Reference

VDR & M&A Glossary

84+ terms defined across 8 categories. The most comprehensive free glossary of virtual data room, M&A, due diligence, fundraising, security, and legal technology terms.

Data Room & VDR Fundamentals

Core terminology for virtual data rooms, data room management, and document sharing platforms.

Virtual Data Room (VDR)

A secure, cloud-based repository for sharing sensitive documents during business transactions.

A Virtual Data Room (VDR) is an online secure repository used to store and share confidential business documents during high-stakes transactions such as mergers and acquisitions, capital raises, IPOs, and legal due diligence. Unlike email or shared drives, a VDR provides granular access controls, tamper-evident audit logs, dynamic watermarking, and structured Q&A workflows — giving the document owner full visibility and control over who sees what. Modern VDRs like SpaceNexus also include AI capabilities (automatic redaction, document categorization, OCR full-text search) that dramatically reduce the time required to prepare and manage a data room.

Physical Data Room

A secure physical location where printed deal documents are reviewed by authorized parties under supervision.

A physical data room is a secure physical location — typically a law firm office or bank vault — where printed copies of deal documents are stored, indexed, and made available for authorized reviewers under supervision. Reviewers attend in person during business hours, and access is logged in a paper register. Physical data rooms were the standard for M&A due diligence from the 1970s through the early 2000s, but have been largely replaced by virtual data rooms due to lower cost, faster setup, broader accessibility, and superior audit trails.

Data Room Index

A master list of every document in the data room, organized by category, with one-line descriptions.

A data room index is a comprehensive list of all documents in a virtual data room, organized by category (Corporate, Financial, Commercial, etc.) with one-line descriptions. The index is the navigation layer that helps reviewers find what they need without asking the seller. Modern VDRs generate the index automatically using AI auto-indexing, which categorizes documents based on filename and content.

Data Room Setup

The process of creating a new data room, configuring folder structure, and preparing for launch.

Data room setup is the process of creating a new virtual data room, configuring the folder structure, uploading initial documents, setting up permission tiers, configuring NDA workflows, and testing the platform before launch. Best practice is to set up the data room 2-3 weeks before the formal process launch, with 80%+ of documents already uploaded.

Permission Tiers

Levels of access granted to different user groups, controlling who sees what documents.

Permission tiers are levels of document access granted to different user groups. In a sell-side M&A process, common tiers include: Initial Bidders (see teaser and CIM only), Shortlisted Bidders (see full data room), Final Round Bidders (see confidential materials), Counsel (see legal documents only), and Advisors (see specific workstreams). Tiered access controls information disclosure and maintains competitive tension in the auction.

NDA Click-Through

An online workflow that requires users to accept an NDA before accessing the data room.

An NDA click-through is an online workflow where users must read and electronically accept a non-disclosure agreement before being granted access to the data room. The workflow records the acceptance with timestamp and IP address, providing legal evidence that the user agreed to the NDA terms. NDA click-through eliminates the need for paper NDAs and accelerates data room launch.

Bulk Upload

The process of uploading many documents to a data room at once, often via drag-and-drop.

Bulk upload is the process of uploading hundreds or thousands of documents to a virtual data room simultaneously, typically via drag-and-drop or folder upload. Modern VDRs support bulk upload with AI auto-indexing that categorizes documents into the right folders based on filename and content, saving hours or days of manual organization work.

AI Auto-Indexing

Automatic categorization of uploaded documents into the correct folder using AI/ML.

AI auto-indexing uses machine learning to automatically categorize documents uploaded to a VDR into the correct folder based on filename, content, and document type. For example, the AI can recognize that a PDF named 'Acme_2024_10K.pdf' is a financial document and route it to the Financial folder. Auto-indexing dramatically reduces the time required to organize large data rooms, from days to hours.

Data Room Retention

How long the data room and its contents are kept accessible after the deal closes.

Data room retention refers to how long the data room and its contents remain accessible after a deal closes or is terminated. Retention can be configured for weeks, months, years, or indefinitely. SEC Rule 17a-4 requires broker-dealers to retain records for 6 years, HIPAA requires 6 years, and some financial regulations require 7+ years. VDRs typically support configurable retention policies with cryptographic deletion verification when retention periods expire.

Data Room Archival

The process of preserving the data room and its audit trail as a permanent record after the deal closes.

Data room archival is the process of preserving the complete data room — including all documents, audit trails, Q&A logs, and access records — as a permanent record after the deal closes. The archived data room is used for post-close reference, regulatory inquiries, and any subsequent disputes. VDRs typically support archival with cryptographic integrity verification.

Folder Structure

The hierarchical organization of documents within a data room, typically by workstream.

A data room folder structure is the hierarchical organization of documents within a VDR, typically organized by workstream (Corporate, Financial, Commercial, Technology, HR, Legal, etc.). Best practice is to use a standardized 8-folder structure that mirrors standard due diligence checklists, allowing buyers to find what they need without asking. The structure is typically numbered (01., 02., etc.) to preserve order.

Deal Room

A virtual data room configured for a specific M&A or fundraising transaction.

A deal room is a virtual data room configured for a specific transaction — typically a named instance with the deal name, custom branding, and deal-specific permission groups and workflows. Multiple deal rooms may exist for the same company (one per transaction) and are managed separately.

M&A Process

Terminology for mergers, acquisitions, and corporate transaction processes.

Sell-Side

Representing the seller or target company in an M&A transaction.

Sell-side refers to advisory work representing the company being sold or its shareholders. Sell-side advisors run the auction process, prepare marketing materials, manage the data room, identify and qualify buyers, run management presentations, coordinate diligence, negotiate the purchase agreement, and shepherd the deal to closing. Sell-side mandates are typically paid via a success fee based on transaction value.

Buy-Side

Representing the acquirer or buyer in an M&A transaction.

Buy-side refers to advisory work representing the acquirer or buyer. Buy-side advisors identify and evaluate acquisition targets, conduct commercial and financial diligence, coordinate with co-advisors and external counsel, prepare investment committee memos, and negotiate the purchase agreement from the buyer perspective. Buy-side mandates are typically paid via a success fee based on transaction value, with potential retainer and expense reimbursement.

Confidential Information Memorandum (CIM)

A comprehensive marketing document used to sell a company, typically 30-50 pages.

A Confidential Information Memorandum (CIM) is the primary marketing document used in a sell-side M&A process. The CIM provides a comprehensive overview of the target company: business overview, market opportunity, products and services, financial performance, growth strategy, and management team. The CIM is distributed to NDAed buyers and serves as the basis for buyer evaluation. CIMs are typically 30-50 pages with significant financial detail.

Management Presentation

The slide deck used in management meetings with potential buyers, typically 30-50 slides.

A management presentation is the slide deck used during in-person or video management meetings between the seller's leadership team and potential buyers. The management presentation provides a higher-level overview than the CIM, with more emphasis on the management team, growth strategy, and the opportunity to invest. Management presentations are typically 30-50 slides and form the basis for the buyer evaluation.

Letter of Intent (LOI)

A non-binding document outlining the key terms of a proposed transaction.

A Letter of Intent (LOI) is a non-binding document that outlines the key terms of a proposed transaction: purchase price, transaction structure, key conditions, exclusivity period, and timeline. The LOI signals serious buyer interest and serves as the basis for detailed definitive agreement negotiation. LOIs typically include binding provisions (exclusivity, confidentiality) and non-binding provisions (price, structure).

Definitive Agreement (DA)

The final, binding contract for an M&A transaction.

The definitive agreement (DA) is the final, binding contract for an M&A transaction, also called the purchase agreement or merger agreement. The DA specifies all transaction terms: purchase price, payment structure, representations and warranties, covenants, indemnification, closing conditions, and termination provisions. The DA is the legally binding document that supersedes the LOI and any prior term sheets.

Merger vs. Acquisition

A merger combines two entities; an acquisition has one entity acquiring another.

A merger is the legal combination of two companies into a single entity, with one company surviving and the other absorbed. An acquisition (or takeover) is the purchase of one company (the target) by another (the acquirer), with the target becoming a subsidiary or being absorbed. The legal structure has implications for tax treatment, shareholder rights, regulatory approval, and post-close integration.

Teaser

A 1-2 page anonymous summary of a deal opportunity, used in the initial buyer outreach.

A teaser is a 1-2 page anonymous summary of a deal opportunity, used in the initial buyer outreach before NDA execution. The teaser provides just enough information to generate buyer interest (industry, size, growth rate, key highlights) without revealing the company's identity. Interested buyers sign an NDA before receiving the CIM.

Process Letter

A document outlining the timeline, key dates, and requirements for participating in a sell-side process.

A process letter (or bid letter) is a document sent to potential buyers outlining the timeline, key dates, and requirements for participating in a sell-side process. The process letter specifies bid submission deadlines, management presentation dates, site visit schedules, and the format for initial bids (LOI, indicative offer, etc.).

First Round Bid (Round 1)

The initial round of bids in a multi-round sell-side auction process.

The first round bid is the initial round of bids in a multi-round sell-side auction process. First round bidders typically submit a non-binding indication of interest (IOI) or non-binding LOI based on the CIM, management presentation, and limited data room access. The seller uses first round bids to narrow the field to 3-5 finalists for the second round.

Second Round Bid (Round 2)

The detailed diligence and refined bid round in a multi-round auction process.

The second round bid is the detailed diligence and refined bid round in a multi-round sell-side auction process. Second round bidders have full data room access, conduct site visits and management interviews, and submit refined bids (often with markup of the draft purchase agreement). The seller uses second round bids to identify the winning bidder and enter exclusive negotiations.

Exclusivity / No-Shop

A period during which the seller agrees not to solicit other offers for the company.

Exclusivity (or a no-shop provision) is a period during which the seller agrees not to solicit or accept other offers for the company, typically 30-60 days. Exclusivity is usually granted to the winning bidder after the LOI is signed, in exchange for the buyer committing to definitive agreement negotiation on the agreed terms. If the deal falls through during exclusivity, the seller can resume the broader process.

Indication of Interest (IOI)

A non-binding preliminary bid submitted in the first round of a sell-side process.

An Indication of Interest (IOI) is a non-binding preliminary bid submitted by a buyer in the first round of a sell-side process. The IOI typically specifies the proposed purchase price range, transaction structure, key conditions, and required financing. The IOI is used by the seller to narrow the field of bidders before the second round.

Stalking Horse Bid

An initial bid in a bankruptcy or distressed sale that sets the floor for an auction.

A stalking horse bid is an initial bid in a bankruptcy or distressed sale (such as a 363 sale) that sets the floor for the subsequent auction. The stalking horse bidder is typically compensated with break-up fees and expense reimbursement if outbid. The stalking horse bid provides certainty of value and terms for the seller, while establishing minimum acceptable terms for competing bids.

Due Diligence

Terminology for the investigation and verification process in M&A, fundraising, and other transactions.

Due Diligence

The investigation and verification process before a transaction, to confirm facts and assess risks.

Due diligence is the investigation and verification process conducted before a transaction — M&A, fundraising, investment, or lending — to confirm the facts presented by the target, assess risks, and inform the transaction terms. Due diligence covers financial, commercial, legal, HR, technology, IP, and operational areas, and can take 4-12 weeks for a typical mid-market deal.

Financial Due Diligence (FDD)

The review of historical financials, projections, and quality of earnings.

Financial due diligence (FDD) is the review of the target's historical financial statements, management accounts, projections, working capital, and quality of earnings. FDD is typically performed by an accounting firm and focuses on identifying accounting issues, one-time or non-recurring items, and the sustainability of projected revenue and EBITDA. FDD findings often drive purchase price adjustments and indemnification provisions.

Quality of Earnings (QoE)

An analysis that adjusts reported EBITDA for non-recurring, non-cash, and non-operational items.

Quality of Earnings (QoE) is a financial analysis that adjusts reported EBITDA for non-recurring, non-cash, and non-operational items to determine the sustainable run-rate earnings of a business. QoE adjustments may include: adding back one-time legal expenses, removing non-recurring revenue, normalizing working capital, and adjusting for owner's compensation. QoE is a critical input to purchase price negotiations.

Commercial Due Diligence (CDD)

The review of market, customers, competition, and growth potential.

Commercial due diligence (CDD) is the review of the target's market position, customer base, competitive landscape, and growth potential. CDD typically includes market sizing, customer references, win/loss analysis, and competitive positioning. CDD is often performed by a strategy consulting firm and provides an independent view of the target's commercial prospects.

Confirmatory Diligence

The final, detailed due diligence conducted in the second round of a process.

Confirmatory diligence is the final, detailed due diligence conducted in the second round of a sell-side process, after the buyer has had full data room access and management presentations. Confirmatory diligence verifies the buyer's investment thesis and identifies any last issues before definitive agreement signing.

Red Flag

A material issue that may cause a buyer to walk away or reprice the deal.

A red flag in due diligence is a material issue that may cause a buyer to walk away from a deal or significantly reprice it. Common red flags include: undisclosed litigation, customer concentration, regulatory issues, key person dependencies, and material weaknesses in financial controls. Red flags should be disclosed proactively by the seller to avoid late-stage deal failure.

Data Room Diligence

The process of reviewing documents in a virtual data room during due diligence.

Data room diligence is the process of reviewing documents in a virtual data room during the due diligence phase of a transaction. Diligence teams use the VDR to access financial statements, contracts, IP documentation, customer evidence, and other materials needed to evaluate the target. Efficient data room diligence requires strategic triage, structured Q&A, and prioritization of material issues.

Due Diligence Checklist

A structured list of documents and information requested during due diligence.

A due diligence checklist is a structured list of documents and information requested during the due diligence process, organized by workstream (financial, commercial, legal, HR, technology, etc.). The checklist ensures that all material areas are covered and helps both sides track the status of document requests. Standard checklists have 100-200+ items depending on deal size and complexity.

Security & Privacy

Information security and data privacy terminology relevant to VDRs and confidential transactions.

Encryption at Rest

Data is encrypted when stored on disk, requiring a key to decrypt.

Encryption at rest protects data by encrypting it when stored on disk, so that even if the physical storage is compromised, the data remains unreadable without the encryption key. AES-256 is the industry standard for encryption at rest, used by governments and financial institutions for classified data.

Encryption in Transit (TLS 1.3)

Data is encrypted while being transmitted over networks, preventing interception.

Encryption in transit protects data while it is being transmitted over networks, using TLS (Transport Layer Security) protocol. TLS 1.3 is the latest version and is the industry standard for protecting web traffic, API calls, and file transfers. Combined with encryption at rest, encryption in transit provides end-to-end data protection.

Multi-Factor Authentication (MFA)

Authentication requiring two or more verification factors to log in.

Multi-factor authentication (MFA) requires users to provide two or more verification factors to log in: something they know (password), something they have (security key or phone), and/or something they are (biometric). Phishing-resistant MFA using FIDO2 hardware keys is the gold standard for VDR security.

Single Sign-On (SSO)

Authentication that lets users log in once and access multiple applications.

Single Sign-On (SSO) lets users log in once with their corporate identity and access multiple applications without re-authenticating. VDRs support SSO via SAML 2.0 or OpenID Connect with major identity providers (Okta, Azure AD, Google Workspace). SSO improves security by centralizing authentication and enables SCIM provisioning for automated user lifecycle management.

IP Whitelisting

Access restricted to specific IP addresses or ranges.

IP whitelisting restricts VDR access to specific IP addresses or CIDR ranges (e.g., the buyer's office network, VPN). Combined with strong authentication, IP whitelisting provides an additional layer of security for highly sensitive transactions, ensuring that even compromised credentials cannot be used from unauthorized networks.

FIPS 140-2/140-3

US government standard for cryptographic modules.

FIPS 140-2 (and the newer FIPS 140-3) is the US government standard for cryptographic modules, specifying security requirements for the design and implementation of cryptographic modules. FIPS 140-2/140-3 validation is required for cryptographic modules used in US government systems and is often required for healthcare, financial services, and defense VDR deployments.

Breach Notification

Required notification to authorities and affected parties of a data breach.

Breach notification is the legally required notification to regulatory authorities and affected individuals of a data breach. GDPR requires notification within 72 hours. SEC cyber disclosure rules require 8-K disclosure within 4 business days for material incidents. HIPAA requires notification to affected individuals, HHS, and (for breaches affecting 500+ individuals) media.

Phishing-Resistant MFA

MFA that cannot be bypassed by phishing attacks, typically using FIDO2 keys.

Phishing-resistant MFA is multi-factor authentication that cannot be bypassed by phishing attacks. The gold standard is FIDO2/WebAuthn using hardware security keys (YubiKey, Titan) or platform authenticators (Windows Hello, Touch ID). Unlike SMS or TOTP codes, FIDO2 keys cryptographically bind the authentication to the legitimate website, preventing phishing.

Customer-Managed Encryption Keys (CMEK)

Encryption keys controlled by the customer, not the service provider.

Customer-managed encryption keys (CMEK) are encryption keys controlled by the customer, not the service provider. With CMEK, the service provider cannot decrypt customer data without the customer's key, providing an additional layer of security for highly sensitive transactions. CMEK is often required for zero-trust architectures and for customers in regulated industries.

Zero Trust Architecture

A security model that requires continuous verification of every user and device.

Zero trust is a security model that requires continuous verification of every user, device, and transaction — not just verification at login. Zero trust principles include: least-privilege access, continuous authentication, microsegmentation, and assume-breach posture. For VDRs, zero trust means: phishing-resistant MFA, IP whitelisting, device binding, customer-managed keys, and continuous anomaly detection.

Document Management

Terminology for document handling, redaction, watermarking, and version control in VDRs.

Dynamic Watermarking

A watermark that displays viewer-specific information on every page.

Dynamic watermarking renders a visible overlay on every page of every document viewed or downloaded in the VDR, with viewer-specific information: name, email, IP address, timestamp. Dynamic watermarks are a powerful forensic deterrent — if a document leaks, the watermark identifies exactly which user leaked it. The watermark is rendered server-side and cannot be removed by the viewer.

Redaction

Permanent removal or obscuring of sensitive content from a document.

Redaction is the permanent removal or obscuring of sensitive content from a document before sharing. In M&A, redaction is used to protect commercially sensitive information (customer names, pricing, financials) when sharing with bidders who should not see the full document. VDRs support both manual and AI-powered redaction with irreversible removal of redacted content.

AI Redaction

Automatic detection and redaction of sensitive information using AI/ML.

AI redaction uses machine learning to automatically detect and redact sensitive information in documents: PII (personally identifiable information), PHI (protected health information), trade secrets, and confidential business information. AI redaction dramatically reduces the time required to prepare documents for sharing in a data room, from days to hours.

View-Only Mode (Screen Shield)

Documents rendered as images that cannot be downloaded, printed, or screenshotted.

View-only mode (also called screen shield) is a document protection mode that renders documents as images in the browser, preventing download, printing, copy/paste, and screen capture attempts. View-only mode is used for the most sensitive materials — pre-release financials, M&A targets, pre-IPO information — where the document owner wants to ensure the recipient can view but not extract the content.

Screenshot Prevention

Browser-based protection that blocks common screenshot and screen recording tools.

Screenshot prevention uses browser-based protections to block common screenshot and screen recording tools (Snipping Tool, Snagit, OBS, etc.) when view-only mode is enabled. The protection renders documents with overlays that make screenshots show as black or blurred. While no client-side protection is 100% effective, screenshot prevention deters the vast majority of casual and opportunistic leakage.

Version Control

Tracking changes to documents over time, with the ability to compare and restore versions.

Version control is the tracking of changes to documents over time, with the ability to view, compare, and restore previous versions. In M&A data rooms, version control ensures that buyers always see the current version of each document, with full version history preserved for audit purposes. Modern VDRs use built-in version control rather than filename conventions (v1, v2, FINAL_v2).

Bates Numbering

Sequential numbering applied to documents for identification and tracking.

Bates numbering is the sequential numbering of documents (often applied as a stamp on each page) for unique identification and tracking. Bates numbering is used in litigation discovery and in some M&A processes where documents need to be referenced precisely. VDRs support automatic Bates numbering with configurable prefix, start number, and format.

Fundraising & Investment

Terminology for venture capital, private equity, and investment fund operations.

Series A

The first significant round of venture capital funding for a startup.

Series A is the first significant round of venture capital funding for a startup, typically $2-15M, used to scale the business after product-market fit. Series A investors typically receive preferred stock with liquidation preferences, anti-dilution provisions, and board seats. Series A marks the transition from seed-stage to growth-stage.

SAFE (Simple Agreement for Future Equity)

An agreement giving the right to future equity in exchange for investment.

A SAFE (Simple Agreement for Future Equity) is an investment instrument that gives the investor the right to receive equity in a future priced round, in exchange for the investment today. SAFEs are commonly used in seed and pre-seed rounds because they are simpler and cheaper than priced rounds. SAFEs typically have a valuation cap, discount rate, and (sometimes) MFN provision.

Convertible Note

A loan that converts to equity at a future priced round.

A convertible note is a loan made to a startup that converts into equity at a future priced round, typically with a discount rate and valuation cap. Unlike SAFEs, convertible notes accrue interest and have a maturity date. Convertible notes were the dominant pre-seed/seed instrument before SAFEs became popular in recent years.

Private Placement Memorandum (PPM)

A legal document providing detailed information about a private securities offering.

A Private Placement Memorandum (PPM) is a legal document provided to prospective investors in a private securities offering. The PPM contains detailed information about the offering, the issuer, the risks, and the terms — required under securities laws for private placements under Regulation D and other exemptions.

Limited Partnership Agreement (LPA)

The legal agreement that governs a private equity or venture capital fund.

A Limited Partnership Agreement (LPA) is the legal document that governs a private equity or venture capital fund. The LPA defines the fund's terms: management fee, carried interest, investment period, fund life, key person provisions, LP rights, and GP obligations. The LPA is negotiated between the GP (general partner) and the fund's LPs (limited partners).

Side Letter

An agreement between an LP and GP that modifies fund terms for that specific LP.

A side letter is an agreement between a specific limited partner and the fund's general partner that modifies the fund's standard terms for that LP. Side letters typically include fee discounts, MFN (most favored nation) clauses, co-investment rights, and GP commitments. Side letters are individually negotiated and confidential.

Most Favored Nation (MFN)

A provision guaranteeing an LP the best terms given to any other LP.

A Most Favored Nation (MFN) clause in a side letter guarantees an LP that they will receive the best economic terms given to any other LP in the fund. MFN typically applies to fee discounts, carried interest rates, and co-investment rights. MFN creates pressure on the GP to give similar terms to all LPs to avoid future MFN claims.

Capital Call

A notice to LPs requiring them to fund a portion of their committed capital.

A capital call is a notice from the fund's general partner to the limited partners requiring them to fund a portion of their committed capital within a specified period (typically 10-15 business days). PE and VC funds typically call capital in tranches as investment opportunities are identified, rather than calling the full commitment upfront.

Carried Interest (Carry)

The GP's share of fund profits, typically 20% above an LP hurdle.

Carried interest (or carry) is the general partner's share of the fund's profits, typically 20% above a preferred return (hurdle) to LPs. Carry aligns GP incentives with LP returns — the GP earns carry only if LPs earn their preferred return first. Carry is the primary economic incentive for fund managers.

Limited Partner (LP)

An investor in a private equity or venture capital fund.

A limited partner (LP) is an investor in a private equity or venture capital fund. LPs commit capital to the fund and receive distributions of investment proceeds, but have limited involvement in investment decisions. Typical LPs include pension funds, endowments, foundations, family offices, insurance companies, and high-net-worth individuals.

Financial & Deal Terms

Financial terminology commonly used in M&A, valuation, and deal structuring.

EBITDA

Earnings Before Interest, Taxes, Depreciation, and Amortization.

EBITDA (Earnings Before Interest, Taxes, Depreciation, and Amortization) is a measure of operating profitability that excludes non-operating expenses and non-cash charges. EBITDA is commonly used in M&A valuation, with deal multiples typically expressed as EV/EBITDA ratios. EBITDA is a non-GAAP measure, and buyers typically perform quality of earnings analysis to verify reported EBITDA.

EV/EBITDA Multiple

Enterprise value divided by EBITDA, a common valuation metric.

The EV/EBITDA multiple is a valuation metric that compares enterprise value (total value of the business) to EBITDA. For example, a business sold for $100M with $10M EBITDA has a 10x EV/EBITDA multiple. Multiples vary significantly by industry, growth rate, and market conditions — software companies often trade at 15-30x EBITDA, while industrial companies may trade at 5-8x EBITDA.

Earnout

A contingent payment to the seller based on post-close performance.

An earnout is a contingent payment to the seller based on the post-close performance of the business, typically tied to revenue, EBITDA, or other metrics. Earnouts bridge valuation gaps between buyer and seller by tying part of the purchase price to future performance. Earnouts typically last 2-3 years and may be subject to caps, floors, and dispute resolution mechanisms.

Escrow (Holdback)

A portion of the purchase price held by a third party to secure indemnification obligations.

An escrow (or holdback) is a portion of the purchase price held by a third-party escrow agent to secure the seller's indemnification obligations for breaches of representations and warranties. The escrow amount is typically 5-15% of the purchase price and is released to the seller over 12-24 months, less any indemnification claims. Escrow may be replaced or supplemented by RWI insurance.

Internal Rate of Return (IRR)

The annualized return on an investment accounting for timing of cash flows.

The Internal Rate of Return (IRR) is the annualized rate of return on an investment that makes the net present value of all cash flows equal to zero. IRR accounts for the timing of cash flows, making it a more accurate measure of return than simple return multiples. PE and VC funds typically target IRRs of 20%+ over the fund life.

Total Value to Paid-In Capital (TVPI)

The total value of distributions plus remaining portfolio value divided by paid-in capital.

Total Value to Paid-In Capital (TVPI) is the total value of all distributions plus the remaining portfolio value, divided by total paid-in capital. TVPI measures the total return on a fund investment, including both realized and unrealized gains. A TVPI of 2.0x means investors have doubled their money (or have portfolio value expected to double it).

Distributions to Paid-In Capital (DPI)

The ratio of cash distributions to paid-in capital, measuring realized returns.

Distributions to Paid-In Capital (DPI) is the ratio of cash distributions returned to investors divided by total paid-in capital. DPI measures realized returns only — it does not include remaining portfolio value. A DPI of 0.5x means investors have received 50% of their capital back in cash distributions. DPI is the most conservative measure of fund performance.

Multiple on Invested Capital (MOIC)

The total value of an investment divided by the amount invested.

Multiple on Invested Capital (MOIC) is the total value of an investment (distributions plus remaining value) divided by the amount invested. A MOIC of 3.0x means the investment is worth three times the original investment. MOIC is a simple multiple that does not account for the time period of the investment — a 3.0x MOIC over 5 years is very different from a 3.0x MOIC over 10 years.

Frequently asked questions

What is the most comprehensive VDR glossary?

The SpaceNexus glossary at /glossary is the most comprehensive free VDR and M&A glossary, with 100+ terms across 8 categories: Data Room & VDR Fundamentals, M&A Process, Due Diligence, Legal & Compliance, Security & Privacy, Document Management, Fundraising & Investment, and Financial & Deal Terms.

How is a VDR different from cloud storage?

A VDR (virtual data room) is purpose-built for controlled, auditable, secure information exchange during high-stakes transactions. Cloud storage (Dropbox, Google Drive) is built for general collaboration. VDRs provide granular permissions, dynamic watermarking, structured Q&A, immutable audit trails, ethical wall enforcement, and regulatory certifications (SOC 2, ISO 27001, GDPR, HIPAA) that consumer cloud storage does not.

What is the difference between buy-side and sell-side?

Sell-side advisory work represents the company being sold (or its shareholders) in an M&A transaction — running the auction, managing the data room, identifying buyers. Buy-side advisory work represents the acquirer — identifying targets, conducting diligence, negotiating the purchase agreement. The same advisor can represent both sides in different transactions, but cannot represent both sides of the same transaction due to ethical wall requirements.

What is quality of earnings?

Quality of Earnings (QoE) is a financial analysis that adjusts reported EBITDA for non-recurring, non-cash, and non-operational items to determine sustainable run-rate earnings. QoE is critical in M&A because reported EBITDA often includes items that won't continue post-close. QoE findings often drive purchase price adjustments and indemnification provisions.

What is the most important VDR security certification?

SOC 2 Type II is the most important VDR security certification for enterprise customers. It's an independent audit of security controls over a 6-12 month period, evaluating controls across five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy). ISO 27001 is the international equivalent and is often required by European and APAC customers. HIPAA BAA is required for healthcare transactions.