A virtual data room is document hosting with an evidence layer bolted on. The hosting is the cheap part; the evidence is what the price reflects.

This guide covers what the evidence layer is for, when you need it, and the control everyone forgets.
What you are actually buying
Per-user permissions. Different people see different documents, controlled individually rather than by handing out links.
An audit trail. Every view, by name, with a timestamp, exportable.
Watermarking. The viewer's identity rendered onto each page they open.
Controlled printing and downloading. Restricted or logged.
Notice that every one of those is about knowing and proving rather than about delivering documents. Delivery is solved; proof is the product.
When the proof matters
Regulated transactions. Where a regulator may ask who had access to what and when, and an answer is required.
Competing bidders. Several parties in the same process who must not see each other's activity, and who may later dispute whether they had equal information.
Anything likely to be litigated. Where the question of who saw a particular disclosure could become material.
In those, the audit trail is the reason the room exists and the cost is proportionate.
| Private addresses | Data room | |
|---|---|---|
| Deliver documents | Yes | Yes |
| Withdraw access | Yes | Yes |
| Per-user permissions | By separate links | Properly |
| Named audit trail | No | Yes |
| Watermarking | No | Yes |
| Provable afterwards | No | Yes |
| Setup | Minutes | Days |
| Cost | Low | High |
When it does not
A seed round. A small acquisition. A commercial partnership where both sides trust each other enough to be talking.
In those the practical requirements are: the documents are available, they are not public, and access ends when the process does.
An index page with documents at unguessable addresses, a password on the sensitive ones, and the discipline to take it down afterwards covers all three. Setting that up takes an afternoon rather than a week of configuration and training.
The mistake is buying the evidence layer for a process where nobody will ever ask for evidence.
Watermarking, honestly
A watermark bearing the viewer's name does two things.
It deters, because a person forwarding a document with their own name across every page is identifiable.
And it traces, because if the document surfaces somewhere it should not, you know whose copy it was.
It does not prevent. Anyone who can read a screen can photograph it, and no control has ever changed that. Buying a room in the belief that documents cannot leave is buying the wrong thing.

The control everyone skips
Withdrawing access when the process ends.
Every option supports it, including the cheapest. Almost nobody does it, because there is no prompt and no deadline attached.
Six months after a failed transaction, the other side's team frequently still has live access to the entire disclosure. That is a larger real exposure than anything watermarking addresses, and closing it costs ten minutes.
Put a date on the process when you open it, and close access on that date.
Closely related: How to set up a data room, and Secure file sharing for business for the adjacent problem. Choosing hosting as a developer is also close.
Put it at an address
Ask whether anyone will need to prove access later, buy the room when they will, use private addresses when they will not, treat watermarking as tracing rather than prevention, and withdraw access when the process closes.
Then you pay for evidence only when evidence is the thing you need.