The full list of what is built and works in our own test environment — not a roadmap. The production service has not opened: the Trust Center says what is proven, where, and what is not.
Named, ordered stages per room, each able to require its own NDA type before content unlocks.
Granular, folder- and document-group-level permission grants, with explicit allow/deny/no-opinion states — never a silent default.
Competing bidders structurally isolated from each other — one group cannot see who else is in another, or what they're doing.
Every download is watermarked to the viewer's identity by default, and so is every view beyond the first (teaser) stage, not an admin's opt-in choice. Clean Team documents are always watermarked on every page and offer no download, print or export. Where a plan includes native download, an administrator can grant the original file, which carries no watermark.
A reviewed workflow before anything is redacted — nothing ships without approval.
Turning off a room's multi-factor authentication or watermarking, narrowing the watermark's scope, or clearing its IP allowlist, requires a second, independent administrator's sign-off on every plan. Enterprise adds dual-control approval of high-risk access grants; on Starter and Pro those grants need a fresh second-factor check instead.
Buyer-scoped questions, with a one-click promotion to a shared FAQ visible to every bidder.
A formal, ticket-like workflow distinct from Q&A — its own priority and materiality tracking.
A versioned narrative memo with per-buyer-group read receipts, so a seller can see who's actually read it.
Category-based preferences (security, access changes, content, Q&A/DDR, billing, and more).
Results are pre-filtered by permission before they're ever returned — a search can't reveal a document you don't have access to.
Every security-relevant action written to an append-only, hash-chained ledger, sealed daily. Anchoring each seal outside our own database is built and switches on with the production service.
Proof that a specific party did or did not access specific documents in a specific window, which anyone can check without an account. A preview feature: not yet signed by an independent key service.
Real buyer engagement, structurally excluding any internal support/admin activity from the numbers a seller sees.
Blocks destruction and erasure of anything under hold, at room, document-group, or document scope.
A legal export needs the approval of two people besides the person who asks and produces a hashed manifest of the room's sealed snapshot, with a permanent, immutable log of every attempt — approved or denied. Bundling the documents themselves, as a PDF bundle or as native files with a load file for e-discovery tools, is not built yet.
A formal, auditable workflow for access, erasure, rectification, and restriction requests.
Every deal room isolated at the database layer, not only in the application: row-level security is forced on every table.
Not offered, by design — it's a known-weak factor we won't offer even as an option.
Real, revocable sessions — signing out of a session ends it immediately, not on next token expiry.
Programmatic access for teams that need it (Enterprise).
Single sign-on with your identity provider, delivered as a custom integration scoped with you on request (Enterprise). Not a self-serve feature.