A contract in which each side promises to keep what it learns confidential and to use it only to assess the deal. It is normally the first document signed, because nothing useful about a company can be shared before it exists.
Why it matters
An NDA exists because a company for sale has to describe itself before anyone will pay for it,
and describing itself honestly means naming customers, revealing margins, and showing the things
that would hurt it if a competitor, employee, or the wider market saw them. None of that can be
shared safely without a promise attached to it, so the NDA is normally the very first document
either side signs — often before a name is even used.
For a founder, the NDA is the thing that lets you stop hiding behind a teaser
and start having a real conversation. For a buyer, signing one is usually a small cost for access
to the one thing that actually lets them decide whether to spend real money on the deal. Both
sides treat it as a formality, and both are half right: it is quick to sign, but what it actually
covers is worth reading carefully, because the document itself is doing very little once trust
between the two sides has broken down.
In AI companies the stakes are a step higher than usual. Model architecture, training data
sources, prompt libraries and evaluation results are the kind of detail that is cheap to describe
and expensive to give away, and a buyer that walks away from the deal still has all of it in their
heads. An NDA cannot erase what someone has learned — it can only make using it against you
something they agreed not to do.
How it works
Most NDAs used in a deal are mutual: both sides may share sensitive information, and both
sides are bound to protect what they receive. A one-way NDA appears when only one party is
disclosing anything of substance, which is rarer than people assume — even a buyer's identity and
strategy is confidential information the seller is trusted with.
The core promise has three parts. Information covered by the agreement must be kept
confidential, used only to evaluate the deal, and not shared beyond a defined, usually
named, group of people. A well-drafted NDA also says for how long the promise lasts — sensitive
detail does not stop being sensitive the day talks end — and what happens to copies and notes if
the deal falls through: returned, destroyed, or simply left to expire under the confidentiality
clause.
Two carve-outs appear in nearly every version. Information that was already public, or that
the receiving party can show it already knew, is not covered — an NDA cannot make public
information secret again. And a party may usually disclose what it is legally compelled to
disclose, such as under a court order, typically after telling the other side first so they have a
chance to object.
A short non-solicitation clause is common too: a promise not to use the process as a way to
poach staff or customers under cover of due diligence. It is worth reading for, because it is easy
to skim past and expensive to violate.
What to watch for
Confidentiality does not equal non-use. A well-drafted NDA restricts not just who can see the
information, but what it can be used for. Without a clean "use restriction" clause, a competitor
that walks away from a deal has still learned your pricing, your churn, and your product roadmap
— legally, so long as they never repeat it aloud.
Read the term, not just the promise. An NDA that expires in a year sounds fine until you
remember that a customer list or a pricing strategy can still be damaging in year two. Match the
duration to how long the information actually stays sensitive, not to how long the deal is
expected to take.
"Residual knowledge" clauses are the quiet danger. Some NDAs, usually pushed by larger
acquirers, include language letting the recipient use anything retained in an employee's
unaided memory. That sounds harmless until the buyer's product team "happens to" build something
that looks a lot like what they saw in your data room.
An NDA does not stop a bad-faith buyer from walking away with knowledge. It gives you a legal
claim if they misuse it, not a guarantee they never see it. The real protection is releasing
information in stages — a teaser, then a CIM once an NDA is
signed, then full detail in the data room only once real intent is shown —
so the most sensitive material only goes to buyers who have already proven they are serious.
Get it signed by the entity, not the individual. A buyer may be a fund, a corporate, or an
individual acting for a company that does not yet exist on paper. Whoever signs should have the
authority to bind the party that will actually receive your information.
On GetDeal
Every confidential listing on GetDeal is gated behind exactly this promise: until an NDA is
signed, a buyer sees only industry, country and size — the company name, website and documents
stay hidden. Signing happens through built-in e-signature, and it is the event that unlocks the
next stage of the deal room rather than a side document exchanged by email and easily lost track
of.
Because the NDA gate sits in front of the data room rather than replacing
it, a founder is never asked to hand over sensitive documents on trust alone — the confidentiality
promise and the controlled access it protects are two separate, enforced steps, both visible on
the shared stage tracker.
Raise or sell your AI startupthe Playbook — the deal stages, what each one unlocks, and which agreement is signed when
Questions people ask
- When should an NDA be signed in a sale process?
- Before any identifying detail is shared, and usually before a buyer sees more than an anonymous summary. Most processes send a short teaser first, then ask for a signed NDA before releasing the fuller memorandum, so nothing sensitive is exposed to someone who has not yet made a real commitment to look properly.
- Does an NDA stop a buyer from using what they learned?
- A well-drafted one restricts use as well as disclosure, meaning the buyer cannot act on the information beyond evaluating the deal, not just refrain from repeating it publicly. A weaker NDA that only covers secrecy leaves a buyer free to use what they learned so long as they never reveal the source.
- Is an NDA the same for every buyer in a process?
- Usually yes, in substance, because a seller wants every party assessed on the same terms and does not want to negotiate confidentiality language with each one separately. Minor changes are sometimes accepted for a larger institutional buyer with its own standard wording, but the core promises rarely move.
- What happens to the information if the deal does not close?
- The NDA should say. Most require the receiving party to return or destroy copies of confidential material, while the underlying confidentiality obligation continues to apply for a defined period afterwards, since the sensitivity of what was shared does not disappear just because talks ended.
See also
More in Deal process
- CIM — The full written case for buying a company — what it does, how it makes money, its customers, its financials and its risks.
- Closing — The moment ownership actually changes hands and the money moves.
- Data room — The controlled place where a seller puts the documents a buyer needs — contracts, accounts, cap table, IP assignments.
- Disclosure schedule — The seller’s list of exceptions to the promises made in the contract.
- Due diligence — The buyer checking that the company is what it was said to be — financial, legal, technical, commercial.
Keep reading
- How to sell an AI startup
- AI-powered due diligence for startup investing
- Frequently asked questions about GetDeal
Updated 2026-09-09