How to set up a data room

A data room is an index, a set of documents, and the ability to take access away. Everything else is a question of how much scrutiny the deal will get.

A data room is a set of documents at private addresses with an index in front of them, and a way to take access away when the process ends.

Dedicated software adds proof of who saw what. Whether you need that depends on whether anyone will ever have to prove it.

A data room index on a screen listing document categories, each linking to its own address.
A data room index on a screen listing document categories, each linking to its own address.

This guide covers the index, what the paid tools add, and why emailing a pack is the one thing not to do.

The index is what you are judged on

The other side forms an opinion of how you run things within about a minute of arriving, and the index is all they have seen at that point.

A clear index with sensible categories, everything named the way a reader would name it, and nothing obviously missing reads as a business that has its affairs in order. A folder called Documents containing forty files with internal names reads as the opposite, whatever is in them.

Spend time on the index. It is the cheapest credibility available in the whole process.

What the paid tools add

Dedicated data room software provides per-user permissions, a full audit trail, watermarking, and the ability to demonstrate afterwards exactly who accessed what.

That matters when the transaction is regulated, when there are competing bidders who must not see each other's activity, or when a dispute later could turn on who saw which document.

It matters much less for a seed round or a small acquisition, where the practical requirements are: the documents are available, they are not public, and access ends when the process does.

Emailed pack Private addresses Data room software
Withdraw access Impossible Take pages down Per user
See what was read No Per document Per person per document
Provable afterwards No Partially Yes
Setup effort None Small Significant
Cost None Low High

Never email the pack

This is the specific mistake worth avoiding.

A diligence pack sent as attachments is permanent. It sits in inboxes at the other firm, gets forwarded internally to people you did not choose, and remains readable indefinitely after the deal falls over. There is no version of asking for it back that works.

Addresses you can withdraw. When the process ends, the pages come down, and whatever was forwarded is now a set of links that lead nowhere.

One address per document

Splitting the room into per-document addresses gives you something useful during the process.

You see which documents are being opened and, more tellingly, which are being reopened. A contract read four times in two days is the subject of an internal argument, and the questions are coming.

That is a few days of warning to prepare an answer, which is worth more than most things in a diligence process.

A list of documents with open counts, one clearly read more than the others.
A list of documents with open counts, one clearly read more than the others.

Access control, honestly

Unguessable addresses keep documents out of search and away from anyone not given the link. For most of what goes in a data room that is sufficient.

Add a password for the genuinely sensitive material: the cap table, employment contracts, anything with personal data in it.

What none of this stops is the other side saving a copy while access is open. Assume they have. The purpose of withdrawal is to end ongoing access, not to un-see anything.

Closely related: How document tracking works, and How to share a PDF as a link for the adjacent problem. How to share a video as a link is also close.

Put it at an address

Write the index first, give each document its own address, keep the addresses unguessable, watch what gets reread, and take it down when the process ends.

Then the pack stays yours after the deal moves on.

Questions people ask

Do I need dedicated data room software?

For a regulated transaction or anything where access has to be auditable, yes. For an early fundraise or a small deal, a private index page with documents behind it does the job that matters.

What does the expensive software actually add?

Per-user permissions, an audit trail of who saw what and when, watermarking, and the ability to prove all of it afterwards. If nobody will ever have to prove it, you are paying for the proof.

What goes in it?

An index first, then financials, contracts, cap table, key agreements and anything the other side has asked for twice. The index is the part people underestimate.

How do I withdraw access when the deal ends?

Take the pages down. That is the one thing an emailed pack cannot do, and it is the main reason not to email a diligence pack.

Can I tell what they looked at?

With per-document addresses, yes: which documents were opened and when. That is genuinely useful during a process, because the documents being read repeatedly are the ones the questions will come from.

Keep reading