
Healthcare due diligence in 2026: the billing problem that surfaces after close
Healthcare due diligence in 2026: the 8 review areas, the billing and overpayment trap buyers inherit, and how to run a data room for healthcare due diligence.
SaaS due diligence is the review a buyer or growth investor runs on a subscription software company before investing or acquiring. It tests whether the recurring revenue is genuinely recurring, because in a SaaS transaction the entire valuation rests on the durability of that revenue rather than on assets.
Almost every SaaS deal that reprices does so for the same reason. The seller presents an ARR number built by management, the buyer's accountants rebuild it from the billing system and the contracts, and the two numbers do not match. This guide covers the nine metrics a buyer verifies, the specific ways ARR gets overstated, the contract clauses that block a closing, and the technical and security review that runs alongside all of it.
Running that review means putting subscription reports, customer contracts, source code documentation and penetration test findings in front of reviewers who should not all see the same material. A data room for SaaS due diligence solves that with one scoped link per party. Section 8 covers the setup step by step.
SaaS due diligence is the structured investigation a buyer, growth investor or private equity fund runs on a subscription software target after signing a letter of intent. It covers the same ground as any M&A review, meaning financials, legal, tax and commercial, but it reorganises the whole exercise around a single question: how much of this revenue survives the next renewal cycle without the current owner in the building?
That question changes what gets examined. In a manufacturing acquisition, the balance sheet carries plant, inventory and receivables that a buyer can inspect and value. In a SaaS acquisition the balance sheet is mostly deferred revenue and a bank account. What the buyer is really purchasing is a set of contracts, a codebase, and a renewal habit. None of those appear as assets, so diligence has to construct their value from evidence rather than read it off a statement.
The second difference is who does the work. A general M&A due diligence checklist puts financial, legal and commercial workstreams side by side. A SaaS review adds two more that often matter as much: a technical due diligence workstream that assesses the product, the architecture and the engineering team, and a subscription analytics workstream that rebuilds the revenue metrics from raw billing data. On a mid-market SaaS deal it is normal to have four separate advisers running in parallel, each pulling from the same document set.
The third difference is that the seller's own numbers are the subject of the investigation, not the source of it. ARR, net revenue retention and churn are management metrics. They have no accounting standard behind them, no auditor signing off on the definition, and no consistency between companies. Two SaaS businesses with identical contracts can report ARR figures 15 percent apart purely because they made different choices about what counts. Diligence exists to remove that discretion.
Timing follows the standard pattern. A buy-side review starts after the letter of intent and runs 4 to 10 weeks depending on size, with the quality of earnings work and the technical review overlapping in the middle weeks. Sell-side preparation, where the company runs the same analysis on itself before going to market, typically starts 3 to 6 months earlier and is the single highest-return activity a founder can do before a process.
Every SaaS diligence report is built on the same nine measurements. They are not independent: retention drives the ARR bridge, cohort behaviour explains retention, and gross margin sets what any of it is worth. But each is verified separately, because each has its own characteristic way of being flattered.
The first four describe revenue durability. ARR and its bridge tell you the direction of travel. Gross and net revenue retention tell you what happens to a customer base left alone. Logo churn tells you how many relationships are ending regardless of value. Cohort behaviour tells you whether the pattern is stable or whether the most recent cohorts are behaving worse than the ones the averages were built on.
The next three describe the economics. Customer concentration measures how much of the revenue depends on a handful of relationships. Gross margin and cost of revenue reveal whether this is really a software business. CAC payback measures how long the company takes to earn back what it spends to acquire a customer, which is the closest thing SaaS has to a return on invested capital.
The last two are summary tests. Rule of 40 combines growth and profitability into one number that boards and buyers use as a shorthand for whether the business is compounding or burning. Revenue recognition under ASC 606 or IFRS 15 is not a performance metric at all, but it determines whether the reported revenue line means what a buyer assumes it means.
| # | Metric | What it measures | How it gets overstated |
|---|---|---|---|
| 1 | ARR and the ARR bridge | Annualised contracted recurring revenue and how it moved | Bookings counted as ARR, or ramped deals annualised at final-year rate |
| 2 | Gross and net revenue retention | Revenue kept from an existing cohort, before and after expansion | Measured on surviving customers only, or on a cherry-picked cohort |
| 3 | Logo churn | Share of customer accounts lost over a period | Downgrades reclassified as renewals so the logo is never counted as lost |
| 4 | Cohort behaviour | How each signup cohort retains and expands over time | Old strong cohorts shown while recent cohorts are omitted |
| 5 | Customer concentration | Share of ARR held by the largest accounts | Related entities of one group counted as separate customers |
| 6 | Gross margin and cost of revenue | Subscription revenue less hosting, support and delivery cost | Support, customer success or hosting parked in operating expenses |
| 7 | CAC payback | Months to recover fully loaded customer acquisition cost | Expansion revenue included, or part of sales cost excluded |
| 8 | Rule of 40 | Growth rate plus profit margin, targeted at 40 or above | Adjusted EBITDA with aggressive add-backs used as the margin |
| 9 | Revenue recognition | ASC 606 or IFRS 15 treatment of subscriptions and services | Multi-year fees recognised early, or services bundled into subscription |
Benchmarks give the numbers meaning. Net revenue retention above 120 percent is treated as best in class for B2B SaaS selling to mid-market and enterprise, 100 to 110 percent is healthy, and below 90 percent almost always triggers a repricing conversation. Gross revenue retention, which ignores expansion and therefore cannot be rescued by upsell, is the harder test: 85 to 90 percent is respectable for enterprise contracts and materially lower for SMB products. Gross margin of 75 to 85 percent is the software benchmark, CAC payback under 12 months is strong and over 24 months is a problem, and any single customer above 10 percent of ARR gets its own page in the report.
Cohort analysis is where an experienced reviewer spends the most time, because blended averages hide the direction of travel. A company whose 2023 cohort retains at 115 percent and whose 2025 cohort retains at 88 percent will still report a respectable blended figure for another year. The cohort table shows the deterioration immediately, which is why buyers ask for it monthly by signup month rather than annually.

Metric evidence, raw billing exports and customer contracts each get their own folder so reviewers can be scoped separately.
The evidence standard matters as much as the metric. A buyer will not accept a spreadsheet of ARR by month. They will ask for the raw subscription export from the billing system, the contract file for the top 20 to 30 customers by value, the invoice history, and the cash collections, and then rebuild the metrics themselves. A seller who cannot produce the raw data loses the argument by default, regardless of whether the management figures were right.
The single most common finding in SaaS due diligence is that reported ARR is higher than the revenue base can support. This is rarely fraud. It happens because ARR is a management metric with no accounting definition, and every judgement call inside it points in the same direction.
Start with the definition a buyer will apply. Committed ARR is the annualised value of contracted, recurring subscription revenue from active customers as of a point in time. Each word in that sentence removes something. Contracted excludes verbal commitments and unsigned renewals. Recurring excludes implementation fees, training, professional services and one-off overage. Subscription excludes hardware, reselling and pass-through. Active excludes customers who have given notice, whether or not their term has expired.
Sellers rarely apply all four filters at once. A paid three-month pilot at $4,000 per month gets annualised to $48,000 of ARR even though nobody has committed beyond the pilot. A customer who served termination notice in November stays in the December ARR figure because the contract technically runs to March. A $200,000 implementation project gets folded into the subscription line because it was billed on the same invoice. A ramped three-year deal that pays $100,000 in year one, $200,000 in year two and $300,000 in year three gets reported at $300,000 because that is the run rate the contract eventually reaches.
The gap between ARR and GAAP revenue exists for legitimate reasons too, and a good reviewer separates the two. ARR is a forward-looking point-in-time snapshot; GAAP revenue is backward-looking and recognised over the period the service is delivered under ASC 606 or IFRS 15. A company that closed a large deal in December will show it fully in ARR and barely at all in that year's revenue. That divergence is normal. The divergence that matters is the one that persists across four consecutive quarters, because that indicates a definitional problem rather than a timing one.
| Finding | How it surfaces | Commercial remedy |
|---|---|---|
| Pilots counted at full annualised value | Contract review shows fixed-term trials with no renewal obligation | Removed from committed ARR, price adjusted at the multiple |
| Customers who served notice still in ARR | Termination notices compared against the subscription export | Removed from ARR and reflected in the churn assumption |
| Services revenue inside the subscription line | Invoice detail split by revenue type against the general ledger | Reclassified and valued at a lower multiple, or excluded |
| Ramped contracts annualised at final-year rate | Payment schedules in the top customer contracts | ARR restated at current contractual rate for the period |
| Usage overage annualised as recurring | Twelve months of billing detail against committed minimums | Only the committed minimum counts toward recurring revenue |
| Related entities counted as separate customers | Parent company mapping across the customer list | Concentration recalculated, sometimes triggering an escrow |
| Bookings presented as ARR | Total contract value reconciled to annualised value | ARR restated, and the growth rate falls with it |
| Deferred revenue does not tie to ARR | Deferred revenue rollforward against billings and collections | Full quality of earnings scope extension, usually at the buyer's cost |
A quality of earnings review is how the normalisation actually gets done. In a SaaS deal the QoE provider builds an ARR bridge for each of the last eight to twelve quarters: opening ARR, plus new business, plus expansion, less contraction, less churn, equals closing ARR. Then they tie that bridge to three independent sources. The billing system export tells them what was invoiced. The deferred revenue rollforward tells them what was recognised. Cash collections tell them what was actually paid. Any ARR that cannot be traced to all three gets challenged.
The arithmetic of a restatement is what makes this worth the fee. At a 6x revenue multiple, every $1M of ARR reclassified out of the recurring line removes $6M from the headline price. On a company reporting $18M of ARR where $2M turns out to be services and another $2M is at risk, the correction is larger than the entire diligence budget by two orders of magnitude. That is also why sell-side preparation pays: a founder who applies the committed ARR definition to their own numbers before the process starts never has to defend a figure they cannot support.
Fees follow the general market. A quality of earnings engagement runs roughly $25,000 to $200,000 depending on deal size and complexity, with lower middle market sell-side reports commonly $25,000 to $50,000, and turnaround is typically 3 to 6 weeks. In SaaS the bulk of that time goes into the ARR reconciliation rather than into EBITDA add-backs, which is the opposite of a services or manufacturing deal. The rest of the financial due diligence scope, meaning working capital, debt-like items and the tax review, runs alongside it on a normal timetable.
Growth investors apply the same discipline for a different reason. Where an acquirer is buying the revenue outright, a minority investor is underwriting the next three years of compounding, so the cohort table matters more to them than the current quarter. Founders raising from the funds in our list of SaaS investors should expect the committed ARR definition to be applied in a growth round exactly as it would be in a sale, often by the same accounting firms.
Once the metrics are rebuilt, legal counsel reads the contracts that produce them. This workstream regularly changes the deal more than the financial one, because a contract clause can block a closing outright in a way that a metric never does.
Auto-renewal is the first thing checked. An evergreen contract that renews annually unless the customer gives 60 or 90 days notice is worth considerably more than one requiring an affirmative opt-in each year, and a customer base split between the two structures needs to be quantified rather than described. Reviewers count how many contracts carry evergreen terms, what the notice windows are, and when the largest renewals fall relative to the expected closing date. A deal that closes six weeks before 30 percent of the base comes up for renewal is a different deal from one that closes just after.
Assignment and change-of-control clauses come next, and they are the clauses most likely to delay a closing. Many enterprise SaaS contracts require the customer's written consent before the agreement can be assigned, and some define an acquisition of the vendor as an assignment. If a meaningful share of ARR sits behind consent requirements, the seller has to run a consent campaign before closing, which means telling customers about the transaction earlier than anyone wants to. Counsel will map every material contract into three buckets: freely assignable, assignable with notice, and consent required.
Pricing protections are the third area. Most-favoured-nation clauses commit the vendor to giving a customer the best price offered to anyone comparable, which caps the buyer's ability to raise prices across the base. Price-lock provisions do the same thing directly by fixing rates for a term, sometimes for the life of the relationship. A buyer whose model assumes 5 to 7 percent annual price increases needs to know what share of ARR is contractually prevented from moving.
| Clause | Why the buyer cares | Typical remedy if adverse |
|---|---|---|
| Auto-renewal and notice period | Determines how much ARR renews without a sales effort | Retention assumption lowered in the model |
| Assignment or change of control | Consent may be required before the deal can close | Consent campaign, or a closing condition on a consent threshold |
| Most-favoured-nation pricing | Caps the buyer's ability to raise prices post-close | Price increase removed from the value creation plan |
| Price lock or fixed uplift cap | Freezes rates for a defined term or for the relationship | Modelled at the contractual cap rather than at market |
| Uncapped liability | Exposes the acquired entity to unbounded claims | Specific indemnity or an increased escrow |
| Termination for convenience | Customer can exit at will, so the revenue is not committed | Excluded from committed ARR entirely |
| Service level credits | Outages convert directly into revenue give-backs | Historic credits deducted from normalised revenue |
| Data protection addendum terms | Sub-processor and transfer commitments bind the buyer | Remediation plan agreed before signing |
Uncapped liability and termination for convenience are the two clauses that most often produce a specific indemnity. A contract with unlimited liability for data breach in a company holding customer personal data is an unquantified exposure, and unquantified exposures do not get priced, they get indemnified. Termination for convenience is more straightforward: revenue a customer can walk away from at 30 days notice is not committed recurring revenue, and a disciplined buyer strikes it from the ARR base regardless of how reliably that customer has renewed in the past.

Customer contracts go to legal counsel and the QoE provider, but not to the technical advisor or the lender.
Customer diligence itself is the last piece and the most sensitive. Buyers want reference calls with 5 to 15 customers, and sellers resist because a call reveals the process to the customer base. The usual compromise is that calls happen only in the final week of exclusivity, run through the adviser rather than the buyer directly, and are limited to accounts the seller nominates. Where reference calls are not possible, buyers substitute a product usage analysis: login frequency, seat utilisation against contracted seats, and feature adoption by account, all of which predict renewal better than the customer's own stated satisfaction.
The technical workstream runs in parallel and answers a different question: can this product carry the revenue plan the buyer just paid for? It has four components, and each produces findings that land in the model as either capital expenditure, hiring cost, or risk.
Architecture and scalability come first. The reviewer examines whether the platform is genuinely multi-tenant or a set of single-tenant instances maintained separately, because the second structure caps gross margin and makes every release slower. They look at hosting arrangements and cloud spend against revenue, database design and known bottlenecks, and what the system has actually handled at peak rather than what it is theoretically designed for. A product that supports 400 customers comfortably may need a rebuild at 2,000, and the buyer needs to know which side of that line the growth plan sits on.
Code quality and key-person risk come second and are often the more important finding. Reviewers assess test coverage, deployment frequency, incident rates, documentation, and the state of technical debt, usually through a combination of repository analysis and interviews with the engineering team. Key-person risk is measured concretely: how much of the codebase has been touched by only one person, whether that person is staying, and what their retention package looks like. In a company of 30 engineers it is common to find that two of them are irreplaceable within a year, which converts directly into retention bonuses in the deal structure.
Open-source licence exposure is third. Every serious review now produces a software bill of materials and scans it for copyleft licences, particularly GPL and AGPL components, which can require the distribution of derivative source code under conditions incompatible with a commercial product. The finding is rarely fatal, but remediation takes engineering time and the buyer will want a dated plan rather than an assurance. Permissive licences still need checking for attribution obligations that nobody has met.

Penetration test findings and architecture diagrams are the documents most worth restricting to view only and watermarking.
Security and compliance is fourth and increasingly decisive, because enterprise customers make it a condition of purchase. A current SOC 2 Type II report is the baseline expectation for a B2B SaaS company selling into the enterprise, and the reviewer reads the scope statement and the exceptions rather than just noting that the report exists. A Type II covering only the production environment says nothing about internal access controls. ISO 27001 certification serves a similar role in European markets.
GDPR posture matters wherever the target processes personal data of people in the EU. Reviewers look for a record of processing activities, data processing agreements with every sub-processor, a lawful transfer mechanism for data leaving the EU, documented retention schedules, and evidence of how data subject requests are handled. They will also confirm that the company can meet the 72-hour breach notification obligation, because the acquirer inherits that clock on day one. Penetration testing is checked for cadence, normally annual with a named external firm, and for remediation evidence rather than for the report alone. A test with unfixed critical findings from 18 months ago is a worse signal than no test at all.
One newer area now appears in nearly every review: how the target uses AI and what rights it holds over customer data. Buyers ask whether customer content is used to train models, whether the contracts permit it, which model providers are in the processing chain, and whether the data protection addenda cover them. A product with AI features built on customer data without explicit contractual permission is a finding that legal counsel will want closed before signing.
Bramwell Systems is a hypothetical B2B SaaS company selling compliance workflow software to mid-market financial services firms. Management markets the business on $18.4M of ARR, 41 percent year-on-year growth and net revenue retention of 118 percent. A growth equity fund signs a letter of intent at a 7x revenue multiple and commissions a quality of earnings review alongside a technical assessment.
The QoE team rebuilds the ARR bridge from the billing system rather than from the management deck. Of the $18.4M reported, $14.2M reconciles cleanly to signed contracts, invoices and cash collections. That is genuine committed ARR and nobody disputes it.
The next $2.1M is not recurring at all. It is implementation fees, data migration projects and a block of custom development work performed for three large customers, all invoiced on the same statements as the subscriptions and therefore folded into the same line. Services revenue is real revenue, but it does not renew and does not earn a software multiple.
The final $2.1M is contracted but at risk. Four paid pilots worth $610,000 have no renewal obligation. Two customers representing $840,000 served termination notice in the previous quarter and remain in ARR because their terms run into the following year. The rest is usage overage above committed minimums that was annualised at the peak month.
Worked scenario. Only the verified recurring block earns the software multiple, which is why the restatement moves the price more than any other single finding.
The commercial effect is straightforward. At 7x, the $4.2M restatement removes $29.4M from the headline price. The fund reprices rather than walks, applies the multiple only to the verified $14.2M, values the services revenue separately at a lower multiple, and puts $2.4M into escrow against the pilots converting. Diligence ran through a data room holding 640 documents across nine folders, with the QoE provider, the technical adviser, legal counsel and the lender each on a separate scoped link.
The most expensive mistake a seller makes is presenting an ARR figure they cannot rebuild from the billing system. Management ARR is almost always maintained in a spreadsheet that has drifted from the underlying data over several years of edits. When the buyer's accountants ask for the raw subscription export and the two do not reconcile, the credibility damage extends beyond the metric itself, and every other number in the deck gets treated as suspect.
The second is running the technical review too late. Architecture findings, key-person risk and open-source exposure all change either the price or the deal structure, and a finding that arrives in the final week of exclusivity cannot be reflected in a price that has already been agreed in principle. Buyers who scope the technical workstream at the same time as the financial one avoid this; buyers who treat it as a confirmatory step at the end do not.
The third is ignoring the contract file until legal diligence starts. Assignment consents in particular take weeks of calendar time, because they require reaching a named signatory at each affected customer. A seller who discovers in week six that 30 percent of ARR requires customer consent has to choose between delaying the closing and telling their largest customers about the transaction under time pressure.
The fourth is treating cohort analysis as optional. Blended retention hides deterioration for at least a year, and a buyer who accepts a single company-wide net revenue retention figure without the monthly cohort table is buying an average that may already be historic. This is also the analysis sellers most often decline to produce, which is itself informative.
The fifth is sharing diligence material without access control. Source code documentation, architecture diagrams, penetration test findings and the full customer contract file are exactly the material a competitor would want, and SaaS processes frequently involve strategic buyers who are also competitors. Circulating it over email to four adviser teams creates an exposure the seller carries even if the transaction never completes. A properly configured data room for SaaS due diligence removes that risk without slowing anybody down, and our startup due diligence guide covers the folder structure that suits an earlier-stage version of the same process.
A data room for SaaS due diligence carries a wider range of document sensitivity than a typical M&A room. The financial folder holds commercially sensitive numbers. The engineering folder holds a description of how the product is built. The security folder holds a list of unfixed vulnerabilities. Those three should never sit behind the same permission set, and in a process involving strategic buyers who compete with the target, the difference is not theoretical.
Papermark is a secure, fully customizable, and developer-friendly data room built for modern dealmakers, with page-by-page analytics, dynamic watermarking, and transparent pricing (open-source and self-hosting available).

A SaaS diligence room with one folder per workstream, so permissions can differ by folder rather than by document.
Most SaaS processes still start on a shared drive, and it is the deal type where that habit costs the most, because four adviser teams need four genuinely different views of the same material. There are four concrete reasons a dedicated data room for SaaS due diligence earns its place. If you are still choosing a platform, our comparison of the best virtual data rooms covers pricing model, bidder management and compliance across the main providers.
The buyer is often a competitor. Strategic acquirers in SaaS sell into the same market as the target. Architecture documentation tells them how the product works, the customer contract file tells them what every account pays, and the churn analysis tells them which accounts to approach if the deal dies. A seller cannot refuse to disclose this material and still run a credible process, but they can control who sees which folder, whether it can be downloaded, and whether every page carries the viewer's identity.
Four reviewers need four different scopes. The QoE provider needs billing exports, the deferred revenue rollforward and the top customer contracts. The technical adviser needs architecture documentation, the security folder and the engineering org chart. Legal counsel needs the full contract file, IP assignments and employment agreements. The lender needs the financial summary and nothing else. A shared drive gives you one permission set. A data room for SaaS due diligence gives you one per link over the same underlying documents.
The request list arrives in waves. The reviewer reads the subscription export, then asks for the twelve contracts it references, then asks for the invoice history behind three of those. Across 640 documents and 80 open questions, an email thread loses track within a fortnight, and the same question gets asked twice by two different workstreams while a third goes unanswered.
The disclosure record matters after closing. When an indemnity claim surfaces two years later, the question is what was disclosed, to whom, and on what date. A per-visitor audit log answers that precisely. An inbox does not, and reconstructing it from email is exactly the exercise nobody wants to run under legal pressure.
The rest of this section is the practical setup: five steps to build a data room for SaaS due diligence that handles all four.
Create one folder per workstream: corporate and cap table, revenue and subscription metrics, financial statements, customer contracts, product and architecture, security and compliance, people and employment, intellectual property, and tax. That structure is what makes differentiated access possible later. A room organised as a flat pile of 640 files forces you to choose between giving everyone everything or hand-picking documents for each reviewer, and neither survives four parallel workstreams.
Upload in bulk by dragging the whole folder tree straight in, and Papermark preserves the structure. Automatic file indexing on the Data Rooms Plus plan builds and maintains the index as documents arrive, which matters in SaaS diligence because the request list grows in waves rather than arriving complete on day one.
This is where a SaaS room differs most from a general M&A room. Four adviser teams typically need four different views of the same document set, and the technical folder is the one that needs the tightest control.
| Reviewer | Folders granted | Rights |
|---|---|---|
| Buyer's corporate development team | All nine workstreams | View and download |
| Quality of earnings provider | Revenue and metrics, financials, top customer contracts | View and download |
| Technical due diligence adviser | Product and architecture, security, engineering org | View only, watermarked |
| Legal counsel | Contracts, corporate, IP, people | View and download |
| Lender | Financial summary, ARR bridge | View only |
Granular file-level permissions are set per link rather than per user, so each team gets its own link carrying its own folder scope, email allowlist or domain restriction, and download rule. Access is link-based, so no reviewer creates an account, which removes the friction that makes busy advisers ignore a room and revert to email attachments.

Permissions are set per link, so the technical adviser and the lender see entirely different folders of the same room.
Switch the product and architecture folder and the security folder to view only, and turn on dynamic watermarking, which stamps every page with the viewer's email, IP address and timestamp as it renders. Screenshot protection adds a further deterrent on the penetration test findings and the customer contract file specifically.
Pair that with NDA agreements on the link itself, so a reviewer accepts the confidentiality terms before the first document opens rather than in a separate email thread nobody can find later. The honest limit is worth stating plainly: a file that has been downloaded is legally treated as read, and no platform can recall it. That is precisely why download is disabled rather than discouraged on these folders, and why watermarking exists, because it makes any leak traceable to a named viewer.

Dynamic watermarking renders viewer identity onto every page, which is what makes a leak traceable to one reviewer.
SaaS diligence questions arrive in waves and cross workstreams. The QoE provider asks for the subscription export, reads it, then asks for the twelve contracts it references. The technical adviser reads the architecture note and asks about hosting cost allocation, which is really a finance question. Run over email, those threads fragment across the CFO, the CTO and two advisers, and nobody can tell which of 80 open questions is still unanswered.
The Q&A module on Data Rooms Plus attaches each question to the document that prompted it, with permissions controlling who sees which threads, so the lender never sees the technical adviser's findings and one bidder never sees another's questions. Answers can be published to a single group or to everyone, and the whole log exports to a spreadsheet for the closing file.
Page-by-page analytics show which reviewer opened which document, when, and for how long. In SaaS diligence this is an early warning system: an adviser who has spent forty minutes in the cohort retention file has found something, and you will usually hear about it a week before their report lands. Time spent in the customer contract folder is the other reliable signal.

Per-visitor analytics show which diligence documents each adviser opened and how long they spent on each page.
After closing, data room freeze makes the room immutable and exports it as an archived ZIP with a certificate. When an indemnity claim about a disclosed contract surfaces two years later, that archive is the record of exactly what was disclosed, to whom, and on what date.

Papermark is our #1 VDR provider for M&A transactions right now. In two deals we used custom branding, dynamic watermarking, and granular permissions.
Tyler
The Data Rooms plan is €99/month with a 7-day free trial and includes 3 team members, unlimited data rooms, unlimited documents, custom domain, advanced data room branding, data room analytics, NDA agreements, dynamic watermarking, and granular file-level permissions. Data Rooms Plus at €249/month adds 5 team members, the Q&A module with permissions, the visitor audit log, automatic file indexing, email invite viewers, a dedicated account manager, and SOC 2 Type II. Data Rooms Premium at €549/month adds 10 team members plus multi-team, unlimited encrypted storage, full API access, SSO on request, whitelabeling and custom layouts. For a competitive SaaS process where the same documentation goes to several bidders, unlimited data rooms under one subscription means one room per bidder with no per-project fee.
No credit card required.