What protects confidential documents at each stage of a Virtual Data Room.
Author: AMS Updated: 30 September 2026 Reading time: 6 minutes
What protects confidential documents at each stage of a Virtual Data Room.
Author: AMS Updated: 30 September 2026 Reading time: 6 minutes
Executive Summary
A Virtual Data Room (VDR) can hold some of the most sensitive documents an organisation handles and typically these documents are being shared to multiple parties, internal or external to the organisation. A Data Room's security can be described as a list of features, such as encryption, authentication and audit logging. In practice, each of those controls matters at different stages of the Data Room's life.
A Virtual Data Room is set up, participants are added, it is used by several parties overseen by the VDR's owner or controller as the work changes, and then the data room is closed. Common security questions are important at different stages of the Data Room's lifecycle: Who defines the structure, who is granted access and to what, what is recorded, where the data is held, and what happens to it once the work ends.
This page sets out those questions stage by stage and how AMS Virtual Data Rooms answers them.

Key Takeaways
What is a Virtual Data Room (VDR)?
A Virtual Data Room is a structured, access-controlled online environment in which confidential documents are organised and shared with multiple parties for a defined piece of work. Common uses include due diligence during a transaction, disclosure in a legal matter and audits or regulatory reviews. Unlike a general shared drive, a Data Room follows a consistent index, grants each party access according to their role, and records activity for the duration of the work.
How security changes during the lifecycle
Unlike a shared folder where the workspace is set up once and rarely changes, a Data Room changes frequently throughout its life. Parties join and leave, documents are added in batches, and the structure is refined as the work develops, then can be fixed once it is agreed. At the end, a complete copy can be downloaded for long-term storage and reference, and the Data Room deleted.
Each of these changes is a point where security can be compromised if controls are not managed properly. Common problems with Data Rooms include permissions being granted to the wrong party, the Data Room's structure being edited after it was agreed and removing access to participants whose role in the work / project has ended. Therefore, for a buyer questioning the effectiveness of a Data Room's security, an important question is not only which security controls a Data Room includes, but at which stage each one applies.

Security at each stage of a Data Room
Before any external party joins, administrators establish the preliminary folder structure, the numbering system and the access rules. Decisions made here determine which parties will be able to see what, so setup should be restricted to administrators.
Internal and external parties are added according to their role in the work. Each should be granted access only to the content they need, with defined permission levels. These can be down to a file, sub-folder or Virtual Data Room Container level.
Documents are added, reviewed and referenced within the agreed structure. Every access and action should be automatically logged, so the handling of each document can be evidenced after the event. Data should remain encrypted both in transit and while being stored.
As the work develops, administrators or Virtual Data Room Owners / Controllers manage users and permissions. It is important they also remove access that is no longer required. Once the structure is agreed, locking it prevents documents or folders being moved.
When the work concludes, the Data Room can be downloaded to retain a complete copy for longer term storage or reference and then deleted from the portal by the Data Room owner.
How to assess the security of a Virtual Data Room
Data should be encrypted in transit and at rest, and the supplier should be able to state the standard used.
Confirm whether multi-factor authentication can be enforced.
Look for permissions granted according to each party's role, managed by an administrator.
Every document access and activity should be recorded within the Data Room.
Check whether the folder structure can be locked once it is agreed and if it can be unlocked if the structure needs to be altered again.
Confirm the hosting country and whether each customer's data is stored separately from other customers' data.
Confirm what happens to the Data Room files once the work ends and if administrators can download a full copy of the Data Room for long term storage and reference.
How AMS Virtual Data Rooms approaches security
Setup and structure
AMS Virtual Data Rooms are set up by administrators, who establish the folder structure and access rules upfront. A consistent index structure keeps documents organised and easy to reference, using a clear numbering system. The folder structure can be locked once agreed and unlocked again if it needs to be changed.
Access
Relevant internal and external parties are added based on their role in the project, and access is granted according to responsibility. Administrators manage users, permissions and access levels from a secure admin portal. Multi-factor authentication can be enforced for all user accounts.
Encryption
Encryption is applied to data during transfer and while stored, using 256-bit AES standards.
Audit trail
Full audit logging of document access and activity is recorded within each data room.
Hosting and isolation
Data is hosted within UK Microsoft Azure data centres. Customer data is held in separate storage accounts and databases for isolation and protection.
Closure
Once a project or transaction concludes, administrators can download a complete copy for long-term storage or reference, and delete the Data Room from the portal.

Compliance
AMS is ISO 27001 and Cyber Essentials certified, holds a published NHS DSPT status of Standards Met for 2025-26, and complies with UK GDPR and the Data Protection Act 2018. Independent testing and ongoing internal monitoring protect against evolving threats.
Certified Information Security Management System.
Demonstrating core security controls.
Compliant with the NHS Data Security and Protection Toolkit.
Talk to our sales and support team.