BlogMergers and AcquisitionsSaaS due diligence in 2026: not all ARR is real ARR

SaaS due diligence in 2026: not all ARR is real ARR

22 min read
Marc Seitz

Marc Seitz

SaaS due diligence is the review a buyer or growth investor runs on a subscription software company before investing or acquiring. It tests whether the recurring revenue is genuinely recurring, because in a SaaS transaction the entire valuation rests on the durability of that revenue rather than on assets.

Quick recap

  • SaaS due diligence assesses whether a subscription software company's recurring revenue will still be there in twelve months, which is what the multiple is actually paid for.
  • Nine metrics carry most of the weight: ARR and the ARR bridge, gross and net revenue retention, logo churn, cohort behaviour, customer concentration, gross margin, CAC payback, rule of 40, and revenue recognition under ASC 606 or IFRS 15.
  • Reported ARR and GAAP revenue diverge in almost every deal, because ARR is a management metric with no accounting definition and no auditor standing behind it.
  • Committed ARR counts only contracted, recurring subscription value from active customers, which excludes pilots, services fees, usage spikes above committed minimums, and accounts that have already served notice.
  • Net revenue retention above 120 percent is considered best in class for B2B SaaS, 100 to 110 percent is healthy, and anything under 90 percent usually reprices the deal.
  • Gross margin of 75 to 85 percent is the benchmark, and a target sitting well below it usually has hosting costs or a services business hiding inside the subscription line.
  • Change-of-control and anti-assignment clauses in customer contracts can require consent from a meaningful share of the customer base before the deal can close.
  • A quality of earnings review typically costs $25,000 to $200,000 and takes 3 to 6 weeks, and in SaaS it spends most of that time reconciling ARR to billings and to deferred revenue.
  • A data room for SaaS due diligence has to serve four different reviewers at once: the QoE provider, the technical advisor, legal counsel, and the lender, each with a different folder scope.
  • Papermark hosts a data room for SaaS due diligence with granular file-level permissions, dynamic watermarking, and per-visitor analytics from €99/month.

Almost every SaaS deal that reprices does so for the same reason. The seller presents an ARR number built by management, the buyer's accountants rebuild it from the billing system and the contracts, and the two numbers do not match. This guide covers the nine metrics a buyer verifies, the specific ways ARR gets overstated, the contract clauses that block a closing, and the technical and security review that runs alongside all of it.

Running that review means putting subscription reports, customer contracts, source code documentation and penetration test findings in front of reviewers who should not all see the same material. A data room for SaaS due diligence solves that with one scoped link per party. Section 8 covers the setup step by step.

1. What is SaaS due diligence?

SaaS due diligence is the structured investigation a buyer, growth investor or private equity fund runs on a subscription software target after signing a letter of intent. It covers the same ground as any M&A review, meaning financials, legal, tax and commercial, but it reorganises the whole exercise around a single question: how much of this revenue survives the next renewal cycle without the current owner in the building?

That question changes what gets examined. In a manufacturing acquisition, the balance sheet carries plant, inventory and receivables that a buyer can inspect and value. In a SaaS acquisition the balance sheet is mostly deferred revenue and a bank account. What the buyer is really purchasing is a set of contracts, a codebase, and a renewal habit. None of those appear as assets, so diligence has to construct their value from evidence rather than read it off a statement.

The second difference is who does the work. A general M&A due diligence checklist puts financial, legal and commercial workstreams side by side. A SaaS review adds two more that often matter as much: a technical due diligence workstream that assesses the product, the architecture and the engineering team, and a subscription analytics workstream that rebuilds the revenue metrics from raw billing data. On a mid-market SaaS deal it is normal to have four separate advisers running in parallel, each pulling from the same document set.

The third difference is that the seller's own numbers are the subject of the investigation, not the source of it. ARR, net revenue retention and churn are management metrics. They have no accounting standard behind them, no auditor signing off on the definition, and no consistency between companies. Two SaaS businesses with identical contracts can report ARR figures 15 percent apart purely because they made different choices about what counts. Diligence exists to remove that discretion.

Timing follows the standard pattern. A buy-side review starts after the letter of intent and runs 4 to 10 weeks depending on size, with the quality of earnings work and the technical review overlapping in the middle weeks. Sell-side preparation, where the company runs the same analysis on itself before going to market, typically starts 3 to 6 months earlier and is the single highest-return activity a founder can do before a process.

2. The 9 metrics a buyer verifies

Every SaaS diligence report is built on the same nine measurements. They are not independent: retention drives the ARR bridge, cohort behaviour explains retention, and gross margin sets what any of it is worth. But each is verified separately, because each has its own characteristic way of being flattered.

The first four describe revenue durability. ARR and its bridge tell you the direction of travel. Gross and net revenue retention tell you what happens to a customer base left alone. Logo churn tells you how many relationships are ending regardless of value. Cohort behaviour tells you whether the pattern is stable or whether the most recent cohorts are behaving worse than the ones the averages were built on.

The next three describe the economics. Customer concentration measures how much of the revenue depends on a handful of relationships. Gross margin and cost of revenue reveal whether this is really a software business. CAC payback measures how long the company takes to earn back what it spends to acquire a customer, which is the closest thing SaaS has to a return on invested capital.

The last two are summary tests. Rule of 40 combines growth and profitability into one number that boards and buyers use as a shorthand for whether the business is compounding or burning. Revenue recognition under ASC 606 or IFRS 15 is not a performance metric at all, but it determines whether the reported revenue line means what a buyer assumes it means.

#MetricWhat it measuresHow it gets overstated
1ARR and the ARR bridgeAnnualised contracted recurring revenue and how it movedBookings counted as ARR, or ramped deals annualised at final-year rate
2Gross and net revenue retentionRevenue kept from an existing cohort, before and after expansionMeasured on surviving customers only, or on a cherry-picked cohort
3Logo churnShare of customer accounts lost over a periodDowngrades reclassified as renewals so the logo is never counted as lost
4Cohort behaviourHow each signup cohort retains and expands over timeOld strong cohorts shown while recent cohorts are omitted
5Customer concentrationShare of ARR held by the largest accountsRelated entities of one group counted as separate customers
6Gross margin and cost of revenueSubscription revenue less hosting, support and delivery costSupport, customer success or hosting parked in operating expenses
7CAC paybackMonths to recover fully loaded customer acquisition costExpansion revenue included, or part of sales cost excluded
8Rule of 40Growth rate plus profit margin, targeted at 40 or aboveAdjusted EBITDA with aggressive add-backs used as the margin
9Revenue recognitionASC 606 or IFRS 15 treatment of subscriptions and servicesMulti-year fees recognised early, or services bundled into subscription

Benchmarks give the numbers meaning. Net revenue retention above 120 percent is treated as best in class for B2B SaaS selling to mid-market and enterprise, 100 to 110 percent is healthy, and below 90 percent almost always triggers a repricing conversation. Gross revenue retention, which ignores expansion and therefore cannot be rescued by upsell, is the harder test: 85 to 90 percent is respectable for enterprise contracts and materially lower for SMB products. Gross margin of 75 to 85 percent is the software benchmark, CAC payback under 12 months is strong and over 24 months is a problem, and any single customer above 10 percent of ARR gets its own page in the report.

Cohort analysis is where an experienced reviewer spends the most time, because blended averages hide the direction of travel. A company whose 2023 cohort retains at 115 percent and whose 2025 cohort retains at 88 percent will still report a respectable blended figure for another year. The cohort table shows the deterioration immediately, which is why buyers ask for it monthly by signup month rather than annually.

Data room for SaaS due diligence with subscription metrics and contract folders

Metric evidence, raw billing exports and customer contracts each get their own folder so reviewers can be scoped separately.

The evidence standard matters as much as the metric. A buyer will not accept a spreadsheet of ARR by month. They will ask for the raw subscription export from the billing system, the contract file for the top 20 to 30 customers by value, the invoice history, and the cash collections, and then rebuild the metrics themselves. A seller who cannot produce the raw data loses the argument by default, regardless of whether the management figures were right.

3. The ARR trap: why reported ARR and GAAP revenue diverge

The single most common finding in SaaS due diligence is that reported ARR is higher than the revenue base can support. This is rarely fraud. It happens because ARR is a management metric with no accounting definition, and every judgement call inside it points in the same direction.

Start with the definition a buyer will apply. Committed ARR is the annualised value of contracted, recurring subscription revenue from active customers as of a point in time. Each word in that sentence removes something. Contracted excludes verbal commitments and unsigned renewals. Recurring excludes implementation fees, training, professional services and one-off overage. Subscription excludes hardware, reselling and pass-through. Active excludes customers who have given notice, whether or not their term has expired.

Sellers rarely apply all four filters at once. A paid three-month pilot at $4,000 per month gets annualised to $48,000 of ARR even though nobody has committed beyond the pilot. A customer who served termination notice in November stays in the December ARR figure because the contract technically runs to March. A $200,000 implementation project gets folded into the subscription line because it was billed on the same invoice. A ramped three-year deal that pays $100,000 in year one, $200,000 in year two and $300,000 in year three gets reported at $300,000 because that is the run rate the contract eventually reaches.

The gap between ARR and GAAP revenue exists for legitimate reasons too, and a good reviewer separates the two. ARR is a forward-looking point-in-time snapshot; GAAP revenue is backward-looking and recognised over the period the service is delivered under ASC 606 or IFRS 15. A company that closed a large deal in December will show it fully in ARR and barely at all in that year's revenue. That divergence is normal. The divergence that matters is the one that persists across four consecutive quarters, because that indicates a definitional problem rather than a timing one.

FindingHow it surfacesCommercial remedy
Pilots counted at full annualised valueContract review shows fixed-term trials with no renewal obligationRemoved from committed ARR, price adjusted at the multiple
Customers who served notice still in ARRTermination notices compared against the subscription exportRemoved from ARR and reflected in the churn assumption
Services revenue inside the subscription lineInvoice detail split by revenue type against the general ledgerReclassified and valued at a lower multiple, or excluded
Ramped contracts annualised at final-year ratePayment schedules in the top customer contractsARR restated at current contractual rate for the period
Usage overage annualised as recurringTwelve months of billing detail against committed minimumsOnly the committed minimum counts toward recurring revenue
Related entities counted as separate customersParent company mapping across the customer listConcentration recalculated, sometimes triggering an escrow
Bookings presented as ARRTotal contract value reconciled to annualised valueARR restated, and the growth rate falls with it
Deferred revenue does not tie to ARRDeferred revenue rollforward against billings and collectionsFull quality of earnings scope extension, usually at the buyer's cost

A quality of earnings review is how the normalisation actually gets done. In a SaaS deal the QoE provider builds an ARR bridge for each of the last eight to twelve quarters: opening ARR, plus new business, plus expansion, less contraction, less churn, equals closing ARR. Then they tie that bridge to three independent sources. The billing system export tells them what was invoiced. The deferred revenue rollforward tells them what was recognised. Cash collections tell them what was actually paid. Any ARR that cannot be traced to all three gets challenged.

The arithmetic of a restatement is what makes this worth the fee. At a 6x revenue multiple, every $1M of ARR reclassified out of the recurring line removes $6M from the headline price. On a company reporting $18M of ARR where $2M turns out to be services and another $2M is at risk, the correction is larger than the entire diligence budget by two orders of magnitude. That is also why sell-side preparation pays: a founder who applies the committed ARR definition to their own numbers before the process starts never has to defend a figure they cannot support.

Fees follow the general market. A quality of earnings engagement runs roughly $25,000 to $200,000 depending on deal size and complexity, with lower middle market sell-side reports commonly $25,000 to $50,000, and turnaround is typically 3 to 6 weeks. In SaaS the bulk of that time goes into the ARR reconciliation rather than into EBITDA add-backs, which is the opposite of a services or manufacturing deal. The rest of the financial due diligence scope, meaning working capital, debt-like items and the tax review, runs alongside it on a normal timetable.

Growth investors apply the same discipline for a different reason. Where an acquirer is buying the revenue outright, a minority investor is underwriting the next three years of compounding, so the cohort table matters more to them than the current quarter. Founders raising from the funds in our list of SaaS investors should expect the committed ARR definition to be applied in a growth round exactly as it would be in a sale, often by the same accounting firms.

4. Contracts and customer diligence

Once the metrics are rebuilt, legal counsel reads the contracts that produce them. This workstream regularly changes the deal more than the financial one, because a contract clause can block a closing outright in a way that a metric never does.

Auto-renewal is the first thing checked. An evergreen contract that renews annually unless the customer gives 60 or 90 days notice is worth considerably more than one requiring an affirmative opt-in each year, and a customer base split between the two structures needs to be quantified rather than described. Reviewers count how many contracts carry evergreen terms, what the notice windows are, and when the largest renewals fall relative to the expected closing date. A deal that closes six weeks before 30 percent of the base comes up for renewal is a different deal from one that closes just after.

Assignment and change-of-control clauses come next, and they are the clauses most likely to delay a closing. Many enterprise SaaS contracts require the customer's written consent before the agreement can be assigned, and some define an acquisition of the vendor as an assignment. If a meaningful share of ARR sits behind consent requirements, the seller has to run a consent campaign before closing, which means telling customers about the transaction earlier than anyone wants to. Counsel will map every material contract into three buckets: freely assignable, assignable with notice, and consent required.

Pricing protections are the third area. Most-favoured-nation clauses commit the vendor to giving a customer the best price offered to anyone comparable, which caps the buyer's ability to raise prices across the base. Price-lock provisions do the same thing directly by fixing rates for a term, sometimes for the life of the relationship. A buyer whose model assumes 5 to 7 percent annual price increases needs to know what share of ARR is contractually prevented from moving.

ClauseWhy the buyer caresTypical remedy if adverse
Auto-renewal and notice periodDetermines how much ARR renews without a sales effortRetention assumption lowered in the model
Assignment or change of controlConsent may be required before the deal can closeConsent campaign, or a closing condition on a consent threshold
Most-favoured-nation pricingCaps the buyer's ability to raise prices post-closePrice increase removed from the value creation plan
Price lock or fixed uplift capFreezes rates for a defined term or for the relationshipModelled at the contractual cap rather than at market
Uncapped liabilityExposes the acquired entity to unbounded claimsSpecific indemnity or an increased escrow
Termination for convenienceCustomer can exit at will, so the revenue is not committedExcluded from committed ARR entirely
Service level creditsOutages convert directly into revenue give-backsHistoric credits deducted from normalised revenue
Data protection addendum termsSub-processor and transfer commitments bind the buyerRemediation plan agreed before signing

Uncapped liability and termination for convenience are the two clauses that most often produce a specific indemnity. A contract with unlimited liability for data breach in a company holding customer personal data is an unquantified exposure, and unquantified exposures do not get priced, they get indemnified. Termination for convenience is more straightforward: revenue a customer can walk away from at 30 days notice is not committed recurring revenue, and a disciplined buyer strikes it from the ARR base regardless of how reliably that customer has renewed in the past.

Link permissions restricting the customer contracts folder in a data room for SaaS due diligence

Customer contracts go to legal counsel and the QoE provider, but not to the technical advisor or the lender.

Customer diligence itself is the last piece and the most sensitive. Buyers want reference calls with 5 to 15 customers, and sellers resist because a call reveals the process to the customer base. The usual compromise is that calls happen only in the final week of exclusivity, run through the adviser rather than the buyer directly, and are limited to accounts the seller nominates. Where reference calls are not possible, buyers substitute a product usage analysis: login frequency, seat utilisation against contracted seats, and feature adoption by account, all of which predict renewal better than the customer's own stated satisfaction.

5. Technical, security and compliance review

The technical workstream runs in parallel and answers a different question: can this product carry the revenue plan the buyer just paid for? It has four components, and each produces findings that land in the model as either capital expenditure, hiring cost, or risk.

Architecture and scalability come first. The reviewer examines whether the platform is genuinely multi-tenant or a set of single-tenant instances maintained separately, because the second structure caps gross margin and makes every release slower. They look at hosting arrangements and cloud spend against revenue, database design and known bottlenecks, and what the system has actually handled at peak rather than what it is theoretically designed for. A product that supports 400 customers comfortably may need a rebuild at 2,000, and the buyer needs to know which side of that line the growth plan sits on.

Code quality and key-person risk come second and are often the more important finding. Reviewers assess test coverage, deployment frequency, incident rates, documentation, and the state of technical debt, usually through a combination of repository analysis and interviews with the engineering team. Key-person risk is measured concretely: how much of the codebase has been touched by only one person, whether that person is staying, and what their retention package looks like. In a company of 30 engineers it is common to find that two of them are irreplaceable within a year, which converts directly into retention bonuses in the deal structure.

Open-source licence exposure is third. Every serious review now produces a software bill of materials and scans it for copyleft licences, particularly GPL and AGPL components, which can require the distribution of derivative source code under conditions incompatible with a commercial product. The finding is rarely fatal, but remediation takes engineering time and the buyer will want a dated plan rather than an assurance. Permissive licences still need checking for attribution obligations that nobody has met.

Screenshot protection applied to penetration test findings in a SaaS due diligence data room

Penetration test findings and architecture diagrams are the documents most worth restricting to view only and watermarking.

Security and compliance is fourth and increasingly decisive, because enterprise customers make it a condition of purchase. A current SOC 2 Type II report is the baseline expectation for a B2B SaaS company selling into the enterprise, and the reviewer reads the scope statement and the exceptions rather than just noting that the report exists. A Type II covering only the production environment says nothing about internal access controls. ISO 27001 certification serves a similar role in European markets.

GDPR posture matters wherever the target processes personal data of people in the EU. Reviewers look for a record of processing activities, data processing agreements with every sub-processor, a lawful transfer mechanism for data leaving the EU, documented retention schedules, and evidence of how data subject requests are handled. They will also confirm that the company can meet the 72-hour breach notification obligation, because the acquirer inherits that clock on day one. Penetration testing is checked for cadence, normally annual with a named external firm, and for remediation evidence rather than for the report alone. A test with unfixed critical findings from 18 months ago is a worse signal than no test at all.

One newer area now appears in nearly every review: how the target uses AI and what rights it holds over customer data. Buyers ask whether customer content is used to train models, whether the contracts permit it, which model providers are in the processing chain, and whether the data protection addenda cover them. A product with AI features built on customer data without explicit contractual permission is a finding that legal counsel will want closed before signing.

6. Worked scenario: verifying ARR at Bramwell Systems

Bramwell Systems is a hypothetical B2B SaaS company selling compliance workflow software to mid-market financial services firms. Management markets the business on $18.4M of ARR, 41 percent year-on-year growth and net revenue retention of 118 percent. A growth equity fund signs a letter of intent at a 7x revenue multiple and commissions a quality of earnings review alongside a technical assessment.

The QoE team rebuilds the ARR bridge from the billing system rather than from the management deck. Of the $18.4M reported, $14.2M reconciles cleanly to signed contracts, invoices and cash collections. That is genuine committed ARR and nobody disputes it.

The next $2.1M is not recurring at all. It is implementation fees, data migration projects and a block of custom development work performed for three large customers, all invoiced on the same statements as the subscriptions and therefore folded into the same line. Services revenue is real revenue, but it does not renew and does not earn a software multiple.

The final $2.1M is contracted but at risk. Four paid pilots worth $610,000 have no renewal obligation. Two customers representing $840,000 served termination notice in the previous quarter and remain in ARR because their terms run into the following year. The rest is usage overage above committed minimums that was annualised at the peak month.

Bramwell Systems: reported ARR after verification
18.4$M reported ARR
  • Verified recurring ARR14.2 · 77%
    Ties to contracts, invoices and cash collections
  • Services and one-off revenue2.1 · 11%
    Implementation, migration and custom development
  • At risk or non-renewing2.1 · 11%
    Pilots, customers under notice, annualised overage

Worked scenario. Only the verified recurring block earns the software multiple, which is why the restatement moves the price more than any other single finding.

The commercial effect is straightforward. At 7x, the $4.2M restatement removes $29.4M from the headline price. The fund reprices rather than walks, applies the multiple only to the verified $14.2M, values the services revenue separately at a lower multiple, and puts $2.4M into escrow against the pilots converting. Diligence ran through a data room holding 640 documents across nine folders, with the QoE provider, the technical adviser, legal counsel and the lender each on a separate scoped link.

7. Common mistakes in SaaS due diligence

The most expensive mistake a seller makes is presenting an ARR figure they cannot rebuild from the billing system. Management ARR is almost always maintained in a spreadsheet that has drifted from the underlying data over several years of edits. When the buyer's accountants ask for the raw subscription export and the two do not reconcile, the credibility damage extends beyond the metric itself, and every other number in the deck gets treated as suspect.

The second is running the technical review too late. Architecture findings, key-person risk and open-source exposure all change either the price or the deal structure, and a finding that arrives in the final week of exclusivity cannot be reflected in a price that has already been agreed in principle. Buyers who scope the technical workstream at the same time as the financial one avoid this; buyers who treat it as a confirmatory step at the end do not.

The third is ignoring the contract file until legal diligence starts. Assignment consents in particular take weeks of calendar time, because they require reaching a named signatory at each affected customer. A seller who discovers in week six that 30 percent of ARR requires customer consent has to choose between delaying the closing and telling their largest customers about the transaction under time pressure.

The fourth is treating cohort analysis as optional. Blended retention hides deterioration for at least a year, and a buyer who accepts a single company-wide net revenue retention figure without the monthly cohort table is buying an average that may already be historic. This is also the analysis sellers most often decline to produce, which is itself informative.

The fifth is sharing diligence material without access control. Source code documentation, architecture diagrams, penetration test findings and the full customer contract file are exactly the material a competitor would want, and SaaS processes frequently involve strategic buyers who are also competitors. Circulating it over email to four adviser teams creates an exposure the seller carries even if the transaction never completes. A properly configured data room for SaaS due diligence removes that risk without slowing anybody down, and our startup due diligence guide covers the folder structure that suits an earlier-stage version of the same process.

Manage due diligence with a virtual data room

No credit card required

Page by page analytics
Unlimited documents & folders
Permission management
Dynamic watermarks
NDA collection
Real-time alerts
Custom branding
Audit trail

8. Data room for your SaaS due diligence

A data room for SaaS due diligence carries a wider range of document sensitivity than a typical M&A room. The financial folder holds commercially sensitive numbers. The engineering folder holds a description of how the product is built. The security folder holds a list of unfixed vulnerabilities. Those three should never sit behind the same permission set, and in a process involving strategic buyers who compete with the target, the difference is not theoretical.

Papermark is a secure, fully customizable, and developer-friendly data room built for modern dealmakers, with page-by-page analytics, dynamic watermarking, and transparent pricing (open-source and self-hosting available).

Papermark data room for SaaS due diligence with folders organised by diligence workstream

A SaaS diligence room with one folder per workstream, so permissions can differ by folder rather than by document.

Why you need a data room for SaaS due diligence

Most SaaS processes still start on a shared drive, and it is the deal type where that habit costs the most, because four adviser teams need four genuinely different views of the same material. There are four concrete reasons a dedicated data room for SaaS due diligence earns its place. If you are still choosing a platform, our comparison of the best virtual data rooms covers pricing model, bidder management and compliance across the main providers.

The buyer is often a competitor. Strategic acquirers in SaaS sell into the same market as the target. Architecture documentation tells them how the product works, the customer contract file tells them what every account pays, and the churn analysis tells them which accounts to approach if the deal dies. A seller cannot refuse to disclose this material and still run a credible process, but they can control who sees which folder, whether it can be downloaded, and whether every page carries the viewer's identity.

Four reviewers need four different scopes. The QoE provider needs billing exports, the deferred revenue rollforward and the top customer contracts. The technical adviser needs architecture documentation, the security folder and the engineering org chart. Legal counsel needs the full contract file, IP assignments and employment agreements. The lender needs the financial summary and nothing else. A shared drive gives you one permission set. A data room for SaaS due diligence gives you one per link over the same underlying documents.

The request list arrives in waves. The reviewer reads the subscription export, then asks for the twelve contracts it references, then asks for the invoice history behind three of those. Across 640 documents and 80 open questions, an email thread loses track within a fortnight, and the same question gets asked twice by two different workstreams while a third goes unanswered.

The disclosure record matters after closing. When an indemnity claim surfaces two years later, the question is what was disclosed, to whom, and on what date. A per-visitor audit log answers that precisely. An inbox does not, and reconstructing it from email is exactly the exercise nobody wants to run under legal pressure.

The rest of this section is the practical setup: five steps to build a data room for SaaS due diligence that handles all four.

Step 1: build the room by workstream, not by document

Create one folder per workstream: corporate and cap table, revenue and subscription metrics, financial statements, customer contracts, product and architecture, security and compliance, people and employment, intellectual property, and tax. That structure is what makes differentiated access possible later. A room organised as a flat pile of 640 files forces you to choose between giving everyone everything or hand-picking documents for each reviewer, and neither survives four parallel workstreams.

Upload in bulk by dragging the whole folder tree straight in, and Papermark preserves the structure. Automatic file indexing on the Data Rooms Plus plan builds and maintains the index as documents arrive, which matters in SaaS diligence because the request list grows in waves rather than arriving complete on day one.

Step 2: set permissions per reviewer group

This is where a SaaS room differs most from a general M&A room. Four adviser teams typically need four different views of the same document set, and the technical folder is the one that needs the tightest control.

ReviewerFolders grantedRights
Buyer's corporate development teamAll nine workstreamsView and download
Quality of earnings providerRevenue and metrics, financials, top customer contractsView and download
Technical due diligence adviserProduct and architecture, security, engineering orgView only, watermarked
Legal counselContracts, corporate, IP, peopleView and download
LenderFinancial summary, ARR bridgeView only

Granular file-level permissions are set per link rather than per user, so each team gets its own link carrying its own folder scope, email allowlist or domain restriction, and download rule. Access is link-based, so no reviewer creates an account, which removes the friction that makes busy advisers ignore a room and revert to email attachments.

Granular folder-level permissions applied per reviewer link in a Papermark data room

Permissions are set per link, so the technical adviser and the lender see entirely different folders of the same room.

Step 3: protect the material a competitor would want

Switch the product and architecture folder and the security folder to view only, and turn on dynamic watermarking, which stamps every page with the viewer's email, IP address and timestamp as it renders. Screenshot protection adds a further deterrent on the penetration test findings and the customer contract file specifically.

Pair that with NDA agreements on the link itself, so a reviewer accepts the confidentiality terms before the first document opens rather than in a separate email thread nobody can find later. The honest limit is worth stating plainly: a file that has been downloaded is legally treated as read, and no platform can recall it. That is precisely why download is disabled rather than discouraged on these folders, and why watermarking exists, because it makes any leak traceable to a named viewer.

Dynamic watermark showing viewer email, IP address and timestamp on a diligence document

Dynamic watermarking renders viewer identity onto every page, which is what makes a leak traceable to one reviewer.

Step 4: run the request waves through Q&A, not email

SaaS diligence questions arrive in waves and cross workstreams. The QoE provider asks for the subscription export, reads it, then asks for the twelve contracts it references. The technical adviser reads the architecture note and asks about hosting cost allocation, which is really a finance question. Run over email, those threads fragment across the CFO, the CTO and two advisers, and nobody can tell which of 80 open questions is still unanswered.

The Q&A module on Data Rooms Plus attaches each question to the document that prompted it, with permissions controlling who sees which threads, so the lender never sees the technical adviser's findings and one bidder never sees another's questions. Answers can be published to a single group or to everyone, and the whole log exports to a spreadsheet for the closing file.

Step 5: read the analytics, then close the room properly

Page-by-page analytics show which reviewer opened which document, when, and for how long. In SaaS diligence this is an early warning system: an adviser who has spent forty minutes in the cohort retention file has found something, and you will usually hear about it a week before their report lands. Time spent in the customer contract folder is the other reliable signal.

Per-visitor analytics across SaaS due diligence documents in a Papermark data room

Per-visitor analytics show which diligence documents each adviser opened and how long they spent on each page.

After closing, data room freeze makes the room immutable and exports it as an archived ZIP with a certificate. When an indemnity claim about a disclosed contract surfaces two years later, that archive is the record of exactly what was disclosed, to whom, and on what date.

Tyler

Papermark is our #1 VDR provider for M&A transactions right now. In two deals we used custom branding, dynamic watermarking, and granular permissions.

Tyler

Fox Island Group

What it costs

The Data Rooms plan is €99/month with a 7-day free trial and includes 3 team members, unlimited data rooms, unlimited documents, custom domain, advanced data room branding, data room analytics, NDA agreements, dynamic watermarking, and granular file-level permissions. Data Rooms Plus at €249/month adds 5 team members, the Q&A module with permissions, the visitor audit log, automatic file indexing, email invite viewers, a dedicated account manager, and SOC 2 Type II. Data Rooms Premium at €549/month adds 10 team members plus multi-team, unlimited encrypted storage, full API access, SSO on request, whitelabeling and custom layouts. For a competitive SaaS process where the same documentation goes to several bidders, unlimited data rooms under one subscription means one room per bidder with no per-project fee.

No credit card required.

FAQ

More useful articles from Papermark

Ready to create your deal room?