There is no NDA at seed. Every deck, every memo, every cap table I put in front of an investor might, eighteen months from now, sit on the desk of someone building a competing product. That is not paranoia; it is the deal-flow math of early-stage investing. Once I accepted it, the actual question got much simpler: not "how do I keep this safe" but "what exactly am I willing to lose." Withhold everything and the raise never gets off the ground, because conviction requires evidence. Share everything and you have handed a blueprint to whoever asks nicely enough. Somewhere between those two failure modes is a data room that actually works.
I am a founder, midway through raising our seed round. What follows is the process I actually ran to build our data room, including the parts I got wrong the first time. It is not a template; it is a record.
My starting thesis, which held up: a data room used to be a folder. Run properly in 2026, it is three separate things wearing one interface. It is an editorial decision about what never gets shared, made once and revisited rarely. It is a measurement instrument, because every document you hand over is also a probe into how seriously the other side is looking. And it is, for the first time this cycle, something an AI answers questions from directly. That last part changes what "building" the room even means: you are not just organizing files, you are writing source material for a system that will represent you in your absence.
Part 1 — Before touching a single document
Step 1: Accept there is no NDA, then write the never-share list
Seed investors will not sign an NDA before looking at your materials, and if you ask, most treat the request itself as a small red flag. (The polite ones will explain why. The others just stop replying.) A seed fund looks at hundreds of companies a year across overlapping categories. An NDA binding them to every founder's confidentiality terms would make pattern-matching across a market impossible, and a fund that would rather protect your secrets than see enough deals to find the outliers is not a fund with useful judgment anyway. I stopped treating this as an obstacle once I understood it was structural, not personal.
That reframes the actual problem. With no legal backstop, the room's contents have to earn their place on a different basis: does showing this create conviction that outweighs the risk of it leaking. Most documents clear that bar easily. A financial model, a product walkthrough, a customer list with logos you are proud of. Some do not, and those go on what I started calling the never-share list. Written down, in our case, later than it should have been, which I will come back to.
Mine had four categories. Customer-identifying contract terms: not the fact that we have customers, which is worth sharing, but the specific pricing and volume terms in those agreements, because a competitor with that sheet could underprice a renewal conversation before we ever had it. The unpatented mechanics of our core IP, meaning the parts of what we do that are defensible only by not being known. Security architecture specifics, for the obvious reason that a document describing exactly how a system is protected is also a document describing exactly where to look. And the fourth, the one that surprises people: our full reading of the market itself. We are industry veterans before we are tech founders, and the most valuable thing we own is not in the codebase. It is the way we see the category: how we think this will be consumed a few years from now, how our clients' industry will evolve, and in what order. Hear it once and you cannot unhear it; it reorganizes how you look at the whole space. The deck carries exactly enough of that thesis to make the case. The full version stays out of the room, because of everything we have, it is the easiest thing to steal. No code to copy, no team to poach. Just a way of seeing that fits in one memo.
Writing that list down as an explicit standard mattered more than I expected. Once it existed, every decision about what to include was pre-filtered against it, instead of being adjudicated document by document under time pressure with an investor waiting. If you are starting this process, write your version of this list first. Everything else gets easier once it exists.
Step 2: You are trading information for engagement, so measure the engagement
I have been measuring investor attention since before this raise. When a fundraise meant emailing a deck as a PDF, I ran it through a read-receipt tool, because that was the only way to know whether an investor who said "sending it to my partners" actually did. Later, deck tools showed me which slide made someone pause and which they blew past. A data room is the next rung on that ladder: it tells you who is doing real analytical work and who is skimming. Investors do not let you watch their face while they read your materials; analytics are the next best thing. The instrumentation exists. The discipline is deciding to read it, and the reason to read it is not curiosity. A raise runs on founder attention, and attention spent on an investor who was never going to move is attention taken from one who might. Measurement is how you point that attention at the only goal that counts: closing the round.
Opening a full data room raises the stakes of the trade. You are handing over dozens of documents instead of one deck, and the information asymmetry that measurement corrects for gets bigger, not smaller. If your instrumentation does not improve at the exact moment your disclosure does, you have made a worse trade than the deck-by-email era: more given away, same blind read on who is serious.
So decide upfront which signals you will read. Ours were simple: who opened which folder and how long they stayed, who downloaded files versus reading in the browser, and what questions they asked the room's AI. That last signal is new this cycle, and it turned out to be the most useful one I had. Part 4 is mostly about it.
Part 2 — Building the corpus (where the AI work starts)
Step 3: Assemble the documents, standard themes plus yours
The standard categories are what you expect: formation documents and cap table, financials and the model, deck and memo, key agreements, IP assignments, team documentation. This site keeps the full category-by-category breakdown in its due diligence checklist, and I am not going to produce a worse copy of that page here.
What we added beyond the standard set was specific to where our diligence actually concentrates: a deep research folder documenting the technical and market research underlying our core claims, and a regulation folder addressing the compliance questions that come up early and often in our category. If your company sits in a regulated space or makes a technical claim that needs backing, build the folder that answers that question before someone asks it, not after.
The addition that mattered most, though, was a folder I labeled the DDQ folder. That is due diligence questionnaire, not FAQ, and the distinction is not pedantic. A due diligence questionnaire is the structured set of questions a diligent investor works through methodically: unit economics assumptions, customer concentration, competitive moat, key-person risk, use of proceeds. An FAQ is whatever questions happen to have come up before and felt worth writing down. We pre-answered the DDQ themes before a single investor asked a single question, and we wrote those answers with a second audience in mind: not just a human skimming the room, but the AI that would be answering investor questions on our behalf. A document written to pre-empt the standard diligence questions, in plain declarative sentences, is also the best possible source material for a system that has to retrieve an answer and cite where it came from. Writing for both audiences at once is free, since it is the same document, but only if you write with the AI reader in mind from the start rather than as an afterthought.
Step 4: Fire up an AI agent and audit your own room
Once the corpus existed, before any investor saw it, I put everything, every document across every folder, in one place and ran an AI agent against the whole thing. I used Claude, through Cowork, and gave it three assignments, close to verbatim: "Read everything; find discrepancies and confusing elements." "What is missing for a seed-stage data room?" And, because the room itself would soon be answering questions: "We're using an AI-powered data room. What explainer files should exist to make its answers sharper?"
The first assignment paid for itself immediately. Our documents had been written at different moments, some by different people, and the numbers had drifted: the client count stated in one document did not match another, and several financial figures disagreed depending on which document had been updated last. None of the discrepancies were large, which is exactly what made them dangerous. A big error reads as a mistake; a small inconsistency reads as carelessness, and an investor who catches one starts quietly wondering what else does not reconcile. We fixed every one before anyone else could find them.
We also handed it the never-share list from step 1 and asked it to sweep the room against it. It found a few places where we were breaking our own rules: details that had slipped into documents assembled before the list existed. That is the quiet argument for doing this with an AI at all. The never-share list is only as good as its enforcement, and enforcing it by rereading every page yourself is exactly the kind of work that does not survive contact with a live fundraise.
The third prompt changed the room the most. It proposed documents we did not have: an investor memo pulling the narrative together instead of leaving it scattered across the deck, a financial model overview translating the spreadsheet's assumptions into prose, an R&D roadmap explaining where the technical work goes next. Then it kept going: a go-to-market document, founder bios written for diligence rather than for the website, an exit strategy document, a moat document. We wrote them all. The logic behind every one was the same: an AI reading the room the way an investor's AI eventually would could find nothing coherent to point to for those questions, so we gave it something. Yes, we now have documents whose entire job is to explain other documents. I have made my peace with it.
Step 5: Write the bespoke files with the AI, not by the AI
The way we wrote those documents is the part I would recommend most specifically, and it was not "ask the AI to write a memo." I tried that once. You get something plausible, generic, and missing every judgment call that only exists in your head.
What we ran instead was a loop. I started by writing rough bullets of what I believed a seed investor needed to take away: the points they would repeat to their own investment committee when we were not in the room. Claude turned the bullets into a draft, with the full data room available to it as context. I corrected the draft. Then came the useful part: I asked it to reread the corrected version as a tier-1 seed investor and report the good, the bad, and the ugly, with explicit instructions not to sugarcoat. We worked through that list together, filling gaps, fixing what was misleading, rewriting what could be misinterpreted. Throughout, it had a standing invitation to ask me clarifying questions whenever the room's documents did not settle a point, and it used it more than I expected. The memo that resulted is mine. Every claim in it is something I wrote, said, or signed off on under cross-examination, and it is better than what either of us would have produced alone.
The line of questioning that earned its keep was go-to-market. It has been our weakest area since the beginning: we sell to enterprises, and enterprise at seed is a hard motion to run credibly. Every pass of the good-bad-ugly review flagged it, and every clarifying question about it was one I liked less than the last. That discomfort was the useful part. It forced a genuinely better understanding of our own market, and more importantly a decision about who we would not go after, and why. When investors later pushed on go-to-market, what landed was not the target list. It was the clarity about what we had ruled out.
Step 6: Red-team before any investor enters
The last pre-launch step was adversarial. I asked for a grade against peer seed-stage rooms, a list of what would make an investor pass, and a list of what would make them pause. The two lists got different treatment. Pass reasons, the ones a rational investor walks away over, got fixed outright or addressed head-on in a document. Pause reasons became talking points for calls instead, because some explanations are better delivered in conversation, and a room that pre-explains every conceivable hesitation reads as nervous.
One practical note: this only works as an iterative process, and only if you make the AI play roles and order it to push back. Left to its defaults, it reviews your work like a supportive parent. Ask it to be the skeptical associate, the partner who has seen this movie a hundred times, the competitor reading your room with a highlighter, and tell it explicitly not to sugarcoat anything. The first honest pass stings. That is how you know it is working.
Part 3 — Structuring the room
Step 7: Three phases that mirror how a seed process actually runs
We structured the room into three phases, and the mapping follows the shape of a real seed process rather than an arbitrary tier system. Phase one is narrative: the deck, the investor memo, summary financials, a product overview. Its only job is to build enough conviction that an investor wants to go deeper. Nothing in it should require explanation on a call, and nothing in it is sensitive enough to worry about who eventually sees it. Phase two is business diligence: the full financial model, pipeline and traction detail, the research and regulation folders, the DDQ folder, and team references. This is where a genuinely interested investor spends real time, and where the AI does the most work, because this material is dense enough that nobody reads all of it manually.
Phase three is confirmatory, and at seed it is overwhelmingly a legal exercise: corporate documents, cap table detail, IP assignments, and key contracts, reviewed mostly after a term sheet is signed. Accounting confirmatory work at seed is light; there is usually not much history to confirm yet.
Each phase gate is tied to a milestone of demonstrated engagement, not a date on a calendar. Nobody advances to phase two because five days passed. They advance because they have engaged with phase one in a way that signals real interest: asked a substantive question, spent real time in the materials, taken a second call. That distinction matters practically. A calendar-gated room either rushes unready investors into sensitive material or holds back a serious one arbitrarily, and neither serves you.
What worked well in practice: when an investor earned the next phase, I changed one setting and they had it. All of it, at once. No new link to send, no checking which folder had been shared with whom, no reconciling five sharing systems that each believe something different about the world. And the investor side mattered just as much: before someone earned a phase, they did not see that it existed. Not a locked folder, not a grayed-out name. Nothing. Which means no requests for early access to something they spotted in a file tree, and no questions about a folder name they had not earned yet. The structure of the room was never itself a disclosure.
Step 8: Test the AI like a skeptical associate
Once documents were uploaded and phased, I tested the Q&A layer before any investor touched it. I asked the AI to generate the test questions itself, instructed to make them non-generic and specific to our company: the kind a sharp associate would ask after having read everything, not the boilerplate list every startup gets. Then I ran each question against the room's own AI and read the answers with the same skepticism I would want an investor to bring.
I judged each answer on three things: was it accurate against the source documents, did it cite where the answer came from rather than asserting it unsupported, and, the most revealing test, what it did when the room was actually silent on something. A system that confidently fabricates when it does not know is worse than useless in a diligence context. The correct behavior is to say the material is not there, and testing for that failure mode before an investor could trigger it live was worth every minute it took.
Step 9: Custom instructions, or teaching the AI your context
Early in testing, I asked the room's AI how an investor should think about our valuation. It kept coming back to one comparable transaction in our space with a very low price, treating that number as a market signal for our stage and category. It was not one. That transaction was an acqui-hire: a distressed sale of a team, not the pricing of a business. The AI also kept reaching for revenue multiples, the way a later-stage or public-market analysis would, when revenue multiples tell you close to nothing about a seed round priced on team, market size, and early signal.
Both errors trace to the same root cause. The AI was pattern-matching against the general corpus of valuation discussion it was trained on, which is dominated by later-stage framing, and nothing in our documents told it that framing did not apply here. So we wrote custom instructions steering it toward stage-appropriate valuation framing and directly instructing it to stop treating that one acqui-hire as a relevant comp. The lesson is broader than valuation. The AI answering questions in your room is only ever as calibrated as the context you hand it. Uploading documents gets you a generic answer machine wearing your logo. The custom-instruction pass, going through the specific ways it gets your context wrong and correcting each one explicitly, is what turns it into something that answers the way you would.
And there is a reason I would argue this step is not optional. Investors run AI over your documents whether you offer it or not, and this is not speculation: our own pre-seed investors have spent the past year rebuilding their workflows around agentic AI, vibe-coding their own tooling, with the enthusiasm of people who just discovered they can build things too. It is genuinely fun to watch. It also means that the moment someone downloads your room, your deck and your model are going into their own AI session, and that session carries the exact miscalibrations mine did. The acqui-hire gets anchored on. The revenue multiples get reached for. Except in their session, nobody is there to correct it. The mis-pricing happens silently, inside an analysis you will never see, and it hardens into a partner-meeting opinion before you have had the conversation. The AI in your own room is the only reader of your documents you will ever get to calibrate. That is what the custom-instruction pass really is: not tuning a chatbot, but taking the one seat you are offered at a table where your company is being analyzed by machines either way.
Part 4 — Running the process
Step 10: Investor behavior is the real signal
Once invitations went out, the split in behavior showed up almost immediately. Some investors downloaded a batch of files and went quiet: reviewing on their own time, or possibly not at all, with no way to tell which from the access log alone. Others started asking questions through the room within a day, and the type of question was the real signal, more than the fact of asking one. A question referencing something specific three documents deep (a term in a contract, an assumption buried in a model tab) meant someone was doing the analytical work of underwriting the company. A generic, could-have-asked-without-reading-anything question usually meant an investor keeping the relationship warm while waiting to see whether other investors moved first.
The question patterns fed back into the raise itself. When the same clarifying question kept coming up across investors, the deck or memo was failing to convey something it needed to, so we rewrote that section once instead of answering the same question individually forever. None of this closed a deal; a data room never does. What it did was tell us where to point the attention the raise runs on, and which explanation needed fixing before the next call.
Step 11: Progressing investors asynchronously
The practical benefit of tying phase advancement to engagement rather than a calendar showed up here. Serious investors moved into phase two at different points in the process, each on their own timeline, each on their own demonstrated interest. Never a batch event, never an awkward moment of deciding whether everyone moves up today. One investor earned phase-two access on day four because they had clearly done the phase-one reading and asked a sharp follow-up; another sat in phase one for three weeks because nothing they had done yet warranted more.
The convenience of that asynchrony compounds as the number of active conversations grows. Each investor's access always matches exactly where they are in the process, without anyone tracking it manually or remembering what was promised to whom in which call. I did not build a spreadsheet to manage this. The room's own state was the record.
What I'd do differently
Three things, honestly. I would start the never-share list before having a data room at all, not after beginning to assemble documents. Writing it retroactively meant re-examining folders I had already half-populated instead of filtering from a clean standard. I would write the DDQ folder before the deck rather than after, because pre-answering the hard diligence questions clarified our own narrative in ways that would have made the deck itself better. And I would run the red-team pass twice, not once: before launch, which we did, and again after the first batch of real investor questions came in, because those questions surface gaps that no AI grading its own homework in a vacuum is going to find on the first pass.
The wrong question
Founders sometimes ask whether it is worth adding AI to a fundraise. I think the question is backwards. AI entered your fundraise the moment the first investor downloaded your deck and pasted it into a chat window. It is already reading your documents, already picking your comps, already drafting the first version of the partner-meeting opinion. The only open question is whether anyone taught it your company first.
That is what this whole process was, really: eleven steps of teaching. If you want to see what a room built that way looks like in practice, there is an open demo on this site's homepage, no signup required.