Many studies comparing VDRs (virtual data rooms) to standard file-sharing apps have sent a clear message: file-sharing tools aren’t built for due diligence, but data rooms are. This is undeniably true.
However, do high-end security labels and ISO certifications actually guarantee privacy? More importantly: who holds the keys to your data?

Compliance frameworks prove that a vendor runs a well-managed data center, but they leave a crucial question unanswered: can the vendor read your files?
In fact, across most major VDRs, either the app developer or the hosting provider can still read everything you upload.
What “Enterprise-Grade Security” Actually Certifies
ISO 27001 certifies an information security management system. SOC 2 certifies internal controls around availability, processing integrity, and confidentiality of a service. Both are audits of process, not audits of access.
Neither certification guarantees that the vendor will be technically unable to access your files. Neither requires that support staff nor a compromised admin account.
They confirm the vendor follows good practices around infrastructure, backups, and incident response. They say nothing about whether the vendor holds a key to your deal.
This matters because the marketing language doesn’t distinguish between the two. “Bank-grade encryption” almost always means encryption in transit and at rest, managed by the vendor, with the vendor holding the keys.
That’s a real security measure. It’s also a measure that leaves the vendor — and anyone who compromises the vendor — with the ability to see everything inside your deal room.
AI Features Widen the Same Gap
Most VDR platforms now advertise AI-powered redaction or AI-driven deal analytics as premium features. Both require the platform to process the raw, unredacted content of every document before anything is hidden or summarized.
An AI redaction tool has to read a document to find what needs redacting. A deal analytics engine has to ingest full file contents to generate insights. Neither can function inside an architecture where the vendor cannot see the data.
So platforms marketing AI-powered features on top of “bank-grade security” are, by construction, choosing server-side visibility over confidentiality — while marketing the opposite impression.
For M&A due diligence, that gap is not academic. Financial models, cap tables, and legal disclosures sitting inside a platform that can technically read them create a new, uncontrolled point of exposure — one that exists independent of any breach.
Zero-Knowledge and End-to-End Encryption Are a Different Claim
Zero-knowledge architecture and end-to-end encryption (E2E) make a specific, verifiable claim: the vendor’s own servers never hold the keys required to decrypt your files. Only the parties in the deal can. If the vendor is compelled, breached, or simply curious, there is nothing readable to hand over.
This is a narrower guarantee than “enterprise-grade security” and a stronger one. It’s also rare. Among platforms marketing to M&A lawyers, PE firms, and financial advisors, the overwhelming majority list certifications and encryption-in-transit as their headline security claims. Very few state, in plain terms, that the vendor cannot read the files even if compelled to.
If a platform doesn’t say it explicitly, the safest assumption is that it doesn’t do it.
What to Actually Check Before a Deal?
Certifications are worth confirming. They’re just not the question that matters most. Before relying on a platform for sensitive due diligence, ask directly:
- Does the vendor hold the encryption keys, or do only the parties in the deal?
- Can the platform’s AI features function without the vendor seeing unencrypted content?
- If served with a subpoena or compromised by an attacker, what could the vendor actually hand over?
- Is “end-to-end encrypted” stated explicitly or implied through adjacent language like “bank-grade” or “enterprise-grade”?
A platform that can answer the first question with “only the deal parties hold the keys” is making a fundamentally different promise than one that answers with a list of audits.
Encrypted Deal Room by Qaxa
Designed from the ground up, Qaxa provides a private deal room powered by zero-knowledge, PGP end-to-end encryption.
Unlike platforms that add encryption as a secondary layer over server-side storage, Qaxa encrypts every file, note, task, and message directly on your device. Only you and your deal partners hold the keys.
Because current technology cannot feed data into AI without sacrificing confidentiality, Qaxa intentionally refrains from building AI analytics over your files. Instead, Qaxa unifies the entire deal lifecycle into one encrypted environment.
While conventional VDRs force teams to use unencrypted channels like email or messaging apps for daily collaboration, deal room by Qaxa covers all four core deal tools natively.
Onboarding requires no complex IT procurement—just an email address, with unlimited free invites for clients. The platform’s open-source release is already scheduled, so the encryption will be backed by undeniable auditable proof.
Conclusion
A certification tells you a vendor runs a tidy operation. But it doesn’t tell you who can read your files. Before the next deal room gets chosen by habit or by whichever platform has the longest list of badges, ask the one question that actually matters: who holds the keys to your data. If the answer isn’t “only the parties in the deal”, the deal isn’t as private as the marketing page suggests.
Check your next deal room against that standard before you upload a single document. Visit qaxa.com to see what a secure deal room built on zero-knowledge encryption actually looks like.
