← Back to blog
IP & Copyright

Protecting Your Pitch: Proving What You Shared Before a Term Sheet

By Provlyn·21 July 2026

Founders who cannot prove exactly what they disclosed to an investor — which version, at which moment — face an evidential gap that no sent email, download log, or platform record can close.

The Pitch Process and What Is at Stake

Fundraising is a disclosure process. A founder pitches to dozens of investors over months, sharing financial models, go-to-market strategies, technical architecture, and proprietary market analysis. Each conversation involves disclosing information that has taken months or years to develop. Each investor who receives that information represents a potential conduit to a competitor, a portfolio company, or their own parallel investment thesis.

The scale of what is at stake is significant. In the United States, venture capital firms deployed $215.4 billion across 14,320 deals in 2024, accounting for 57 per cent of worldwide VC deal value, according to the NVCA 2025 Yearbook compiled with PitchBook data. In the United Kingdom, startups raised £9 billion in 2024, a 12.5 per cent increase from 2023, according to UK Private Capital (formerly the BVCA).

Across both markets, the competition for that capital is intense. The overwhelming majority of decks reviewed by investors are declined without funding — each one representing a set of eyes on material the founder cannot later prove they disclosed on specific terms.

The Two Evidential Problems Founders Face When Pitching

Founders face two distinct evidential problems during a fundraising process. The first is version drift. A pitch deck is not a static document. Revenue projections are updated after each investor meeting. The market size slide is revised when a competitor raises. The financial model is recalculated as the business develops. By the time a dispute arises about what was represented to a specific investor at a specific meeting, the founder may have ten versions of the same document and no independent record of which one each investor received.

The second problem is unauthorised use of disclosed information. An investor who declines to fund a startup retains knowledge of everything the founder disclosed during the process. If that investor subsequently backs a competitor with a similar approach, or if a portfolio company appears to be using the founder's disclosed strategy, defending the founder's position without a contemporaneous record is almost impossible.

The European Commission study that preceded the EU Trade Secrets Directive (2016/943) found that 20 per cent of European businesses surveyed had experienced at least one attempted misappropriation of confidential information over the preceding decade. The EUIPO's 2023 Trade Secrets Litigation Trends report, drawing on 695 judicial proceedings across EU member states between 2017 and 2022, found that commercial information — the category that includes business strategies, financial projections, and go-to-market plans disclosed during fundraising — accounted for 62 per cent of trade secret cases. The risk is not theoretical. It is documented, litigated, and overwhelmingly centred on the kind of material founders share in pitch processes.

A cryptographic deposit made before each document is shared produces a record of what was disclosed — which version, and when — that constitutes the necessary evidential foundation of any misuse claim, even if it does not prove misuse itself. The founder knows what they shared. Without a deposit certificate, they cannot prove the disclosure to the standard a court requires. Without that foundation, the investor can deny the claim and there is no objective starting point for the conversation.

Both problems have the same root cause: standard file-sharing tools — email attachments, shared links, collaborative documents — produce no independent record of what was shared, in which version, and when. They move the file from sender to recipient. They do not produce a cryptographically anchored, legally defensible record of that transaction.

What Pitch Deck Evidence Requires

The evidential standard for proving what was disclosed during a fundraising process has three properties:

Independent — created by a third party with no stake in the outcome of the fundraising or any subsequent dispute.

Contemporaneous — made at the moment the document was shared, not reconstructed from sent folders or download histories after a dispute arises.

Verifiable — in a form that cannot be altered after the fact and can be confirmed by any court, regulator, or counterparty using independent tools.

Consider what happens when none of these is met. A founder alleges that the financial projections they shared with an investor in February differed materially from the version the investor later claimed to have received. The founder's evidence is a sent email from their own account. The investor's evidence is a downloaded file with a creation date that differs by three weeks.

Both are produced by a party to the dispute. Neither is independently anchored. Neither carries a legal presumption of accuracy. A court asked to resolve the question has no objective record to work from — only competing assertions from parties with opposing interests. The dispute becomes a credibility contest rather than a factual determination.

In the United States, federal trade secret case filings reached 1,203 in 2023, a rise from post-DTSA lows, according to the Lex Machina 2024 Trade Secret Litigation Report. The pattern is consistent with a broader trend: the Defend Trade Secrets Act has driven significantly higher litigation volumes since its enactment in 2016, with DTSA-specific filings more than quadrupling from 173 cases in the first year to 749 in 2023. Across that body of litigation, the evidentiary foundation — what was disclosed, to whom, and when — is almost always the first question a court must resolve.

A founder's sent folder satisfies none of the three criteria. It is produced by the party with an interest in the outcome. An investor's download history is produced by the opposing party. A platform's access log, however well-maintained, is a record held on infrastructure controlled by a vendor whose integrity depends on its own controls, not on an external anchor.

A free timestamping service can date a file, and a public blockchain can anchor a hash. But a free RFC 3161 timestamp carries no legal presumption of accuracy — only an assertion the founder would still have to argue for in court. A raw blockchain anchor proves a hash existed, but not by whom, under what accredited authority, or in a form a court will accept without expert testimony. These are fragments. On their own, each leaves a gap an opposing party can widen.

What the evidential standard requires is a record of the document's exact contents — its cryptographic fingerprint — made at the moment it was shared, anchored externally and permanently by a qualified third party with no stake in either side of the transaction.

The Four-Layer Stack: How Pitch Deck Evidence Is Produced

A vault deposit made before a pitch document is shared produces a qualified record of exactly what that document contained at that moment. DocSend data from 2026 shows that investors spend an average of three minutes and 44 seconds reviewing a seed pitch deck. In that window, material worth months of work changes hands. The deposit is made before the deck is sent — not after a dispute arises.

Four mutually-reinforcing layers are assembled into a single qualified certificate.

SHA-256 hash — a unique cryptographic fingerprint of the exact file at that moment. A single change anywhere in the document produces an entirely different fingerprint. The fingerprint cannot be reverse-engineered to reveal the document's contents, which remain entirely under the founder's control.

RFC 3161 timestamp — the fingerprint is timestamped by an accredited Trust Service Provider, creating a cryptographically signed record of the exact moment that version of the document existed. This is not a platform-generated timestamp; it is issued by an accredited third party operating under an internationally recognised standard.

eIDAS Article 41 qualification — the timestamp is qualified by an accredited Qualified Trust Service Provider (QTSP). In EU member states the vault certificate carries a legal presumption of accuracy. Under UK law it is treated as strong electronic evidence. In the United States, Federal Rule of Evidence 901 provides for the admissibility of electronic records where integrity is established through a documented, reproducible process — which the certificate provides. It is recognised under the electronic evidence rules of most developed jurisdictions. This qualification is the distinction between a timestamp anyone can generate for free and one that carries a legal presumption of accuracy.

Bitcoin blockchain anchoring via OpenTimestamps — the fingerprint is anchored on the Bitcoin blockchain, creating a permanent public record that does not depend on any single party's continued operation to remain verifiable. Even if the issuing platform ceased to exist, the record would remain independently verifiable on the blockchain.

These four layers together produce a vault certificate — a downloadable PDF recording the file name, the SHA-256 fingerprint, the qualified eIDAS timestamp, and the Bitcoin blockchain anchor. Individually, these are components a technically capable user could attempt to assemble from free tools. Bound together into a single qualified certificate — retrievable, independently verifiable, and admissible years later without the founder having to reconstruct or explain a folder of loose files — they constitute the record a dispute requires.

Used across every version of every document shared during a fundraising process, this creates a complete disclosure history with an independently anchored record at each point. Each version is dated by an accredited third party at the moment of deposit. The full sequence is verifiable at any future point without relying on any party's own records. That sequence is what transforms a set of sent emails and access logs into a coherent evidential picture — one that does not require the founder to reconstruct anything under adversarial conditions, because the record was made at the time and has not changed.

What the Record Changes for Founders

A founder who deposits each version of their pitch before sharing it walks into every investor meeting with something most founders do not have: an anchored record of exactly what they disclosed, and when. If an investor later disputes what was represented, the deposit certificate answers the question. If proprietary information appears to have migrated to a competitor, the disclosure record establishes what was shared and when. If a dispute arises about which version of a financial model was reviewed before a term sheet was issued, the record is already there.

The EUIPO's 2023 Trade Secrets Litigation Trends report found that the success rate for trade secret infringement claims across the EU stands at approximately 27 per cent. That figure reflects, in part, the difficulty of proving the evidential foundation — what existed, what was disclosed, and when — without a record made at the time. A founder who has made that record before the pitch does not face that reconstruction problem.

The record does not prevent misuse. What it does is make the disclosure a matter of documented fact rather than assertion — which is the foundation any legal action or insurance claim requires. Insurance policies covering IP theft and business losses often turn on the policyholder's ability to establish what was disclosed and when. Without a contemporaneous disclosure record, that requirement is almost impossible to satisfy after the fact. Cryptographic prior proof is not insurance — it is the evidence that makes an insurance claim provable, a legal action actionable, and a dispute resolvable from a position of fact rather than assertion.

If you have built something worth pitching — a product, a financial model, a strategy that took months or years to develop — the question is not whether an independent record is worth the cost. It is whether you can afford to disclose your most valuable material without one. Its absence is not measured in legal fees or settlement figures. It is measured in the deal that did not close, the claim that could not be proved, the competitor that could not be challenged.

For anything you have spent months or years building, disclosing it without a qualified record is not a saving. It is a risk with no upside. The record costs almost nothing to create at the moment of sharing. Reconstructing it after a dispute cannot be done.

This post provides general information about the role of cryptographic evidence. It is not legal advice. For advice on a specific matter, consult a qualified lawyer in your jurisdiction.

Related Reading

Trade Secret Management During Fundraising and Due Diligence — WIPO Guide to Trade Secrets and Innovation

The Data Room as Evidence: Proving What Investors Saw Before They Committed

NDA Breaches and the Evidence Problem: Proving What Was Disclosed Under an NDA

James Snell is the founder of Provlyn, a platform providing cryptographic prior proof of IP ownership. provlyn.com