Data room for investors: startup checklist and folder structure

Ilya SpiridonovIlya Spiridonov
20 min read

An investor data room is the set of supporting documents a founder shares when a fundraising conversation moves from the pitch into diligence.

Start with the current deck, raise summary, financials, cap table, traction, and company records the investor actually needs. Keep first outreach light. Restrict sensitive material, and add legal or customer documents when requested.

Prepare the material before the raise, but don't expose the complete room to every cold recipient. A tracked deck is usually enough for first contact. Open the room when an investor asks for evidence, supporting files, or a diligence request list.

This checklist is general operational guidance, not legal, tax, accounting, or investment advice. The exact documents depend on stage, jurisdiction, business model, investor, and transaction. Let the investor's request list and advice from your professional advisers control the final room.

Prepare early. Share progressively.

Build and reconcile the room before fundraising starts, but do not expose the complete set to every cold recipient. Start with the deck. Add sensitive financial, ownership, customer, and legal material when the conversation reaches diligence.

The 30-second investor data room checklist

  • Current pitch deck
  • Raise summary, use of funds, and milestones
  • Historical financials and a forecast with documented assumptions, where relevant
  • Current cap table with an as-of date
  • Traction and customer evidence
  • Product overview, roadmap, and relevant IP information
  • Team and organization information
  • Requested corporate, legal, security, and privacy material
  • Diligence request tracker and room update log

Daniela Ogliaro's Carta guide to investor data rooms lists the cap table, deck, financial statements, market material, IP evidence, contracts, governance documents, and investor-requested information as common categories. That is a useful cross-check, not a reason to upload every possible record on day one.

When to create a data room for investors

Prepare the source documents before fundraising starts. Share them in stages.

  1. Before outreach: reconcile the deck, cap table, actual financials, forecast, and use of funds.
  2. During first contact: send the deck through a separate tracked link for each investor.
  3. After material interest: open a focused room when the investor asks for supporting evidence.
  4. During diligence: add requested corporate, legal, employment, IP, customer, security, and privacy material after internal review.
  5. Before close: follow the investor's and counsel's due diligence request list.

At pre-seed or seed, when the raise still needs only one deck, share it as a tracked HummingDeck link and keep the supporting pack private until someone asks for it.

Investor Justine Moore's a16z guide to data rooms recommends preparing the room before the fundraise so the underlying numbers are ready. For a company that hasn't launched, its suggested set is lean: a deck, team information, roadmap, and pilot or beta evidence when available.

The a16z article reflects a consumer investor's perspective, so treat it as one investor view rather than a universal diligence standard.

The AirTree team's startup data room guide makes the stage shift clear. Seed-stage rooms can be more qualitative, while growth-stage rooms become more quantitative.

That preparation should happen before a term sheet. In an April 2026 Orrick interview on European tech deal terms, Jamie Moore advises founders to get the company's records in order early and build the room before the term sheet arrives.

For outreach, email, format, and follow-up, use the separate guide to sending a pitch deck to investors.

What to share at pre-seed, seed, and Series A

Use stage as a starting point, then follow the request in front of you.

MaterialPre-seedSeedSeries A
Pitch deckFirst-send documentCurrent full deckCurrent full deck
Raise and use-of-funds summaryShort summaryIncludeTie the raise to milestones and planned use of funds
FinancialsRunway and key assumptions when requestedHistorical results plus modelAvailable history, model, and a clear actual-versus-forecast boundary
Cap tableKeep the current cap table ready; share detailed access when diligence startsCurrent cap table during diligenceCurrent cap table and requested financing history
TractionPilot, waitlist, design-partner, or early proofKPI history and relevant cohortsDetailed KPI, retention, concentration, and unit-economics evidence
Customer evidenceAnonymized proofReferences or evidence with permissionDeeper evidence and redacted agreements when requested
Corporate, IP, and legalKeep core formation and IP-ownership records ready; share detail when requestedFormation and IP records when requestedCounsel-led diligence set
Security and privacyInclude when material to the businessRequest-ledOften relevant for B2B, regulated, or data-heavy companies

Pre-seed data room

Build a lean supporting pack, but lead with the deck. Have the current cap table, core formation records, IP-ownership evidence, and a current financial snapshot ready for diligence. Add the founding team's relevant background, product roadmap, pilot or beta evidence, cash runway, and use of funds after interest develops.

Wefunder's December 2025 data-room guide uses that kind of core set at pre-seed, while recommending that access and room depth scale with the stage and the investor's request.

Don't manufacture a full financial history that doesn't exist. Separate known costs from assumptions and state the date of every number.

Seed data room

Open a focused room when a conversation becomes serious. Include historical results, forecast assumptions, current cap table, traction history, product evidence, and selected company records.

Seed investors can ask for more than the default set. Add documents against a named request instead of guessing which legal file matters.

Series A data room

Expect a deeper request-led process. Depending on the company, this can include longer financial history, ownership and financing records, detailed metrics, customer concentration, governance, IP ownership, material agreements, employment records, and security or privacy material.

There is no fixed Series A document count. A clean software company, regulated fintech, marketplace, and hardware startup won't produce the same diligence set.

Later or complex rounds

Let counsel and the investor's request list drive the structure. Use a formal virtual data room when the process requires granular permissions, formal audit exports, structured Q&A, contracted compliance evidence, or a regulated or multi-party workflow.

Copyable investor data room folder structure

Copy this tree and remove anything that doesn't apply. A file marked REQUESTED should be added only when the investor, counsel, or transaction calls for it.

00_START_HERE/
  00_data_room_index_and_update_log.xlsx
  01_pitch_deck.pdf
  02_raise_summary_and_use_of_funds.pdf

01_FINANCIALS/
  01_historical_financials.xlsx
  02_forecast_and_assumptions.xlsx
  03_cash_runway_and_key_milestones.pdf

02_OWNERSHIP_AND_FINANCING/
  01_current_cap_table.xlsx
  02_prior_financing_summary.pdf
  03_financing_documents_REQUESTED/

03_TRACTION_AND_CUSTOMERS/
  01_kpi_history.xlsx
  02_cohort_retention_or_pipeline_analysis.xlsx
  03_customer_evidence_REDACTED.pdf

04_PRODUCT_AND_IP/
  01_product_overview_and_demo.pdf
  02_product_roadmap.pdf
  03_ip_ownership_summary_REQUESTED.pdf

05_TEAM/
  01_leadership_and_organization.pdf
  02_hiring_plan.pdf
  03_employment_and_contractor_records_REQUESTED/

06_CORPORATE_AND_LEGAL_REQUESTED/
  01_formation_and_governance/
  02_material_agreements/
  03_ip_and_employment_assignments/

07_SECURITY_AND_PRIVACY_WHEN_RELEVANT/
  01_security_overview.pdf
  02_privacy_and_data_terms.pdf

08_DILIGENCE_REQUESTS/
  01_request_tracker.xlsx
  02_responses_and_updates.md

Use this naming pattern inside each section:

NN_topic_as_of_YYYY-MM-DD.ext

The tree is a platform-neutral content plan. It isn't a HummingDeck folder-import feature. HummingDeck Rooms use tabs and sections rather than nested folders. Map each top-level directory to a tab and each subgroup to a section.

If the deck is no longer enough, put the current supporting files in a simple HummingDeck Room instead of sending a trail of attachments. Open the investor-room demo to see the recipient experience before you build one.

What belongs in each data room section

00 Start Here

Give the investor one reliable entry point.

  • Room index with file owner, current version, and last update date
  • Current pitch deck
  • Raise amount and instrument when decided
  • Use of funds tied to the next milestones
  • Update log for material changes

The index should say where to find a file, not repeat the file's contents. Keep obsolete versions out of the active room.

01 Financials

  • Historical profit and loss statements for the available period
  • Balance sheet and cash flow statement when available and relevant
  • Current cash, burn, and runway
  • Forecast with a separate assumptions tab
  • Budget and hiring plan tied to use of funds
  • Explanation of material one-time costs or accounting changes

Mark the boundary between actuals and forecast. Use an as-of date, consistent currency, and the same revenue definition used in the deck.

Justine Moore's a16z guide specifically calls out inconsistent numbers, unclear actual-versus-projection boundaries, and selected high-performing cohorts as investor red flags. The guide's example: a deck that claims $2 million ARR while the model shows $1.5 million. Stop and reconcile the source before opening the room.

02 Ownership and financing

  • Current cap table with an as-of date
  • Summary of prior rounds
  • SAFEs, convertible notes, warrants, or similar instruments when requested
  • Equity plan and option-pool summary when requested
  • Prior financing documents when requested
  • Pro forma ownership analysis when prepared with advisers

Have the cap table owner and company counsel review the set. Don't treat an old spreadsheet as the source of truth because it has a familiar filename.

03 Traction and customers

  • KPI history for complete, comparable periods
  • KPI definitions and source systems
  • Retention or cohort analysis that fits the business model
  • Revenue or customer concentration when relevant
  • Pipeline summary with stages and definitions when relevant
  • Anonymized case studies, references, or product-usage evidence
  • Redacted customer agreements when specifically requested and approved

Use metrics that describe the real business. A subscription startup, marketplace, usage-based product, and services company need different KPI sets.

Don't show only the best cohort. If a metric changed definition, state when and why. Get permission before naming a customer as a reference or sharing its agreement.

04 Product and IP

  • Product overview or short recorded demo
  • Current roadmap with status and owner
  • Architecture or technical overview when relevant
  • Registered and unregistered IP summary when requested
  • Founder, employee, and contractor IP assignments when requested
  • Open-source or third-party dependency review when material

Keep a product roadmap honest. Separate committed work, active work, and ideas under consideration.

Orrick's UK founder guidance lists company IP, IT information, customer and supplier agreements, and employment material among common legal diligence areas. Jurisdiction and transaction terms change the actual request.

05 Team

  • Leadership summary and organization view
  • Founder and key-team background relevant to the company
  • Current headcount and hiring plan
  • Employee and contractor templates when requested
  • Option and benefit summaries when requested
  • Material employment records after counsel review

Minimize personal data. A hiring plan can show roles, timing, and budget without exposing candidate or employee details.

  • Formation and governance documents requested for the round
  • Board and shareholder approvals requested for review
  • Material commercial agreements
  • Loan, lease, partnership, or supplier agreements when material
  • Litigation or dispute information after counsel review
  • Required licenses or regulatory correspondence when applicable

Wefunder's current guidance treats core corporate records, a current cap table, and basic IP-ownership evidence as material that should already be in order. It also recommends selective disclosure, redaction, permissions, and counsel review as diligence deepens. Use that as a preparation baseline, not a universal upload list.

Ask counsel before sharing privileged legal advice. Uploading material to a room can have consequences beyond organization and convenience.

07 Security and privacy

  • Current security overview
  • Data-flow or architecture summary when relevant
  • Privacy policy and applicable data terms
  • Material incident summary after legal and security review
  • Independent reports or certifications the company actually holds
  • Open remediation items when disclosure is required, as determined with the security owner and counsel

State only controls and certifications that can be verified. Don't turn a hosting choice or encryption setting into a blanket compliance claim.

08 Diligence requests

Track the work instead of answering the same question in several email threads.

Use these columns:

FieldExample
RequestFY2025 monthly P&L
Requested byInvestor name
OwnerFinance lead
Due date2026-07-24
StatusIn review
ResponseAdded to Financials
Document linkCurrent file URL
Last updated2026-07-23

A request tracker is operational, not legal evidence. Use the investor's formal channel when the process requires one.

What not to upload by default

More files don't make a better room. Hold these back unless they are requested, relevant, and reviewed:

  • unredacted customer, employee, shareholder, or candidate personal data;
  • full customer contracts without permission or a specific request;
  • tax returns, employment agreements, board minutes, or other legal records added “just in case”;
  • privileged legal advice;
  • passwords, credentials, source-code secrets, raw production exports, or unrestricted personal-data dumps;
  • obsolete forecasts or spreadsheets that conflict with the deck;
  • several files named final_v3_revised with no date or owner;
  • information the company isn't authorized to disclose.

Redaction isn't only visual. Check file metadata, comments, hidden spreadsheet tabs, formulas, speaker notes, and embedded attachments before upload. Adobe's current PDF redaction and sanitization guidance explains why content removal and hidden-information cleanup are separate steps. Microsoft also documents how Document Inspector can find hidden data in documents, spreadsheets, and presentations.

How to control access as diligence progresses

Use progressive disclosure. The access level should become tighter as the material becomes more sensitive.

Use one link per investor for the first-send deck. This keeps access simple and separates engagement by intended recipient.

When the room adds financial, ownership, or legal material, create a new Restricted link for allowed investor emails, eligible company domains, or both.

Use exact email addresses for a particularly sensitive room unless everyone with an eligible firm domain should qualify. A domain rule matches the exact host, so add subdomains separately. Generic email providers such as Gmail can't be used as Restricted domain rules.

Don't tell an investor that you “switched on” a restriction if the tool fixes the access mode when the link is created. Create and test the new link. The access mode can't be changed after creation, although entries on a Restricted link's allowlist can be edited.

3. Know what each identity method proves

  • Open: no email gate. A viewer is anonymous unless the link is personalized.
  • Ask Email: the viewer types an address. The address is self-reported.
  • Verify Email: the viewer proves access to the email inbox, but the link doesn't use a prebuilt allowlist.
  • Restricted: the viewer verifies an allowed exact email address or eligible company domain.

Inbox verification isn't legal identity verification. Keep the claim at the level the control supports.

4. Set download, expiration, and revocation rules

Allow downloads when offline review is necessary and the disclosure risk is acceptable. Expiration and revocation limit later access through the share link after enforcement. They can't erase a file that was downloaded, cached, captured, or otherwise retained while access was valid.

5. Separate audiences when they need different material

Use separate rooms when file sets must be reliably isolated. Separate links can keep access and analytics distinct, but they aren't formal per-file permission groups. Test every link against its intended document set before sharing it.

6. Test the recipient view

Open the exact link in a private browser window. Check the access step, allowed address, file order, downloads, mobile view, and expired-link behavior.

7. Treat analytics as context

Room and document views, recorded time, completion, return visits, and additional-viewer signals can help you prepare a relevant response. They don't prove investor intent or a pending decision.

An additional-viewer signal can reflect forwarding, another device, or another stakeholder. It doesn't prove a forwarding event, a distinct person, legal identity, or who shared the link.

For the product-level tracking model, see HummingDeck document analytics. Read how to track an investor pitch deck before building founder follow-up rules around engagement.

How to run the room during the raise

Assign one room owner

The owner controls the index, approves changes, checks links, and coordinates requests. Contributors can own files, but one person should own the active room.

Reconcile the source documents

Before granting access, compare the deck, cap table, financial model, KPI file, and raise summary. Definitions and dates should match.

Keep an update log

Record the file, prior version, new version, change, date, and owner. Notify active investors when a material file changes and explain what changed.

Mark actuals and forecasts clearly

Use separate columns, tabs, labels, or styling. State the period, currency, source, and assumptions.

Close requests in one tracker

Give each request an owner and response. Link to the current file instead of attaching another copy in email.

Review access after the round

Revoke stale links, remove former collaborators, archive the final index, and keep the company's source records in their proper systems.

Set up an investor data room in HummingDeck

HummingDeck investor data room software fits a focused startup raise that doesn't require formal per-file permissions.

  1. Create a Room for the raise.
  2. Map the folder tree's top-level groups to tabs and sections.
  3. Add the current documents, tracked URLs, and supported embeds.
  4. Create a personalized link for early review, then a separate Restricted link when sensitive diligence begins.
  5. Set expiration and download rules, revoke stale links, and review room and document engagement for each recipient link.

As of August 4, 2026, link expiration, download restrictions, per-page analytics, geographic insights, and 30 days of analytics history start on Starter. Ask Email, Verify Email, Restricted sharing, Discussions, stakeholder mapping, and 90 days of analytics history require Pro or Business. Free, Starter, and Pro cap room documents and active recipient links; Business is the unlimited tier. Check current HummingDeck pricing before opening a large room.

Every HummingDeck Room includes one mutual action plan. Use a flat checklist or phases, assign buyer-visible tasks by email, keep internal tasks private, and add dates, dependencies, and progress where useful.

On Pro and Business, link-scoped Discussions include a general room thread and contextual threads on buyer-visible plan tasks, documents, tracked URLs, supported embeds, and sections. Everyone using the same link joins the same conversation, so use a verified or Restricted recipient link for sensitive questions.

Room analytics can show total views, unique viewer records, average recorded time, documents opened, completion, activity trends, and per-document engagement. Pro and Business add stakeholder mapping for additional-viewer signals. HummingDeck isn't a document editor, cap-table system, e-signature platform, or formal VDR audit system.

For pitch-deck tracking and the broader fundraising workflow, see HummingDeck for fundraising. For a stage-based tool comparison, see the DocSend alternatives for fundraising.

When to use a formal VDR instead

Choose a formal virtual data room when the investor, counsel, transaction, or policy requires:

  • nested folder trees and document indexing;
  • per-file, per-folder, bidder, or role permissions;
  • NDA gating and acceptance records;
  • dynamic watermarking;
  • structured questions and file requests;
  • formal audit exports;
  • single sign-on;
  • contracted compliance or certification evidence;
  • multi-bidder, regulated, or complex M&A workflows.

HummingDeck doesn't provide the nested folders, granular permission groups, NDA records, dynamic watermarking, formal file-request or diligence-Q&A workflow, audit exports, SSO, or named-certification workflow listed above. Its Discussions feature is link-scoped collaboration, not a formal VDR request system. Review data room alternatives when the process requires those controls.

If the workspace is for a sales pursuit rather than investor diligence, use digital sales rooms instead.

Frequently asked questions

What should be included in an investor data room?

Start with the current deck, raise summary, financials, cap table, traction, product material, and team information. Add corporate, legal, IP, customer, employment, security, and privacy documents when the investor or counsel requests them. Keep a room index and request tracker beside the files.

When should a startup create its data room?

Prepare the underlying documents before the fundraise so the numbers can be reconciled. Send the deck first during broad outreach. Open the focused room when an investor asks for supporting evidence or begins diligence.

Does a pre-seed startup need a data room?

A lean supporting pack is often enough at pre-seed. Prepare the deck, current cap table, core company and IP-ownership records, current financial snapshot, team, roadmap, pilot or beta evidence, runway, and use of funds. Share the additional material after interest develops instead of exposing a full legal room to every cold recipient.

Do investors need access to every document?

Give each investor the material needed for the current stage and request. Sensitive customer, employee, ownership, legal, and security information should be disclosed deliberately. Separate links or rooms when audiences need different sets.

Should investors sign an NDA before receiving access?

NDA practice varies by investor, stage, material, and jurisdiction. A link access gate isn't a contract, and HummingDeck doesn't record NDA acceptance. Keep first outreach low-friction, reserve confidential material for later review, and ask counsel when an NDA is appropriate.

How should an investor data room be organized?

Use a short Start Here section followed by Financials, Ownership, Traction, Product, Team, requested Corporate and Legal material, Security and Privacy when relevant, and Diligence Requests. Number files, add as-of dates, and keep one update log.

How do you protect sensitive data room documents?

Minimize what you share, redact personal or confidential data, verify the recipient inbox when appropriate, control downloads, set expiration, and revoke stale links. These controls reduce exposure but can't recall a downloaded copy or prevent an authorized reader from sharing information another way.

When should a startup use a formal VDR?

Use a formal VDR when the process requires granular file permissions, NDA records, dynamic watermarking, structured Q&A, audit exports, SSO, contracted compliance evidence, or complex multi-party diligence. Choose the tool from the transaction requirements, not the startup's stage label alone.

Build the room before the request arrives

Start with the copyable tree, assign an owner, and reconcile the numbers before opening access. Then share only the material the investor needs at that point in the process.


Related: