 people
Visible sections3 of 4
Access statusActive
Protected delivery

Private material is served as private material.

The public viewer keeps protected manifests and assets out of shared caches, uses short-lived asset delivery and marks private room and document routes for no indexing.

Private responses

No shared-cache storage.

Protected manifests and assets use private, no-store response policy.

Short-lived delivery

Asset URLs expire quickly.

Page, image and download redirects are issued with a short validity window rather than permanent public paths.

Search isolation

Private links stay out of indexes.

Viewer routes carry noindex rules, and private rooms are not placed in the public sitemap.

The audit layer

The control and the resulting event stay together.

Verification, access requests, NDA signatures, document views, downloads and revocation changes remain inspectable in the room. Export the audit record when legal or procurement needs the evidence outside RoundOS.

Questions

Security controls, answered.

01Are private rooms indexed by search engines?

No. Private room and document routes carry noindex rules and are excluded from the public sitemap.

02What happens when I revoke a link?

That credential stops opening the room. Other recipient links remain active unless you change them separately.

03Can a forwarded link bypass verification?

No. When email verification is required, a new viewer must verify their own identity before gated material opens.

04Does watermarking prevent screenshots?

No. It makes the captured page attributable to a verified recipient and time instead of claiming an impossible screenshot lock.

05Can I export the audit history?

Yes. The room audit record can be exported for review outside RoundOS.

Secure from room one

Start with the room. Apply the controls that fit the deal.

Identity, scope, expiry and accountability stay part of one recipient path.

No credit card. Live in minutes.