Proving the deck existed is the easy half, and it is the half every tool in this space addresses. Hash it, timestamp it, done. The half nobody covers is the disclosure: which of your versions reached which individual, on what date, and whether they opened it.
That is the half a dispute turns on, because the deck is rarely what anyone contests. Our post on pitch deck evidence goes into the version problem in more depth.
| Method | What it records | The difficulty |
|---|---|---|
| Email attachment | A line in your own sent folder | Produced and held by the party relying on it |
| Cloud link | Vendor access logs, if retained | Held on the vendor’s infrastructure, and every recipient gets the same file |
| Data room | Who entered and what they opened | Still the vendor’s record, and rarely dated by an independent party |
| Vault with per-recipient copies | Each view timestamped, each copy separately fingerprinted | Only covers what you actually shared this way |
The last row carries a real limitation and it is worth saying so: it only covers material you actually shared that way. A deck emailed in a hurry before a Tuesday meeting is outside the record, and no product fixes that.
A deck is not a document, it is a sequence. Numbers get updated after every meeting, the market slide is rewritten when a competitor announces, the model is recalculated when the pipeline moves. By the end of a raise the people you have spoken to are holding materially different documents, and no two of them saw the same thing.
That matters in two directions. If someone later says they were shown projections you never made, you need to establish what they actually received. If proprietary material appears elsewhere, you need to establish that it was in the version that went to a particular firm. Both require a record that ties a specific file to a specific recipient on a specific date, and an outbox does not do that.
Sharing from a vault means the material is opened through a controlled link rather than sent. Each view is logged against a timestamp, access can be withdrawn when a process ends, and each recipient can be issued an individually watermarked copy rather than everyone receiving the same file.
Each of those copies has its own SHA-256 fingerprint and its own certificate reference. So a document that turns up where it should not can be matched against the issuance record and attributed to the copy it came from, and therefore to the recipient it was issued to. This works for PDFs, which is how decks and plans are almost always circulated.
For a raise run properly there is a VC Deal Room built for the same purpose on the other side of the table, and the same question applies to what a data room can and cannot establish about what investors saw.
A business plan or financial model can qualify as a trade secret, which requires three things under Article 2(1) of Directive (EU) 2016/943: that it is secret, that it has commercial value because it is secret, and that it has been subject to reasonable steps to keep it secret. The third is where founders in a fundraise are weakest, because reasonable steps have to be shown rather than described.
Restricting access and keeping a dated record of who was granted it is one of those steps, and the record of it is produced as a by-product of sharing normally rather than assembled later to support a claim. Because the measures are weighed as a whole rather than document by document, a practice applied to some material and not to comparable material is weaker than one applied by default, which is an argument for handling everything the same way rather than only what feels sensitive. What that element requires in full is set out on trade secrets, and the separate question of what an agreement actually covers is on NDAs and contracts.
Each version is deposited before it goes out. The file is hashed with SHA-256, the hash is timestamped under RFC 3161 by an accredited trust service provider, and the timestamped hash is anchored to the Bitcoin blockchain. Only the hash travels, so nothing about the contents leaves your control at the point of recording.
With eIDAS qualification the timestamp carries the presumption under Article 41(2) that the date and time are accurate and the data intact, which shifts the burden to whoever disputes it. A blockchain anchor alone does not carry that presumption, a distinction set out in blockchain timestamps compared with qualified timestamps.
Every certificate can be checked without us, using SHA-256, OpenSSL, the European Commission's trusted lists and any OpenTimestamps client. Our timestamp validator is open source and checks any provider's timestamp, not only ours, and independent verification sets out each check in full.
That anybody misused anything. A disclosure record shows what was shared, with whom, and when it was opened. Whether a later product or strategy derives from that disclosure, rather than from independent development or from what was already public, is the contested question and it is decided on far wider evidence. The record puts you in a position to bring the argument from documented fact rather than recollection. It does not win the argument, and a page claiming otherwise would be selling you something it cannot deliver.
Record your first deposit →The founder knows what happened and cannot evidence it. A firm passes, and eighteen months later something close to the strategy appears in a portfolio company or a competitor. The founder is certain the material came from that meeting. What they hold is a sent folder on their own machine, showing that a file with some name went to an address on a date. What they need is a record of which version reached which individual and when it was opened, made by something other than their own email client.
It settles one question and leaves the harder one open. A timestamp proves that a file with that exact content existed on that date, which forecloses any argument that the deck was written later or altered afterwards. It records nothing about the disclosure: not who received it, not which of your versions they got, not whether they opened it. In a dispute the deck is rarely what is contested. The circulation is.
By sharing from a place that records it rather than by attaching files to emails. A deck changes throughout a raise, with numbers updated after each meeting and the market slide rewritten when a competitor announces. Twenty investors can hold twelve different versions. Sharing from a vault means each recipient opens through a controlled link and each view is logged against a timestamp, so the question of which version reached whom is answered by a record rather than by reconstructing your own outbox.
Where each recipient is issued their own copy, yes. Provlyn can issue an individually watermarked copy per recipient, and each copy has its own SHA-256 fingerprint and its own certificate reference. A document that surfaces where it should not can be matched against the issuance record, which identifies the copy and therefore the person it was given to. This works for PDFs, which is the format most decks and business plans are shared in.
That a particular recipient opened a particular file at a particular time. That is narrower than it sounds and more useful than it sounds. It does not establish what they did with the material or what they understood from it. What it removes is the defence that they never saw the thing, which in practice is where these arguments start, and it does so with a record generated at the moment of access rather than assembled afterwards.
No, and the two answer different questions. An agreement creates the obligation. A record establishes what was disclosed under it. Investors frequently decline to sign before a first meeting, which is a commercial reality rather than a problem to be solved by technology, and material shared without an agreement can still be confidential in the general law. What a dated disclosure record does is put you in a position to say precisely what was shared and to whom, whether or not an agreement was in place. The scope question is taken up separately on our NDAs and contracts page.
It can be, if it is secret, has commercial value because it is secret, and has been subject to reasonable steps to keep it secret. Those are the three conditions in Article 2(1) of Directive (EU) 2016/943, mirrored in UK and US law. The third one is where fundraising founders are usually weakest, because reasonable steps have to be evidenced rather than asserted. Restricting access, logging who was granted it, and issuing controlled copies produce exactly that evidence as a by-product of sharing normally. One caution follows from how the test works: measures are weighed as a whole rather than document by document, so a practice applied to some material and not to comparable material is weaker than one applied by default, and an opponent can be expected to make that point.
Each version of each document as it goes out. The deck, the financial model, the market analysis, the product roadmap, the term sheet drafts. Recording only the first version leaves every later one unevidenced, and later versions are usually the ones carrying the material that matters. Each deposit produces its own certificate, so a sequence across a raise shows how the material developed as well as what it contained at each point.
Misuse. It also does not establish that the recipient understood the material, that they retained it, or that anything they did afterwards was connected to it. A defendant in this position will run independent development, and will point to what was already public in your sector at the time. Those arguments are met with market evidence, technical comparison and the sequence of their own development, none of which a disclosure record supplies. What it supplies is the starting point that would otherwise be missing.
In the EU a qualified electronic timestamp carries a presumption under Article 41(2) of Regulation 910/2014 that the date and time are accurate and the data intact. The presumption is rebuttable, shifting the burden to the party disputing it. It applies across all EU member states, and the EEA states recognise qualified timestamps through the EEA Agreement. The UK retains an equivalent framework including the presumption, and recognition between the two regimes now runs one way: UK law continues to recognise EU qualified trust service providers, while the EU no longer recognises UK-registered ones. The United States has no equivalent statutory presumption.
This page gives general information about evidence of disclosure during a fundraising process. It is not legal advice. For a specific matter, consult a qualified lawyer in the relevant jurisdiction.