Quick answer: Most established virtual data rooms handle secure storage, permissions and audit logging to a similar standard, so the choice is rarely decided there. What separates them in practice is how much of the transaction runs inside the platform rather than alongside it, and how much unplanned change the platform absorbs without administrative work. The criteria that reveal this are request handling, the depth at which access can be segmented, whether search reaches document contents, what a mid-process reorganisation costs, and how pricing behaves as the transaction extends.
What actually differs between data room platforms?
Nearly every provider will demonstrate encryption, two-factor authentication, granular permissions, watermarking and audit logs — the baseline functions of any data room. They are established expectations in the category rather than points of differentiation, and a shortlist built around them tends to produce platforms that look interchangeable on paper.
The differences that show up in a live process are narrower and harder to see in a feature list. They concern what the platform does once the transaction stops following the plan it was set up for.
Dillien was built workflow-native — document storage as one component of a transaction platform rather than the whole product — and the criteria below are the ones where that design choice has consequences either way. They are worth testing on any platform under consideration, including ours.
How granular does access control need to be?
Granular enough that any document can be segmented without restructuring the room.
Access is commonly controlled at folder level, which makes the depth at which it reaches the operative question. Where control stops at top-level folders, sensitive material has to be gathered into dedicated branches in advance. Where it reaches subfolders at any depth, and further down to individual documents, material can sit where a reviewer expects to find it and still be restricted on its own.
Two capabilities are worth confirming specifically: whether bidder groups can be kept separate across documents, questions and activity without running parallel rooms, and whether a clean room can be established inside the same room for a bidder with overlapping operations.
Who can change access, and how quickly?
Few processes run as they were scoped, and most of what changes without warning is access. A bidder replaces its legal adviser midway through review. A group's access needs narrowing to material they can already see. A document has to be withdrawn from one group and kept available to another. A party needs continued access after closing for integration purposes.
Such changes are made under time pressure, and the relevant question is who is able to make them. Where the deal team holds that ability, the change is a matter of minutes. Where it requires a request to the provider, the process waits on a response — and while it waits, the material remains visible to the group it was intended to be withheld from, or the incoming party remains outside the room.
Who in the process has never used a data room before?
Advisers on both sides are usually repeat users; they have worked in many rooms and will adapt to another one. The principals often are not — the owner, the founder, the finance director of a company that has not been through a transaction before.
That group also carries a large share of the work inside the room — uploading material, responding to requests, delegating internally — while continuing to run the business alongside the process. We describe that double load in why a virtual data room is critical in M&A processes. The person with the least experience with the tool may well be the person spending the most time in it.
So the question to ask is not only whether the platform is intuitive for a transaction professional, but whether the least experienced participant can work in it without someone sitting beside them. Where they cannot, the work falls either to the adviser or to the provider's onboarding — and whether onboarding is included in the price or billed separately varies. Hours the adviser spends explaining software are hours not spent on the transaction, against a timetable that does not move.
How should request handling be evaluated?
Request handling is where a data room either carries the process or sits beside it. Three questions establish which:
- Can an existing request list be imported rather than rebuilt? The buy side normally issues it as a spreadsheet, and it has to get into the room somehow.
- Can new requests be added inside the room as the process develops, or is the list fixed once loaded and extended elsewhere?
- Can each request be linked to the documents that answer it, so that delivery status is a property of the room rather than a separate record?
Does search need to reach inside documents?
In transactions with substantial contract volume, yes.
Search across file names finds documents that were named well. Search across contents finds a clause in a hundred-page agreement, which is the actual task in legal review. What matters is whether the platform then opens the document at the match rather than at page one.
Can the structure be reorganised once the process is under way?
Structure changes in most processes. Entities come into scope, a workstream splits between two firms, a category expected to hold four documents holds forty.
The question is what the change costs. Where references to documents are positional, moving material means that requests, questions and circulated reports point somewhere else, and time goes to reconciling references rather than reviewing documents. The common response is to leave the structure as it is and work around it for the remainder of the process.
How is a data room priced?
Pricing models vary more than pricing levels, and the model determines how cost behaves as the transaction develops rather than how much it is at signature.
The common structures are per room, per user, by data volume or page count, and annual subscription with a room allowance. The questions that matter are the same in each case: what triggers additional cost, what happens when the room stays open longer than planned, and what it costs to keep the room accessible after closing for integration and audit purposes. Volume-based and per-user models are the ones where the answer is least predictable at the outset — document-heavy transactions and late additions to the review team both change the figure.
Dillien is priced per room per month. Cost follows the number of transactions and how long each runs, both of which are known to the deal team, and adding reviewers or documents does not change it. Where a process needs a different arrangement, a fixed price for a defined project, a reduced rate for paying several months in advance, or an enterprise agreement covering unrestricted use can be put in place instead.
Where is data stored?
For European transactions, storage location is a substantive requirement rather than a preference, and it should be confirmed rather than inferred from where a provider is headquartered.
Where personal data is disclosed as part of diligence — employment records in particular — the data processing arrangements need to be in place before the material is uploaded rather than settled afterwards. ISO 27001 certification and demonstrable GDPR compliance are the baseline expectation.
What matters less than it appears?
Feature count. A long list reflects development history rather than fitness for a particular process. The relevant question is whether the functions used daily work well, not how many exist.
Integration count. What matters is whether the two or three systems a firm actually depends on connect properly, not how many appear on a page.
Questions worth asking in a demonstration
- Unplanned change — Narrow one group's access to material they can already see. Can our own team do that now, without you?
- New parties — Admit a bidder with its own adviser team and permission set. How long does it take, and what does that team need to be told before their first session?
- First-time users — Let someone from our side who has never used a data room upload a document against a request, unguided. What happens?
- Request handling — Can we import our existing request list, and can new requests be added inside the room once the process is running?
- Requests and documents — Can each request be linked to the documents that answer it?
- Q&A — Can a question be assigned to a named person and tracked to resolution, separated by bidder group?
- Access control — How far down can permissions be set: subfolder, or the individual document? And can a clean room be established inside this room?
- Search — Search for a term inside a long agreement. Does the document open at the match?
- Structure — Move a folder now. What happens to the requests and questions referencing it?
- Pricing — What triggers additional cost, and what does keeping this room open after closing cost?
- Data — Where is this stored, and can you evidence ISO 27001 and the data processing terms?
Conclusion
Every platform on a shortlist will clear the security baseline, and most will look capable in a demonstration the provider has built. The differences surface later: in the month the structure no longer fits the process, when a bidder has to be walled off from material already disclosed, when a request arrives that the list was never built to hold.
So the useful evaluation is narrow rather than broad. Take the process you are about to run, identify the three things that will consume the most time in it, and ask each provider during the demonstration how the platform handles precisely those three. To see how Dillien handles them, book a demo.




