Regulation
Amended Regulation S-P and what it means for your data room vendor
By the CogniSuite team
What amended Reg S-P requires
Four obligations for covered institutions, per FINRA's cybersecurity advisory on the rule: a written incident response program, notification of affected individuals, oversight of service providers, and records documenting compliance.
Both compliance dates have passed. FINRA's reminder advisory confirms 3 December 2025 for larger entities and 3 June 2026 for smaller ones. A Holland & Knight alert puts larger entities at investment companies above $1 billion in net assets, advisers above $1.5 billion in AUM, and most broker-dealers with capital above $500,000.
Notice to affected individuals goes out as soon as practicable and within 30 days. A Goodwin alert sets out the exception: none required if the firm determines the information is not reasonably likely to cause substantial harm or inconvenience. If affected individuals cannot be identified, everyone in the compromised system is notified.
Why a data room is a service provider
Because it holds sensitive customer information for the life of a deal. Holland & Knight quotes the definition as any customer information whose compromise could create a reasonably likely risk of substantial harm or inconvenience. In M&A that turns up in HR files, payroll data, cap tables and customer contracts.
You can outsource the operation, not the obligation. If the data room is breached, the duty to notify is yours.
The 72-hour clock
Get it in the contract in writing. Holland & Knight states that a service provider must notify the covered institution no later than 72 hours after becoming aware of unauthorized access to a customer information system. A Proskauer alert calls it written notice within 72 hours. The SEC accepted contractual representations, certifications and attestations, or other reasonable assurances.
Read the two clocks together: your 30 days runs from when you became aware, so a vendor using its full window has spent three of your thirty.
Ten questions to put to a VDR
Work from the Sidley compliance checklist: diligence before engagement, ongoing monitoring, written contract terms. File the answers.
1. The 72-hour commitment, naming who at your firm gets told and how.
2. Named sub-processors: hosting, email delivery, any AI inference provider.
3. Where deal data sits, and its encryption at rest and in transit.
4. Vendor personnel access: who reads your documents, under what process, logged how.
5. Authentication you can enforce on your users and on counterparties.
6. Self-service audit export, without asking the vendor to produce it.
7. What the audit record captures, whether it is tamper-evident, who may read it.
8. What deletion means. A soft delete is not erasure from backups, and the rule carries a disposal requirement.
9. A monitoring cadence you can show, not an onboarding questionnaire.
10. Your own retained file. Proskauer lists policies, incident reports and copies of notifications.
What CogniSuite gives you for the file
- An audit log you export yourself. Around 55 action types: views, downloads including via ZIP, deletes, permission changes, user and org lifecycle, request and Q&A transitions, AI questions. Filter by action, actor, org and date, then pull CSV.
- Permission-scoped AI. Every AI feature that reads deal documents runs through one retrieval function applying the document's own folder permissions, so an answer cannot quote a file the asker may not open. Counterparty-facing drafts are grounded only on what every counterparty on that list can read.
- A short sub-processor list. Text generation and the embedding calls that carry document text run through two shared paths to a single provider, so your external destinations are enumerable, not rebuilt feature by feature.
- Encryption at rest. Document bytes and entry blobs are compressed, then AES-256-GCM encrypted with HKDF-derived keys before touching disk.
- View-only folders that hold. A folder set to view is readable in the viewer but never exported: no download, no native stream, no bulk ZIP.
- Serve-time watermarking. Stored files stay clean originals; viewer name, org, UTC timestamp and CONFIDENTIAL are burned in as the file is served, and an explicit folder setting overrides the org default.

Where the controls stop
- The trail is not tamper-evident. Audit entries are ordinary database rows with no hash chain and no signature.
- Audit reading is advisory-side only. A counterparty cannot pull its own activity record.
- No second factor enforced by us. Your own firm's users can sign in through OpenID Connect single sign-on, configured per firm and restricted to the email domains you nominate, so your identity provider's MFA policy governs them. Deal-room participants sign in with a passwordless emailed code, with lockout after repeated failures and a cap on codes issued. If your policy requires MFA on every account touching customer information, record how counterparty accounts are covered and see /security.
- Watermarking covers PDF, Word, images, Excel and PowerPoint, and refuses to serve a format it cannot mark. Default org permissions are still clean download, so set the policy deliberately and confirm folder by folder.
- Deletion is a soft delete inside the deal's own database. If your disposal policy requires certified erasure on a schedule, get that in writing.
Certification status belongs on /security, not in an article. If a vendor will not put the 72-hour term, the sub-processor list and a dated diligence record in writing, that is your finding.
General information, not legal, tax or financial advice. For how CogniSuite handles security and access, see Security. To see it on a live deal, book a walkthrough.