VIRTUAL DATA ROOM
Secure Document Sharing for Confidential Processes
Built for M&A Advisors, Private Equity Firms, Transaction Counsel, and Investment Bankers who need complete visibility and control over sensitive documents.
Most deal processes still run on email attachments and shared drives — no audit trail, no per-bidder isolation, no cryptographic proof of who saw what and when.
Independently security-tested with OWASP ZAP, Semgrep, and industry-standard scanners — see the full results
WHO THIS IS FOR
Every party in a deal has a different role. MandateRoom enforces that difference.
M&A Sell-Side Processes
- —Share Confidential Information Memoranda (CIMs) with full per-page audit trails
- —Instant access revocation when a bidder withdraws or is disqualified
- —Confidentiality Agreement (NDA) acceptance recorded with timestamp and IP address
- —Real-time engagement analytics — see which buyer groups opened which documents, how long they spent, and which pages they reviewed
Transaction Advisory
- —Per-document permissions across multiple participant groups
- —Immutable record of who viewed which document, which pages, and when — across all parties
- —Instant room archival when the process concludes
- —Entire folder structures can be hidden from specific buyer groups, enforced at both the application and database layers — Group A cannot see that a folder exists, let alone its contents
Legal & Valuation Review
- —Role-based access separating reviewers, advisors, and counterparties
- —Downloadable audit log as a formatted PDF ledger — sequentially numbered entries, cryptographic integrity verified per event, suitable for legal proceedings and regulatory review
- —Cryptographic proof of Confidentiality Agreement acceptance
THE PRODUCT
Built for how deals actually work.
Server-side rendering with identity watermarks
Every page rendered server-side. Viewer email, IP address, timestamp, and document index embedded on every page. Original files never reach the browser.
Forensic audit log with per-event integrity
Every access event cryptographically signed. Duration, pages viewed, and IP address recorded per session. Exportable as a numbered PDF ledger suitable for legal proceedings.
Role-based access with instant revocation
Admin, Reviewer, and Viewer roles enforced at every layer. Revoke access with one click — effective on the next request, no cache residual.
Hierarchical folder structure with per-group restrictions
Organize documents the way your process is structured. Restrict entire folder trees from specific participant groups — they cannot see the folder exists.
Per-viewer engagement analytics
See exactly who viewed which document, how many pages they read, and how long they spent. Know which buyers are engaged before you pick up the phone.
Isolated Q&A with internal notes
Each participant group submits questions in an isolated thread. Internal notes are never visible to external parties. Answers require admin review before publication.
SECURITY
Security is not a feature. It is the architecture.
Every design decision prioritizes the integrity of your confidential materials.
Zero-Trust Access Controls
Per-room role assignment. Per-document permission enforcement. Principle of least privilege applied at every layer.
Forensic Audit Trail
Append-only, HMAC-SHA256 signed. Every view, watermarked download, and login recorded with cryptographic integrity. Exportable as a numbered PDF ledger with per-event integrity badges — suitable for legal proceedings and regulatory review.
Exfiltration Prevention
Server-side page rendering. Dynamic user-identifying watermarks on every page. Original files never reach the browser.
Q&A with Participant Group Isolation
Competing parties submit questions in isolated threads. Group A cannot see Group B's questions. Internal notes are never visible to external participants. Enforced through two independent layers — application-level checks on every request, and a separate database-level policy.
Per-Room MFA Enforcement
Require TOTP two-factor authentication from every participant before accessing a specific room. Independent of account-level security. Per-room configuration.
IP Whitelisting & Access Controls
Restrict room access to specified IP addresses. Members connecting from any IP not on the allowlist are denied access on every request, regardless of valid session.
NDA with Version Tracking
Enforce mandatory non-disclosure agreements before entry. Full version tracking, with cryptographic proof of acceptance tied to user identity, IP address, and timestamp.
Permission Verification Mode
Admins can preview the room's interface exactly as a specific participant would navigate it, at any time — useful for walking through the experience before inviting someone, or troubleshooting what they're seeing. Every use is recorded in the audit log under the admin's real identity — the participant's own audit trail is never affected.
Office Document Conversion
Word, Excel, and PowerPoint files are converted to secure PDFs server-side before rendering. No editable formats reach the browser. All converted documents are rendered as watermarked images with identical protections to native PDFs.
cuid2 non-enumerable IDs · HMAC-SHA256 audit signatures · AES-256 storage encryption
Pricing is shared directly with interested professionals.
Write to us at hello@mandateroom.com to learn more.
No per-user fees. No overages. Currently running a limited early-access program →
I built MandateRoom because I kept seeing confidential deal documents move through email chains and WhatsApp groups — with no record of who saw what, and no way to prove confidentiality was maintained.
Aniket Raj, Founder — hello@mandateroom.com
Before you write to us
All documents are encrypted at rest using AES-256 and in transit using TLS. Documents are stored in private cloud storage with no public access URLs.
Only users explicitly invited to the room. Access is controlled by role-based permissions. You control exactly which documents each participant can view, download, or print.
You can archive the room at any time, which immediately revokes all participant access. Your data is retained and accessible to you for audit purposes.
Yes. You can restrict access to specific IP addresses per room. Members connecting from any unlisted IP are denied access on every request, regardless of a valid session.
Every audit event is cryptographically signed at the moment it's created using HMAC-SHA256, and the log is append-only at the database level. If a record is ever altered after the fact, that change is mathematically detectable.
PDF, Word (DOCX, DOC), Excel (XLSX, XLS), PowerPoint (PPTX, PPT), plain text (TXT), CSV, images (JPG, PNG, TIFF), and ZIP archives. ZIP files are automatically extracted and each file is individually secured and watermarked.
Current authentication includes TOTP two-factor authentication, configurable per account and enforced per room. SAML 2.0 SSO is on our roadmap.
For security reasons, we do not offer a mobile application. Mobile operating systems introduce unacceptable risks regarding local data caching, screen capturing, and insecure networks that compromise our strict exfiltration prevention guarantees.
Our infrastructure providers — Cloudflare, Vercel, and Supabase — each hold independent SOC 2 certifications. MandateRoom itself has not undergone a SOC 2 audit. Full security architecture documentation is available on request to hello@mandateroom.com.
Word (DOCX, DOC), Excel (XLSX, XLS), and PowerPoint (PPTX, PPT) files are converted to secure PDFs server-side before any participant can view them. No editable formats reach the browser. The converted document is rendered as watermarked images — the same protections that apply to native PDFs.
Yes. Admins can use Permission Verification Mode to preview the room's interface exactly as a specific participant would navigate it, at any time — useful for walking through the experience before inviting someone, or troubleshooting what they're seeing. Every use is recorded in the audit log under the admin's real identity — the participant's own audit trail is never affected.