Security & oversight
What DealRoom protects, how, and where its protection stops.
This page is written for the person doing diligence before a deal, not for a marketing brochure. It sets out the security model in plain terms, including the parts that are limits rather than features.
The security model, explained
Five layers, each doing one job.
DealRoom's confidentiality comes from combining transport and storage design, a granular permission model and alias-based identity — not from a single feature.
Transport
DealRoom is designed for encrypted network transport, so data moving between the app and our infrastructure is not sent in the clear.
Storage
Messages and documents are designed for encrypted storage. What sits on our servers is not held as plain, readable files.
Permission model
Every room is built from parties, and every party is built from participants with granular permissions. A document, a message thread or an action can be scoped to a side, to a named participant, or to administrators only — access is set deliberately, not inherited by default.
Identity and alias mapping
Inside a room, participants see a party label and a room-specific alias — Buyer 01, Seller Legal 01 — not another member's telephone number, email address or permanent account ID. The mapping between a real identity and a room alias exists on our systems so accountability is possible, but it is not exposed to other participants in the room.
Contact-detail blocking in messages
Messages are checked for contact details as they are typed. Where a telephone number or email address is detected, the participant is warned and the message cannot be sent, so it is never delivered to the room. The control applies to messages, and the room administrator can override it where a transaction legitimately requires details to be exchanged.
Joining without an email address
An administrator can invite by email or issue a unique join code for the room. Where a code is used, the participant enters the room without disclosing an email address at all — valuable for high-profile principals, diplomatic and government parties, and anyone whose contact details are sensitive in themselves. Entry is still on the administrator's terms: the same alias, agreement gates and permissions apply.
Who can see what
A participant sees the room they were invited into, the parties and aliases operating in it, and only the documents and actions their permissions allow. The administrator who created the room sees the full room: every party, every document configuration and the moderation and audit tools needed to run it responsibly.
Verified claims
What we state plainly, and only what we can stand behind.
We only publish a security claim once it has been technically confirmed. Nothing below is aspirational.
- Designed for encrypted network transport
- Designed for encrypted message and document storage
- Granular room permissions
- Private participant identity mapping
- Administrator oversight
- Controlled document access
- Audit-ready activity records
- Privacy-preserving notifications
- No public participant directory
- No in-app participant-to-participant direct messaging
Administrator oversight
Why one accountable person can see more than everyone else.
Every room needs someone who is responsible for it. That is the administrator — usually the broker, adviser or dealmaker who created the room — and DealRoom gives them the visibility their responsibility requires.
Oversight is not a bolt-on setting. It is built into how a room works: the administrator configures who joins, what they can see, whether an NDA is required before access, and what happens if a participant misuses the room. That responsibility only works if the administrator can review activity inside it.
In practice, that means the administrator can review communications and documents for moderation, audit and compliance purposes. It is the trade-off that makes group communication safe to open up in the first place — everyone can speak in the room because someone is accountable for what happens in it.
Administrator oversight is built into DealRoom by design. The room administrator — the party who created the transaction environment — can review communications and documents for moderation, audit and compliance, keeping every authorised party accountable inside the room rather than relying on unmonitored side conversations. DealRoom is controlled confidentiality with one accountable administrator, not participant-only end-to-end encryption.
Being honest about limits
Controlled confidentiality, not an unbreakable seal.
No platform, including this one, can stop two people who are determined to find and contact one another. Here is what that means in practice.
What DealRoom protects against
- Casual, accidental exposure of telephone numbers, email addresses or account IDs inside the room.
- Built-in, obvious routes for one participant to privately message another within the app.
- Documents leaking to parties who were never granted permission to see them.
- A transaction record scattered across email threads, group chats and personal devices instead of one auditable room.
- Access to confidential rooms before required agreements, such as an NDA, are signed.
What it does not protect against
- Two participants who already know each other, or who choose to identify and contact each other outside the app.
- Misuse of information by someone who was legitimately granted access to it.
- The absence of a properly drafted NDA or non-circumvention agreement — DealRoom supports that workflow but is not a substitute for the contract.
- Participant-only end-to-end encryption that would hide room content from the administrator. DealRoom is deliberately not built this way, because the administrator needs oversight to keep the room accountable.
Audit trail and record-keeping
Room activity is designed to produce audit-ready records: who joined, what was shared, what was approved and when. Document view and download activity is tracked, and moderation actions taken by an administrator are recorded rather than happening invisibly. That gives everyone with a legitimate interest in the transaction — the administrator, and where relevant their professional advisers — a single, ordered record of what happened, instead of reconstructing it after the fact from inboxes.
Retention and closing a room
A DealRoom is built for the life of a transaction, not indefinitely. The administrator can close and archive a room once it completes or falls away, bringing an end to active access for participants while preserving the record of what took place. Rooms carry a retention notice so participants know the environment is time-bound rather than an open-ended inbox.
DealRoom provides communication and transaction-workflow technology. It does not replace properly drafted legal agreements or professional legal advice, and no platform can guarantee that parties will never communicate outside it.
Open the conversation. Keep control of the introduction.
Bring every authorised party into one professional transaction environment without exposing private contact details or creating hidden in-app side channels.
Submitting this form does not create a DealRoom account. Accounts are created securely inside the mobile app.
