What buyers actually test in a software company
Revenue quality, product risk and ownership of the code are the three questions behind almost every technology deal. Revenue quality means recurring contracts, churn, discounts and how much of the book sits with a few customers. Product risk covers architecture, technical debt, security history and the cost of keeping the platform running. Ownership asks whether the company really owns what it sells: employee and contractor IP assignments, third-party components and open-source licenses.
Each question has its own reviewers. Financial advisers live in the metrics folders, a technical due diligence firm reads architecture and security material, and lawyers check contracts and IP. A good room lets each group work in its own lane and pushes questions to the right person on the sell side without the deal team forwarding emails all day.
Releasing sensitive material in stages
The hardest call in a tech sale is timing. A strategic buyer that competes with the target would love to see the pricing sheet and the top fifty customers in round one. The seller needs to show enough to get a strong bid without arming a competitor if the deal fails.
Who sees what in a software sale
- 1Round one
All bidders who signed the NDA
- Anonymized revenue cohorts
- Product overview and architecture summary
- Headline security posture
- 2Round two
Shortlisted bidders and advisers
- Customer contracts with names
- Pricing and discount history
- Penetration test summaries
- 3Clean team
Named reviewers at a competing bidder
- Customer-level revenue and margins
- Product roadmap
- Key account terms
- 4Confirmatory
Preferred bidder only
- Code scan reports
- Open-source license audit
- Employee IP assignments
The clean-team group is the step most often improvised. Set it up before round two, with its own folder rules and audit trail.
A clean team is a small set of reviewers, often outside advisers, who see competitively sensitive data and report only conclusions back to the bidder’s deal team. In a data room that means a separate permission group, view-only access, watermarking with each reviewer’s name and an audit trail that can be exported if a competition authority later asks how information moved.
Code, security and open source
Source code is rarely uploaded to a transaction data room in full. The usual routes are a scan by a specialist firm, whose report goes into the room, or a supervised review session where the buyer’s engineers read code on the seller’s systems. Either way the room holds the evidence: scan results, an architecture overview, a list of third-party and open-source components with their licenses, and the security reports a buyer’s CISO will ask for.
Open-source licenses deserve a folder of their own. Permissive licenses are rarely a problem; copyleft licenses can be, if code under them is distributed with the product. The Open Source Initiative keeps the list of approved licenses most audits use as a reference. A clear inventory, with remediation notes where needed, answers a question that otherwise eats a week of Q&A.
Security history is now a standard request. Expect questions about past incidents, penetration tests, the SOC 2 or ISO 27001 status of the target itself, and how customer data is segregated. Put the reports in a restricted folder with download disabled; they describe how to attack the product as much as how it is protected. Our glossary entry on technology due diligence lists the usual workstreams.
The technology folder buyers open first
18items to prepare before round two
6folders
01Revenue
- ARR bridge and cohort tables
- Churn and expansion by segment
- Top customer concentration
02Contracts
- Master subscription agreement template
- Non-standard customer terms
- Reseller and partner agreements
03IP and open source
- Employee and contractor IP assignments
- Open-source inventory with licenses
- Patents and trademarks
04Product
- Architecture overview
- Hosting and infrastructure costs
- Roadmap summary
05Security
- Penetration test summaries
- Incident history
- Certifications and audit reports
06People
- Engineering organization chart
- Key person retention terms
- Equity and option schedule
A missing contractor IP assignment can delay signing more than any revenue question. Collect them first.
Customer contracts at volume
A SaaS company with a few thousand customers may have hundreds of signed agreements that differ from the standard template. Buyers want to know which ones contain change-of-control clauses, most-favored-customer pricing, uncapped liability or unusual termination rights.
This is where AI features in a data room earn their place. Ellty and Datasite among the picks list built-in AI tools, and Ansarada lists AI features too. Used well, they help sort contracts by type, pull out key clauses and draft first-pass summaries that a lawyer then checks. They do not replace legal review, and the seller should still prepare a contract schedule that says which agreements are non-standard and why.
Risks particular to technology deals
Competitors in the bidder pool. Strategic buyers in software are often direct competitors. Without a clean team and staged release, the seller risks leaking its roadmap and pricing to a rival that walks away.
Employees reading the room. Engineering leaders often help answer technical questions. Their access should be limited to their own folders, because the people folder may include retention and severance terms that are not yet public internally.
Personal data in product exports. Usage data and support tickets can contain customer personal data. Aggregate it, or remove identifiers, before upload. Our article on privacy laws and deal data covers the main regimes.
Export controls on encryption. Software with strong encryption can fall under export control rules in some countries. If the buyer is foreign, ask counsel whether any technical material needs a license before it is shared.
Choosing a provider for a tech sale
Tech buyers are often demanding users. Their own security teams may review the room, and their corporate development staff use several platforms a year. Ask candidates:
- Can a clean-team group be set up with view-only access and its own watermark?
- Does the Q&A route questions to named experts and keep an export for the disclosure schedule?
- What AI features are included, and does the provider say how documents are processed?
- Is SSO or an API required by the buyer’s or seller’s IT policy? iDeals, Datasite and Ansarada list SSO; iDeals lists an API.
- Can the room close with e-signature? Ellty lists it among the picks.
For a broader look at the AI side, see AI due diligence, and for a head-to-head of two of the picks, Ellty vs Datasite.
What to budget
Software sales tend to run fast once launched, with a short, crowded round two. Datasite, iDeals, DealRoom and Ansarada quote on request. Ellty publishes a price from $149/mo with a 14-day free trial, which keeps a four-month process easy to plan. Treat every figure as indicative and confirm it with the provider; our VDR pricing guide explains the billing models.
The estimator below starts from an illustrative four-month sale with about 35 external users, 12,000 pages, Q&A and AI features switched on.
Estimate a room for a software company sale
Starts from a typical process in this industry. Move the sliders to match yours. Ranges are indicative market pricing in USD, not quotes; confirm with the provider.
Indicative total by billing model
Published plans that fit the must-haves
10 more providers in our directory price on request. See VDR pricing for how each model works.
FAQ
Should source code go into the data room?
Usually not in full. Most sellers commission a code scan from a specialist firm and upload the report, or let the buyer's engineers review code under supervision on the seller's systems. The room holds the evidence, not the repository.
What is a clean team in a technology deal?
A small group of reviewers, often outside advisers, who see competitively sensitive data such as customer-level pricing and report only conclusions to the bidder's deal team. In the room it is a separate permission group with view-only access and its own audit trail.
Do AI features help in software due diligence?
They help most with contract volume: sorting agreements, flagging change-of-control clauses and drafting summaries for a lawyer to check. They do not replace legal or technical review.
How long does a data room for a SaaS company stay open?
Typically three to five months from launch to closing. Add a few weeks if a foreign investment or antitrust review applies.
Does the target's own SOC 2 report belong in the room?
Yes, in a restricted folder. Buyers treat it as evidence of how customer data is protected, and its exceptions often lead to Q&A.
