Data Rooms Providers Find a data room
VDR glossary · Security

What is encryption in transit?

Definition

Encryption in transit: Protection of data while it travels between a user's device and the data room servers, so anyone intercepting the connection sees only scrambled traffic.

How it works in a data room

When you open a folder or upload a spreadsheet, your browser and the provider’s servers first agree on a secure session using Transport Layer Security. From then on every request, page image and file chunk is encrypted on the wire. Well-run platforms refuse outdated protocol versions, prefer modern cipher suites and use HTTP Strict Transport Security so a browser never falls back to an unprotected connection. Traffic between the provider’s own services, such as the viewer and the storage layer, should be encrypted too, not only the public-facing hop.

Why it matters in a deal

Bidders and advisers log in from hotels, airports, client offices and home networks you know nothing about. Without encryption in transit, a shared Wi-Fi network or a compromised router could expose the exact pages someone viewed. Buyers’ IT reviewers usually check the minimum protocol version and certificate setup during vendor onboarding, and a weak answer can delay a room’s launch. Pair it with encryption at rest for the full picture: one protects movement, the other protects storage.

Example

A Canadian mining company opens a room for an offtake partner whose geologists work from remote camps over satellite links. The partner’s security team runs a public TLS checker against the provider’s domain before agreeing to log in and confirms that only TLS 1.2 and 1.3 are accepted. The test takes ten minutes and becomes part of the onboarding file. The Canada guide covers the local privacy rules that shaped the rest of that review.

Related terms