Software businesses are valued on recurring revenue, but they are bought on the strength of things the revenue chart does not show: who owns the code, what is hidden in it, and what the company has promised its customers. A UK technology deal room is built to answer those questions quickly, because buyers of software companies tend to arrive with technical advisers who know exactly where to look.
Beneath the ARR line
What sits beneath the ARR line
The deck does its job at the top of the funnel. Once heads of terms are signed, the work moves underwater. Lawyers check that every founder, employee and contractor who wrote code has assigned the rights to the company. Technical advisers scan the codebase for open-source components whose licences could force disclosure of proprietary code. Commercial reviewers read the largest customer contracts for liability caps, service credits and change of control clauses that let a customer leave if the company is sold.
A room plan for a software deal
| Folder | What goes in | Opened to |
|---|---|---|
| Product and roadmap | Architecture overview, product roadmap, hosting arrangements | All bidders after NDA |
| Intellectual property | Assignments, employment and contractor agreements, trade marks, domain registrations | Bidders’ lawyers after heads of terms |
| Customers | Top contracts, standard terms, churn and renewal data | Summary first; full contracts after heads of terms |
| Security and data | Policies, penetration test summaries, incident log, records of processing | Named technical advisers only |
| Tax | Corporation tax returns, R&D relief claims, share scheme filings | Accountants after heads of terms |
Code review without uploading the code
Source code almost never belongs in a data room. Downloads, even watermarked ones, cannot be recalled, and a bidder that walks away has still seen your work. The usual approach is controlled review:
Agree scope with the buyer
Decide whether the buyer needs a full code scan, an architecture walkthrough, or both, and record the agreement in the Q&A log.
Use a third-party scan
An independent scanner runs over the codebase and reports on open-source licences and security issues. Only the report goes in the room.
Offer supervised sessions
For deeper questions, the buyer's technical adviser reviews code on screen with your engineers present, with no copies taken.
Document what was shown
Upload a note of each session to the room so the disclosure record covers it.
Customer data: usually you are the processor
Most SaaS companies process personal data on behalf of their customers, which makes them a processor under UK GDPR. Buyers will want to see the data processing terms you have signed, the list of sub-processors you use and how you handle international transfers. Do not upload customer data itself; a sample record with fields described is enough to show how the product works. If you have reported a breach to the ICO, expect the file to be read closely.
Tax relief and national security
Many UK software companies claim research and development tax relief. Buyers and their accountants will want the claims, the technical reports behind them and any HMRC enquiries, because a challenged claim can lead to repayment after completion.
Deals involving certain technologies, including artificial intelligence and computing hardware, can fall under the National Security and Investment Act, which may require notification to the government before completion. Your lawyers will advise whether it applies; if it does, build the timetable around it.
Mistakes that slow software deals
Founders often discover too late that an early contractor never signed an IP assignment, or that the first version of the product was written before the company existed. Others share full penetration test reports with every bidder instead of a summary, leave admin credentials in architecture diagrams, or upload customer contracts that name customers whose consent to disclosure was required. Fix the IP gaps before the process starts, and redact or summarise before you upload.
Budget
A seed or Series A raise needs only a modest room for a few months. A sale run by a bank to a wide group of bidders may justify an enterprise quote. Since many software companies raise money several times before a sale, consider a provider whose pricing still makes sense if the room stays open between rounds. Our cost guide and providers page set out the options, and our SEIS and EIS page covers early rounds.
Questions people ask
Should we put our source code in the data room?
Generally no. Share an independent scan report and offer supervised review sessions instead. Code that has been downloaded cannot be taken back if the bidder withdraws.
What do buyers of UK SaaS companies check first?
Ownership of the IP, the terms of the largest customer contracts, recurring revenue quality and churn, and security history. Gaps in IP assignments are one of the most common reasons for price chips.
Do we need to tell customers before sharing their contracts?
Check each contract's confidentiality clause. Many allow disclosure to prospective buyers under an NDA; some require consent. Where in doubt, share a summary first and full contracts later in the process.
