Prepare eight folders before you prepare anything else: corporate, cap table, financials, metrics, product and technology, contracts and customers, team and HR, and legal and compliance. If you are pre-pitch, get corporate records and a reconciled cap table airtight first. If you are post-term sheet, expect deeper requests and gate sensitive files behind an NDA with watermarking and link analytics.
TL;DR:
- Ensuring the cap table reconciles with the actual share count and has current 409A valuation is critical to avoid delays during diligence.
- Financial statements should be fully reconciled with bank records and include clear assumptions for projections covering 18 to 36 months.
- The startup data room should prioritize corporate, cap table, financials, and legal documents, with access controls and watermarking to protect sensitive info.
- For early-stage startups, a minimal data room with corporate basics, a reconciled cap table, and some financials suffices; full detail is needed for Series A.
- Common deal stalls stem from cap table inconsistencies, missing IP assignments, stale valuations, or unreconciled financials, which are fixable within days.
Table of Contents
- 1. Corporate and governance documents
- 2. Cap table and equity records
- 3. Financial statements and projections
- 4. Metrics and KPI dashboard
- 5. Product and technology documentation
- 6. Contracts, customers, and vendor agreements
- 7. Team and HR documents
- 8. Legal, compliance, and insurance
- 9. Organizing the data room: folder structure, naming, and access control
- 10. Stage-specific scoping and timeline
- 11. Red flags and common mistakes that slow or kill deals
- 12. A 2 to 4 week engineer-led audit workflow and templates
- 13. What I look for first in a data room, and why clean documents matter
- 14. Optional: Hanad Kubat's fixed-price audit and rebuild offer
- FAQ
- Sources
1. Corporate and governance documents
Investors open this folder first because it tells them whether the company legally exists the way the founders say it does. Every document needs a name that matches across filings, a signature where one is required, and a date that makes sense against the company's timeline.
- Certificate of incorporation and any amendments, in the order they were filed.
- Bylaws and board or stockholder consents for major actions (option pool increases, officer appointments).
- Board and stockholder meeting minutes, especially for anything that touches equity.
- Good standing certificate from the state of incorporation, dated within the last few months.
Mark each item with a status: Exists, Needs update, Needs creation, or N/A. A founder who can hand over this folder in an afternoon signals more competence than one with a perfect pitch deck and a messy minute book.
2. Cap table and equity records
A cap table that does not reconcile to the actual paper is the fastest way to stall a term sheet. The master checklist for startup data rooms lists cap table accuracy among the top items investors verify before anything else, and a reconciled table paired with clean IP assignment is one of the most common factors that determines whether diligence clears.
- A fully diluted cap table export, ideally from Carta or Pulley, plus the pro forma post-money table showing the new round.
- SAFEs or convertible notes, with conversion terms spelled out.
- Option grant ledger and any outstanding warrant schedules.
- Current 409A valuation and its effective date.
Check every signature page, reconcile share counts against stock certificates or the transfer ledger, and confirm the 409A has not gone stale before you share the room.
Pro Tip: Run the cap table reconciliation before you touch anything else: a single off share count can hold up a signature for weeks.
3. Financial statements and projections
Investors want the same numbers in three places: the statements, the bank, and the projections. Reconciled financials beat polished ones, and founders who skip reconciliation are among the most common sources of friction once a term sheet lands, according to TechCrunch's analysis of projection mistakes, which notes that investors expect clearly stated assumptions and a direct tie between projections and historical results.
- Profit and loss, balance sheet, and cash flow with monthly detail: 3 to 6 months for a seed round, 12 months or more for Series A.
- Bank statements, invoices, and AR/AP aging that match the statements line for line.
- A short burn rate summary showing runway in plain numbers.
- Projections for 18 to 36 months, with assumptions written out next to the numbers they drive.
Skip the overfit model with forty tabs. A short, reconciled spreadsheet tied to a bank statement does more work than a glossy five-year forecast nobody can defend in a call.
4. Metrics and KPI dashboard
A single annotated page does more for an investor than a dashboard export with forty charts. A clear one-page KPI summary is often the first document an investor opens, according to the startup data room checklist, and it tends to set the tone for everything that follows.
- MRR or ARR, month over month growth rate, and gross and net revenue retention.
- Churn, broken out by logo and by revenue.
- CAC, LTV, and payback period, with the formula stated next to the number.
- Cohort retention tables and customer segmentation where the business has more than one clear segment.
Keep assumptions visible on the page itself rather than buried in a footnote. For help deciding which numbers matter at your stage, this stage-by-stage guide to SaaS metrics walks through what to track and when.
5. Product and technology documentation
This is the folder where a prototype's cracks usually show. Investors are not asking for a demo, they are asking whether the thing can survive real usage and a security review.
- A working product demo or prototype link, an architecture diagram, a short roadmap, and honest notes on technical debt.
- IP assignment confirmations: contributor agreements, any patents, and signed contractor IP assignment for every person who has touched the codebase.
- A security summary: results of any open-source audit, a SOC 2 report or a security checklist, and data-flow diagrams if the product touches sensitive data.
Redact credentials, customer PII, and anything proprietary that a competitor could use, but never redact the IP assignment paperwork itself. If you built on Lovable, Bolt, Replit, or similar tools and have not had the codebase reviewed, an engineer-led due diligence checklist is worth running before you open this folder to anyone.
6. Contracts, customers, and vendor agreements
Investors read this folder for two things: how concentrated your revenue is, and how exposed you are to a single customer or vendor walking away.
- Top customer contracts, key vendor and partner agreements, and any exclusivity clauses that limit future deals.
- A short customer concentration analysis: what percentage of revenue comes from your top three accounts.
- A summary of renewal and termination terms so an investor does not have to read forty pages of legal language to find the exit clause.
Keep contracts with sensitive pricing or exclusivity terms gated behind an NDA and release them only after a term sheet is signed. Everything else, summaries and redacted versions, can live in the open room from the start.
7. Team and HR documents
Investors check this folder for two risks: undocumented IP and messy equity. Both show up here before they show up anywhere else.
- Org chart and short founder bios.
- Employment agreements with IP assignment clauses for every employee, not just engineers.
- Contractor agreements and signed consultant IP assignment confirmations.
- Option grant summaries and any board or advisor agreements.
Flag any active HR disputes honestly rather than hoping they do not surface, because they will surface during reference calls if not here.
8. Legal, compliance, and insurance
This folder exists so counsel can clear the file quickly instead of chasing documents during a live negotiation.
- Privacy policy, terms of service, and short notes on GDPR or CCPA compliance where applicable.
- Any regulatory licenses your business needs to operate.
- Trademarks, disclosure of pending litigation, and current insurance policies (D&O, E&O, cyber).
NVCA's 2025 updates to its model legal documents sharpened the diligence focus on IP representations and data practices, including what it calls OISP and DSP exposure, according to a breakdown of the NVCA changes. If your company handles regulated data or operates across jurisdictions, add a short counsel memo addressing the specific overlay rather than leaving it implied.
9. Organizing the data room: folder structure, naming, and access control
A predictable folder tree saves every reviewer time and signals that the rest of the company is run the same way.
- 01 Corporate
- 02 Cap Table
- 03 Financials
- 04 Metrics
- 05 Product and Technology
- 06 Contracts and Customers
- 07 Team and HR
- 08 Legal and Compliance
Name files consistently, something like "03_Financials_PnL_2026-Q1.pdf" rather than "final_v2_updated.pdf." Share a light version before a term sheet: pitch materials, a summary metrics page, and high-level corporate records. Hold full financials, contracts, and option grant detail until after the term sheet is signed, gated behind an NDA.
Set permissions so most reviewers can view but not download, watermark PDFs with the investor's name, and turn on link analytics so you can see who opened what. A practical guide to secure data rooms covers these access controls in more depth if you want a second source before you set permissions.
Pro Tip: Version your files with dates in the filename, not "final" or "v2": it is the only naming convention that survives six people editing the same folder.
10. Stage-specific scoping and timeline
What belongs in the room changes by stage, and trying to build a Series A room for a seed pitch wastes time you do not have.
- Seed: a minimal viable room: corporate basics, a reconciled cap table, 3 to 6 months of financials, and a one-page KPI snapshot.
- Series A: the full room, monthly financials for 12 months or more, airtight IP assignment, and a current 409A.
- Post-term sheet: expect counsel to request deeper detail. Budget 2 to 4 weeks for the confirmatory diligence turnaround, which matches the timeline NVCA recommends for a pre-raise regulatory health check.
11. Red flags and common mistakes that slow or kill deals
Most delays trace back to a short list of recurring issues, and most of them are fixable in days if caught early.
- Cap table inconsistencies: share counts that do not match signed documents.
- Missing IP assignment for contractors or early engineers who are no longer around to sign later.
- Stale 409A valuations that no longer reflect the company's current state.
- Financials that do not reconcile to bank statements, undisclosed customer concentration, and non-standard vesting schedules.
Getting the core legal and financial mechanics right is, according to Harvard Business Review's analysis of diligence outcomes, the single factor that determines whether a deal closes on schedule or stalls. A reconciled cap table paired with clean IP assignment is among the top reasons deals stall in confirmatory diligence, per the startup data room checklist. Call counsel for the IP and vesting issues, an accountant for the financial reconciliation, and an engineer for anything in the product or security folder you cannot verify yourself.
12. A 2 to 4 week engineer-led audit workflow and templates
Here is the workflow I run when a founder hands me a prototype that needs to survive a diligence review, and it works whether you run it yourself or hand it to someone technical:
- Read the company context: stage, round size, and what the investor has already asked for.
- Assess stage fit: match the room's scope to seed, Series A, or post-term sheet expectations.
- Mark status on every checklist item: Exists, Needs update, Needs creation, N/A.
- Audit the product and technology folder specifically: architecture, IP assignment, and open security gaps.
- Draft the missing items or flag them for counsel and accounting.
- Open the room with the right permissions, watermarks, and NDA gating in place.
Useful templates to build alongside this: a cap table reconciliation checklist, a one-page KPI dashboard, and a consistent file-naming convention. For the technical half of this audit, the engineer-led due diligence checklist and the SaaS security checklist cover the parts most founders cannot verify alone.
13. What I look for first in a data room, and why clean documents matter

I open the cap table before I open anything else. If the share counts do not match the signed documents, every other folder gets read with more suspicion, fairly or not. My triage is simple: corporate and cap table first, financials second, everything else after.
A fix I make often: a contractor who wrote early code but never signed an IP assignment. It takes one email to resolve, and it is the single most avoidable reason a deal stalls.
— Hanad Kubat
14. Optional: Hanad Kubat's fixed-price audit and rebuild offer
If your product folder is the weak one, that usually means the prototype itself needs work before an investor sees it. I offer a fixed-price Prototype Audit that takes a few days and gets credited against the build if you move forward. Builds start at a fixed price, scope frozen at kickoff, weeks not months, every line written by me, no juniors, and you own the code from the first commit. One name on the contract, no surprise invoices. If this sounds like your situation, get in touch through my site and I will tell you plainly whether a rebuild is what you need.

FAQ
What documents go in a startup data room?
A data room covers eight categories: corporate and governance records, cap table and equity documents, financial statements and projections, metrics and KPIs, product and technology documentation, contracts and customer agreements, team and HR files, and legal and compliance items, as outlined in the master checklist. Each category should carry only what matches the fundraising stage.
How do I organize a data room for investors?
Use a numbered folder tree that mirrors the eight checklist categories, name files with consistent dates rather than "final" or "v2," and share a lighter version before a term sheet and the full room after. Set viewer-only permissions, watermark sensitive PDFs, and track link opens, as recommended in this guide to secure data rooms.
What financial documents do investors expect?
Investors expect a profit and loss statement, balance sheet, and cash flow statement with monthly detail, reconciled against bank statements and invoices. Projections should run 18 to 36 months with assumptions stated clearly next to the numbers, since investors prioritize reconciled facts over polished but unverifiable forecasts, per TechCrunch's reporting on projection mistakes.
What are common red flags in a data room?
The most common issues are cap table inconsistencies, missing IP assignment for contractors, a stale 409A valuation, and financials that do not reconcile to bank records. These issues are frequently cited as top reasons diligence stalls, according to the startup data room checklist.
How long does it take to prepare a data room?
A founder preparing from scratch should budget 2 to 4 weeks, matching the regulatory health check window NVCA recommends ahead of a material raise, per this breakdown of NVCA's 2025 updates. Seed-stage rooms take less time since the scope is smaller; Series A rooms, with twelve months of financials and full IP documentation, take longer.
Sources
- startup-founder-skills: data-room checklist
- NVCA updates to model legal documents: what founders and companies should know
- What most startup founders get wrong about financial projections — TechCrunch
