Data Rooms Providers Find a data room

How We Rate Data Room Providers

Every rating on this site comes from one model, applied the same way to every provider. This page sets out that model in full, so you can check our arithmetic, disagree with our weights and reach your own view.

The five pillars

We score each provider on five pillars. Each pillar carries a fixed weight that reflects how much it tends to matter when a data room is in active use on a transaction.

PillarWeightWhat we assess
Security25%Independent certifications such as SOC 2 and ISO 27001, encryption, access control, two-factor login, dynamic watermarking and the depth of the audit trail.
Deal features25%Structured Q&A, granular permissions, indexing, redaction, document rights control, reporting and other tools a live process relies on.
Ease of use20%How quickly an administrator can set up a room, and how easily outside parties such as bidders, investors and counsel find their way around.
Value20%Whether pricing is published, how predictable the bill is, and how much of the feature set the entry price includes.
Support10%Availability across time zones, response speed and the quality of help when something goes wrong mid-deal.

Security and deal features together account for half of the score, because a room that leaks or cannot run an orderly Q&A fails at its core job. Ease of use and value follow, since a room that bidders struggle with, or that costs more than the process can justify, slows a deal down. Support carries the smallest weight. It matters a great deal on the one bad day, but it rarely separates good providers from each other.

From pillar scores to a rating out of 5

Each pillar is scored on a scale of 0 to 10, to one decimal place. A score of 10 would mean nothing meaningful to add; a score below 6 signals a real gap for transaction work.

The overall rating is calculated in three steps:

  1. Multiply each pillar score by its weight.
  2. Add the five results to get a weighted score out of 10.
  3. Divide by 2 and round to one decimal place to get the rating out of 5.

A worked example: Firmex scores 9.0 for security, 8.3 for deal features, 9.0 for ease of use, 8.5 for value and 9.2 for support. The weighted score is (9.0 × 0.25) + (8.3 × 0.25) + (9.0 × 0.20) + (8.5 × 0.20) + (9.2 × 0.10) = 8.745. Halved and rounded, that gives a rating of 4.4.

We also attach a short verbal label to each rating so the number is easier to read at a glance:

RatingLabel
4.7 and aboveOutstanding
4.4 to 4.6Excellent
4.1 to 4.3Very good
3.8 to 4.0Good
Below 3.8Fair

Ordering and ties

The main ranking at /data-room-providers is sorted by rating, highest first. Where two or more providers share the same rating to one decimal place, they are listed in alphabetical order. We do not use hidden tie-breakers, and we do not adjust a pillar score to separate providers that land on the same number.

How industry and region shortlists are built

Industry pages at /industries and region pages at /regions show three to five providers rather than the full list. Each shortlist is built in the same way:

  1. Define the needs. We write down what the use case actually demands. A biotech licensing room needs tight document rights control and detailed viewing analytics; a restructuring room needs fast set-up and a clean audit trail for creditors.
  2. Filter on facts. We keep providers whose recorded features and certifications match those needs. A provider without a Q&A module will not appear on a shortlist where structured Q&A is essential.
  3. Order the result. The list opens with our highest-rated provider overall, then follows with the providers that fit the brief best. A short note beside each pick explains why it is there.

Region pages add local context, such as the privacy law that applies and the currency buyers usually budget in. They never add local prices; all prices on this site are shown in US dollars as published by the provider, or as “On request” where the vendor quotes privately.

Where the facts come from

Facts about each provider, including starting price, trial availability, certifications, deployment, headquarters, founding year and the twelve tracked features, come from public sources: the provider’s own pricing and security pages, product documentation, trust centers and release notes. Where a vendor claims a certification, we look for the standard it refers to, such as ISO/IEC 27001 for information security management or the AICPA SOC 2 framework for service organization controls. If a fact cannot be confirmed from a public or vendor-provided source, we leave it out rather than guess.

How often we re-check

  • Every quarter: prices, free trial terms and the twelve tracked features for every provider.
  • Every year: a full re-score of all five pillars, including a fresh look at the set-up flow and the outside-party experience.
  • As it happens: whenever a vendor announces a major release, a pricing change or a new certification, or a reader reports something that looks wrong.

Each page shows the date it was last updated. A change to a pillar score is logged internally with the reason for it.

What we never do

  • Sell a place in the ranking or a higher score.
  • Change a rating, a note or a shortlist position because a provider pays us a commission, or stops paying one.
  • Let a vendor write, edit or approve our copy.
  • Publish user review counts or star averages borrowed from review platforms. Our ratings are editorial, and we label them that way.
  • Invent prices, customers, awards, offices or hosting regions.

Our commercial arrangements are described in the disclosure, and our wider standards in the editorial guidelines.

Reporting an error

If a fact, price or score looks wrong, tell us through the contact page. Include the page, what you believe is incorrect and, if you can, a public source. We review every report, correct confirmed errors promptly and update the date on the page. Vendors are welcome to report changes too; we verify them independently before anything is updated.