An investor data room is the set of supporting documents a founder shares when a fundraising conversation moves from the pitch into diligence.
Start with the current deck, raise summary, financials, cap table, traction, and company records the investor actually needs. Keep first outreach light. Restrict sensitive material, and add legal or customer documents when requested.
Prepare the material before the raise, but don't expose the complete room to every cold recipient. A tracked deck is usually enough for first contact. Open the room when an investor asks for evidence, supporting files, or a diligence request list.
This checklist is general operational guidance, not legal, tax, accounting, or investment advice. The exact documents depend on stage, jurisdiction, business model, investor, and transaction. Let the investor's request list and advice from your professional advisers control the final room.
Prepare early. Share progressively.
Build and reconcile the room before fundraising starts, but do not expose the complete set to every cold recipient. Start with the deck. Add sensitive financial, ownership, customer, and legal material when the conversation reaches diligence.
The 30-second investor data room checklist
- Current pitch deck
- Raise summary, use of funds, and milestones
- Historical financials and a forecast with documented assumptions, where relevant
- Current cap table with an as-of date
- Traction and customer evidence
- Product overview, roadmap, and relevant IP information
- Team and organization information
- Requested corporate, legal, security, and privacy material
- Diligence request tracker and room update log
Daniela Ogliaro's Carta guide to investor data rooms lists the cap table, deck, financial statements, market material, IP evidence, contracts, governance documents, and investor-requested information as common categories. That is a useful cross-check, not a reason to upload every possible record on day one.
When to create a data room for investors
Prepare the source documents before fundraising starts. Share them in stages.
- Before outreach: reconcile the deck, cap table, actual financials, forecast, and use of funds.
- During first contact: send the deck through a separate tracked link for each investor.
- After material interest: open a focused room when the investor asks for supporting evidence.
- During diligence: add requested corporate, legal, employment, IP, customer, security, and privacy material after internal review.
- Before close: follow the investor's and counsel's due diligence request list.
At pre-seed or seed, when the raise still needs only one deck, share it as a tracked HummingDeck link and keep the supporting pack private until someone asks for it.
Investor Justine Moore's a16z guide to data rooms recommends preparing the room before the fundraise so the underlying numbers are ready. For a company that hasn't launched, its suggested set is lean: a deck, team information, roadmap, and pilot or beta evidence when available.
The a16z article reflects a consumer investor's perspective, so treat it as one investor view rather than a universal diligence standard.
The AirTree team's startup data room guide makes the stage shift clear. Seed-stage rooms can be more qualitative, while growth-stage rooms become more quantitative.
That preparation should happen before a term sheet. In an April 2026 Orrick interview on European tech deal terms, Jamie Moore advises founders to get the company's records in order early and build the room before the term sheet arrives.
For outreach, email, format, and follow-up, use the separate guide to sending a pitch deck to investors.
What to share at pre-seed, seed, and Series A
Use stage as a starting point, then follow the request in front of you.
| Material | Pre-seed | Seed | Series A |
|---|---|---|---|
| Pitch deck | First-send document | Current full deck | Current full deck |
| Raise and use-of-funds summary | Short summary | Include | Tie the raise to milestones and planned use of funds |
| Financials | Runway and key assumptions when requested | Historical results plus model | Available history, model, and a clear actual-versus-forecast boundary |
| Cap table | Keep the current cap table ready; share detailed access when diligence starts | Current cap table during diligence | Current cap table and requested financing history |
| Traction | Pilot, waitlist, design-partner, or early proof | KPI history and relevant cohorts | Detailed KPI, retention, concentration, and unit-economics evidence |
| Customer evidence | Anonymized proof | References or evidence with permission | Deeper evidence and redacted agreements when requested |
| Corporate, IP, and legal | Keep core formation and IP-ownership records ready; share detail when requested | Formation and IP records when requested | Counsel-led diligence set |
| Security and privacy | Include when material to the business | Request-led | Often relevant for B2B, regulated, or data-heavy companies |
Pre-seed data room
Build a lean supporting pack, but lead with the deck. Have the current cap table, core formation records, IP-ownership evidence, and a current financial snapshot ready for diligence. Add the founding team's relevant background, product roadmap, pilot or beta evidence, cash runway, and use of funds after interest develops.
Wefunder's December 2025 data-room guide uses that kind of core set at pre-seed, while recommending that access and room depth scale with the stage and the investor's request.
Don't manufacture a full financial history that doesn't exist. Separate known costs from assumptions and state the date of every number.
Seed data room
Open a focused room when a conversation becomes serious. Include historical results, forecast assumptions, current cap table, traction history, product evidence, and selected company records.
Seed investors can ask for more than the default set. Add documents against a named request instead of guessing which legal file matters.
Series A data room
Expect a deeper request-led process. Depending on the company, this can include longer financial history, ownership and financing records, detailed metrics, customer concentration, governance, IP ownership, material agreements, employment records, and security or privacy material.
There is no fixed Series A document count. A clean software company, regulated fintech, marketplace, and hardware startup won't produce the same diligence set.
Later or complex rounds
Let counsel and the investor's request list drive the structure. Use a formal virtual data room when the process requires granular permissions, formal audit exports, structured Q&A, contracted compliance evidence, or a regulated or multi-party workflow.
Copyable investor data room folder structure
Copy this tree and remove anything that doesn't apply. A file marked REQUESTED should be added only when the investor, counsel, or transaction calls for it.
00_START_HERE/
00_data_room_index_and_update_log.xlsx
01_pitch_deck.pdf
02_raise_summary_and_use_of_funds.pdf
01_FINANCIALS/
01_historical_financials.xlsx
02_forecast_and_assumptions.xlsx
03_cash_runway_and_key_milestones.pdf
02_OWNERSHIP_AND_FINANCING/
01_current_cap_table.xlsx
02_prior_financing_summary.pdf
03_financing_documents_REQUESTED/
03_TRACTION_AND_CUSTOMERS/
01_kpi_history.xlsx
02_cohort_retention_or_pipeline_analysis.xlsx
03_customer_evidence_REDACTED.pdf
04_PRODUCT_AND_IP/
01_product_overview_and_demo.pdf
02_product_roadmap.pdf
03_ip_ownership_summary_REQUESTED.pdf
05_TEAM/
01_leadership_and_organization.pdf
02_hiring_plan.pdf
03_employment_and_contractor_records_REQUESTED/
06_CORPORATE_AND_LEGAL_REQUESTED/
01_formation_and_governance/
02_material_agreements/
03_ip_and_employment_assignments/
07_SECURITY_AND_PRIVACY_WHEN_RELEVANT/
01_security_overview.pdf
02_privacy_and_data_terms.pdf
08_DILIGENCE_REQUESTS/
01_request_tracker.xlsx
02_responses_and_updates.md
Use this naming pattern inside each section:
NN_topic_as_of_YYYY-MM-DD.ext
The tree is a platform-neutral content plan. It isn't a HummingDeck folder-import feature. HummingDeck Rooms use tabs and sections rather than nested folders. Map each top-level directory to a tab and each subgroup to a section.
If the deck is no longer enough, put the current supporting files in a simple HummingDeck Room instead of sending a trail of attachments. Open the investor-room demo to see the recipient experience before you build one.
What belongs in each data room section
00 Start Here
Give the investor one reliable entry point.
- Room index with file owner, current version, and last update date
- Current pitch deck
- Raise amount and instrument when decided
- Use of funds tied to the next milestones
- Update log for material changes
The index should say where to find a file, not repeat the file's contents. Keep obsolete versions out of the active room.
01 Financials
- Historical profit and loss statements for the available period
- Balance sheet and cash flow statement when available and relevant
- Current cash, burn, and runway
- Forecast with a separate assumptions tab
- Budget and hiring plan tied to use of funds
- Explanation of material one-time costs or accounting changes
Mark the boundary between actuals and forecast. Use an as-of date, consistent currency, and the same revenue definition used in the deck.
Justine Moore's a16z guide specifically calls out inconsistent numbers, unclear actual-versus-projection boundaries, and selected high-performing cohorts as investor red flags. The guide's example: a deck that claims $2 million ARR while the model shows $1.5 million. Stop and reconcile the source before opening the room.
02 Ownership and financing
- Current cap table with an as-of date
- Summary of prior rounds
- SAFEs, convertible notes, warrants, or similar instruments when requested
- Equity plan and option-pool summary when requested
- Prior financing documents when requested
- Pro forma ownership analysis when prepared with advisers
Have the cap table owner and company counsel review the set. Don't treat an old spreadsheet as the source of truth because it has a familiar filename.
03 Traction and customers
- KPI history for complete, comparable periods
- KPI definitions and source systems
- Retention or cohort analysis that fits the business model
- Revenue or customer concentration when relevant
- Pipeline summary with stages and definitions when relevant
- Anonymized case studies, references, or product-usage evidence
- Redacted customer agreements when specifically requested and approved
Use metrics that describe the real business. A subscription startup, marketplace, usage-based product, and services company need different KPI sets.
Don't show only the best cohort. If a metric changed definition, state when and why. Get permission before naming a customer as a reference or sharing its agreement.
04 Product and IP
- Product overview or short recorded demo
- Current roadmap with status and owner
- Architecture or technical overview when relevant
- Registered and unregistered IP summary when requested
- Founder, employee, and contractor IP assignments when requested
- Open-source or third-party dependency review when material
Keep a product roadmap honest. Separate committed work, active work, and ideas under consideration.
Orrick's UK founder guidance lists company IP, IT information, customer and supplier agreements, and employment material among common legal diligence areas. Jurisdiction and transaction terms change the actual request.
05 Team
- Leadership summary and organization view
- Founder and key-team background relevant to the company
- Current headcount and hiring plan
- Employee and contractor templates when requested
- Option and benefit summaries when requested
- Material employment records after counsel review
Minimize personal data. A hiring plan can show roles, timing, and budget without exposing candidate or employee details.
06 Corporate and legal
- Formation and governance documents requested for the round
- Board and shareholder approvals requested for review
- Material commercial agreements
- Loan, lease, partnership, or supplier agreements when material
- Litigation or dispute information after counsel review
- Required licenses or regulatory correspondence when applicable
Wefunder's current guidance treats core corporate records, a current cap table, and basic IP-ownership evidence as material that should already be in order. It also recommends selective disclosure, redaction, permissions, and counsel review as diligence deepens. Use that as a preparation baseline, not a universal upload list.
Ask counsel before sharing privileged legal advice. Uploading material to a room can have consequences beyond organization and convenience.
07 Security and privacy
- Current security overview
- Data-flow or architecture summary when relevant
- Privacy policy and applicable data terms
- Material incident summary after legal and security review
- Independent reports or certifications the company actually holds
- Open remediation items when disclosure is required, as determined with the security owner and counsel
State only controls and certifications that can be verified. Don't turn a hosting choice or encryption setting into a blanket compliance claim.
08 Diligence requests
Track the work instead of answering the same question in several email threads.
Use these columns:
| Field | Example |
|---|---|
| Request | FY2025 monthly P&L |
| Requested by | Investor name |
| Owner | Finance lead |
| Due date | 2026-07-24 |
| Status | In review |
| Response | Added to Financials |
| Document link | Current file URL |
| Last updated | 2026-07-23 |
A request tracker is operational, not legal evidence. Use the investor's formal channel when the process requires one.
What not to upload by default
More files don't make a better room. Hold these back unless they are requested, relevant, and reviewed:
- unredacted customer, employee, shareholder, or candidate personal data;
- full customer contracts without permission or a specific request;
- tax returns, employment agreements, board minutes, or other legal records added “just in case”;
- privileged legal advice;
- passwords, credentials, source-code secrets, raw production exports, or unrestricted personal-data dumps;
- obsolete forecasts or spreadsheets that conflict with the deck;
- several files named
final_v3_revisedwith no date or owner; - information the company isn't authorized to disclose.
Redaction isn't only visual. Check file metadata, comments, hidden spreadsheet tabs, formulas, speaker notes, and embedded attachments before upload. Adobe's current PDF redaction and sanitization guidance explains why content removal and hidden-information cleanup are separate steps. Microsoft also documents how Document Inspector can find hidden data in documents, spreadsheets, and presentations.
How to control access as diligence progresses
Use progressive disclosure. The access level should become tighter as the material becomes more sensitive.
1. Start with a personalized open link
Use one link per investor for the first-send deck. This keeps access simple and separates engagement by intended recipient.
2. Create a separate restricted link for sensitive diligence
When the room adds financial, ownership, or legal material, create a new Restricted link for allowed investor emails, eligible company domains, or both.
Use exact email addresses for a particularly sensitive room unless everyone with an eligible firm domain should qualify. A domain rule matches the exact host, so add subdomains separately. Generic email providers such as Gmail can't be used as Restricted domain rules.
Don't tell an investor that you “switched on” a restriction if the tool fixes the access mode when the link is created. Create and test the new link. The access mode can't be changed after creation, although entries on a Restricted link's allowlist can be edited.
3. Know what each identity method proves
- Open: no email gate. A viewer is anonymous unless the link is personalized.
- Ask Email: the viewer types an address. The address is self-reported.
- Verify Email: the viewer proves access to the email inbox, but the link doesn't use a prebuilt allowlist.
- Restricted: the viewer verifies an allowed exact email address or eligible company domain.
Inbox verification isn't legal identity verification. Keep the claim at the level the control supports.
4. Set download, expiration, and revocation rules
Allow downloads when offline review is necessary and the disclosure risk is acceptable. Expiration and revocation limit later access through the share link after enforcement. They can't erase a file that was downloaded, cached, captured, or otherwise retained while access was valid.
5. Separate audiences when they need different material
Use separate rooms when file sets must be reliably isolated. Separate links can keep access and analytics distinct, but they aren't formal per-file permission groups. Test every link against its intended document set before sharing it.
6. Test the recipient view
Open the exact link in a private browser window. Check the access step, allowed address, file order, downloads, mobile view, and expired-link behavior.
7. Treat analytics as context
Room and document views, recorded time, completion, return visits, and additional-viewer signals can help you prepare a relevant response. They don't prove investor intent or a pending decision.
An additional-viewer signal can reflect forwarding, another device, or another stakeholder. It doesn't prove a forwarding event, a distinct person, legal identity, or who shared the link.
For the product-level tracking model, see HummingDeck document analytics. Read how to track an investor pitch deck before building founder follow-up rules around engagement.
How to run the room during the raise
Assign one room owner
The owner controls the index, approves changes, checks links, and coordinates requests. Contributors can own files, but one person should own the active room.
Reconcile the source documents
Before granting access, compare the deck, cap table, financial model, KPI file, and raise summary. Definitions and dates should match.
Keep an update log
Record the file, prior version, new version, change, date, and owner. Notify active investors when a material file changes and explain what changed.
Mark actuals and forecasts clearly
Use separate columns, tabs, labels, or styling. State the period, currency, source, and assumptions.
Close requests in one tracker
Give each request an owner and response. Link to the current file instead of attaching another copy in email.
Review access after the round
Revoke stale links, remove former collaborators, archive the final index, and keep the company's source records in their proper systems.
Set up an investor data room in HummingDeck
HummingDeck investor data room software fits a focused startup raise that doesn't require formal per-file permissions.
- Create a Room for the raise.
- Map the folder tree's top-level groups to tabs and sections.
- Add the current documents, tracked URLs, and supported embeds.
- Create a personalized link for early review, then a separate Restricted link when sensitive diligence begins.
- Set expiration and download rules, revoke stale links, and review room and document engagement for each recipient link.
As of August 4, 2026, link expiration, download restrictions, per-page analytics, geographic insights, and 30 days of analytics history start on Starter. Ask Email, Verify Email, Restricted sharing, Discussions, stakeholder mapping, and 90 days of analytics history require Pro or Business. Free, Starter, and Pro cap room documents and active recipient links; Business is the unlimited tier. Check current HummingDeck pricing before opening a large room.
Every HummingDeck Room includes one mutual action plan. Use a flat checklist or phases, assign buyer-visible tasks by email, keep internal tasks private, and add dates, dependencies, and progress where useful.
On Pro and Business, link-scoped Discussions include a general room thread and contextual threads on buyer-visible plan tasks, documents, tracked URLs, supported embeds, and sections. Everyone using the same link joins the same conversation, so use a verified or Restricted recipient link for sensitive questions.
Room analytics can show total views, unique viewer records, average recorded time, documents opened, completion, activity trends, and per-document engagement. Pro and Business add stakeholder mapping for additional-viewer signals. HummingDeck isn't a document editor, cap-table system, e-signature platform, or formal VDR audit system.
For pitch-deck tracking and the broader fundraising workflow, see HummingDeck for fundraising. For a stage-based tool comparison, see the DocSend alternatives for fundraising.
When to use a formal VDR instead
Choose a formal virtual data room when the investor, counsel, transaction, or policy requires:
- nested folder trees and document indexing;
- per-file, per-folder, bidder, or role permissions;
- NDA gating and acceptance records;
- dynamic watermarking;
- structured questions and file requests;
- formal audit exports;
- single sign-on;
- contracted compliance or certification evidence;
- multi-bidder, regulated, or complex M&A workflows.
HummingDeck doesn't provide the nested folders, granular permission groups, NDA records, dynamic watermarking, formal file-request or diligence-Q&A workflow, audit exports, SSO, or named-certification workflow listed above. Its Discussions feature is link-scoped collaboration, not a formal VDR request system. Review data room alternatives when the process requires those controls.
If the workspace is for a sales pursuit rather than investor diligence, use digital sales rooms instead.
Frequently asked questions
What should be included in an investor data room?
Start with the current deck, raise summary, financials, cap table, traction, product material, and team information. Add corporate, legal, IP, customer, employment, security, and privacy documents when the investor or counsel requests them. Keep a room index and request tracker beside the files.
When should a startup create its data room?
Prepare the underlying documents before the fundraise so the numbers can be reconciled. Send the deck first during broad outreach. Open the focused room when an investor asks for supporting evidence or begins diligence.
Does a pre-seed startup need a data room?
A lean supporting pack is often enough at pre-seed. Prepare the deck, current cap table, core company and IP-ownership records, current financial snapshot, team, roadmap, pilot or beta evidence, runway, and use of funds. Share the additional material after interest develops instead of exposing a full legal room to every cold recipient.
Do investors need access to every document?
Give each investor the material needed for the current stage and request. Sensitive customer, employee, ownership, legal, and security information should be disclosed deliberately. Separate links or rooms when audiences need different sets.
Should investors sign an NDA before receiving access?
NDA practice varies by investor, stage, material, and jurisdiction. A link access gate isn't a contract, and HummingDeck doesn't record NDA acceptance. Keep first outreach low-friction, reserve confidential material for later review, and ask counsel when an NDA is appropriate.
How should an investor data room be organized?
Use a short Start Here section followed by Financials, Ownership, Traction, Product, Team, requested Corporate and Legal material, Security and Privacy when relevant, and Diligence Requests. Number files, add as-of dates, and keep one update log.
How do you protect sensitive data room documents?
Minimize what you share, redact personal or confidential data, verify the recipient inbox when appropriate, control downloads, set expiration, and revoke stale links. These controls reduce exposure but can't recall a downloaded copy or prevent an authorized reader from sharing information another way.
When should a startup use a formal VDR?
Use a formal VDR when the process requires granular file permissions, NDA records, dynamic watermarking, structured Q&A, audit exports, SSO, contracted compliance evidence, or complex multi-party diligence. Choose the tool from the transaction requirements, not the startup's stage label alone.
Build the room before the request arrives
Start with the copyable tree, assign an owner, and reconcile the numbers before opening access. Then share only the material the investor needs at that point in the process.
Related:
- How to send a pitch deck to investors: Start with the outreach message and move into diligence only after interest develops.
- DocSend alternatives for fundraising: Compare tracked-deck and lightweight-room tools by fundraising stage.
- How to track an investor pitch deck: Interpret opens, slide activity, return visits, and additional-viewer signals without overstating them.
- Data room alternatives for startups and SMBs: Compare lightweight rooms with fuller virtual data rooms.
- Pitch deck benchmarks for 2026: Review source-audited investor reading benchmarks separately from this checklist.
