VDR BUILD GUIDE

A data room another person can actually navigate.

A Virtual Data Room is not a document dump. It is a controlled system showing what exists, which version is current, what is missing, who owns the next action and what may be shared at each stage.

Updated 3 August 20269-minute guideCopy-ready structure
THE STANDARD

A new team member should be able to find the current document, understand its status and identify its owner without asking the founder where it lives.

One current version

Do not place Draft, Final, Final-2 and Latest-Final beside one another. Keep a controlled working location and publish only the approved version.

Index before volume

The document index is the map. It should show file name, date, owner, status, sensitivity and the issue connected to the document.

Access by stage

A first meeting, a serious diligence process and final legal review do not require identical access. Use staged disclosure.

Gaps stay visible

A missing-item tracker is more useful than an empty folder. Record what is absent, who is resolving it and the expected date.

COPY-READY ARCHITECTURE

Suggested folder structure

01 — Corporate formation

Incorporation certificate, constitutional documents, registered-office records and relevant entity registrations.

02 — Ownership and securities

Current cap table, share issuances and transfers, convertible instruments, option pool and supporting approvals.

03 — Governance

Board and shareholder records, material approvals, delegations, policies and related-party information.

04 — Financial and tax

Historical statements, management accounts, forecasts, tax records, bank/debt information and key reconciliations.

05 — Commercial

Material customer, channel, supplier, licensing and partnership agreements, including amendments and renewal status.

06 — People and ESOP

Founder, employment and contractor records, policies, ESOP documents, grant records and key-person dependencies.

07 — Intellectual property

Assignments, licences, trademark/patent records where applicable, open-source register and product ownership evidence.

08 — Privacy and security

Data-flow records, privacy notices, material vendor arrangements, security policies and incident history where relevant.

09 — Compliance and disputes

Material licences, recurring compliance records, notices, claims, investigations, insurance and dispute summaries.

10 — Fundraise materials

Pitch deck, investment memo, use of funds, data-room index, investor Q&A and the transaction-specific request tracker.

Do not upload automatically

Privileged advice, passwords, unnecessary personal data, customer secrets, security credentials and information you are not authorised to disclose require separate handling.

CONTROL SHEET

Build a document index

Create one spreadsheet with these columns. It becomes the working control panel for the data room.

FolderDocumentPeriod/dateStatusOwnerSensitivityGap/action
02 OwnershipCurrent cap tableAs of DD/MM/YYYYApproved / reconcileFounder + CSRestrictedConfirm latest issuance
05 CommercialTop customer agreementSigned DD/MM/YYYYCurrent / amendedSales leadConfidentialRedact pricing if appropriate
07 IPFounder IP assignmentDD/MM/YYYYSigned / missingFounder + counselRestrictedProfessional review

File naming convention

Use a consistent pattern

YYYY-MM-DD_Document-Type_Counterparty_or_Period_Status.pdf
Example: 2026-06-30_Customer-Agreement_ABC-Labs_Signed.pdf

PERMISSION MODEL

Decide who can see what

LevelTypical useExamplesControl
Internal working roomPreparation and remediationDrafts, gap tracker, professional notesSmall internal team only
Early external roomInitial serious investor reviewDeck, summary financials, selected corporate recordsNamed access, limited downloads
Full diligence roomConfirmed diligence processTransaction-specific evidence and material contractsNeed-to-know permissions and activity log
Professional-only subsetLegal, tax or specialist reviewSensitive records requiring professional assessmentRestricted sharing and clear purpose

Access choices depend on the transaction, confidentiality duties and professional advice. A folder structure is not permission to disclose its contents.

48-HOUR START

Build the first usable version

Hours 1–3: create the index

List every expected document before moving files. Mark each item Ready, Review, Missing or Not Applicable.

Hours 4–8: collect, do not rename blindly

Gather records from founders, finance, people, sales and professional advisers. Preserve signed originals and source evidence.

Day 2 morning: reconcile

Compare dates, names, ownership figures and key commercial facts across the documents and pitch materials.

Day 2 afternoon: control and review

Set permissions, identify sensitive files, assign missing items and ask qualified professionals to review matters within their scope.

COMMON FAILURES

What makes a data room hard to trust

Files without context

A large folder exists, but nobody can explain whether documents are current, signed or superseded.

Deck and evidence conflict

Ownership, revenue, customers, employees or milestones differ between the pitch and supporting records.

Everything shared immediately

Sensitive information is exposed before the recipient, stage and purpose have been considered.

No owner or deadline

Gaps are known, but no person is responsible for resolving them before diligence intensifies.

NEXT STEP

Convert the folder list into a live control system.

Koda can help build the index, identify gaps and coordinate the relevant professional work before external access is opened.

Educational preparation tool only. The appropriate content, disclosure stage and access controls depend on the transaction and your confidentiality obligations.