The overall score
Every provider gets six marks out of 10. We multiply each mark by its weight, add them up and multiply by ten, which gives a score out of 100. The weights above reflect what an average deal team needs most: a room that can run the process and protect the documents, followed by how easily people adopt it and how predictable the bill is.
Five of the six marks come from the shared provider facts file that every page on this site reads. The sixth, checklist breadth, is calculated directly: the number of features on our 12-item checklist that the provider lists natively, out of 12, times ten.
The 12-item checklist
Q&A module, audit trail, dynamic watermarks, redaction, e-signature, mobile app, public API, single sign-on, two-factor login, bulk upload, document rights control (view, print and download) and AI features. A feature counts only when the provider lists it natively; add-ons from third parties do not count.
How the top 10 lists work
Each list changes three things, and one editorial rule applies to all of them:
- Weights. The security list puts 45% on data protection; the ease-of-use list puts 55% on ease of adoption; the regional lists keep the overall weights.
- An entry rule. Some lists only admit rooms with a specific feature. The M&A list requires a Q&A module; the most secure list requires watermarks and an audit trail; the AI list requires native AI features, which is why it has fewer than ten entries.
- Bonus points. Small additions for facts that matter to that buyer, such as an ISO 27001 certificate, a published price, a head office in the region or a stated focus on real estate. Every bonus is printed on the list page.
- Editorial review. Editors may adjust the final order within a list. The list score shown reflects that order; every other room keeps its computed score.
Because all lists share the same marks, a change in one fact moves every list at once.
Sources
- Vendor documentation and product pages
- Published pricing pages and trial terms
- Security attestations listed by the vendor (SOC 2, ISO 27001, HIPAA, GDPR statements)
- The shared provider facts file, re-checked monthly
We do not use ratings or review counts from third-party review platforms, and we do not claim hands-on test results we do not have. When a fact is not verified, such as the hosting region of a provider’s rooms, our pages say “ask the vendor”.
What we do not score
We do not score sales experience, contract terms that vary per customer, or incident history, because none of these can be verified consistently across every provider we track. Our profiles suggest the questions to ask about them instead.
Ties and rounding
Scores are shown as whole numbers. When two providers round to the same score, the unrounded number decides the order, then the name. A gap of two or three points should be read as a tie in practice.
Partners and independence
Partner status does not enter the criterion marks or the bonus points: they are computed by the same code for every provider. The build stops if a published list and the ranking code disagree.
Changes to the method
We change the method rarely and log every change on this page with the date. Current version: October 2026, the first public version of the model.
Ellty
iDeals
Datasite