A corporate venture arm, or a larger company in your space, wants to invest. Their diligence team asks for read access to your repository and a walkthrough of your architecture. Should you give it to them? Yes, eventually, but not in the same way you would for a financial investor. A strategic investor may also be a future competitor, a future acquirer, or a future partner, and the people reading your code may sit one desk away from the team building the product that competes with yours.
The short answer: share in stages, share findings before raw code, put the reviewers under a written restriction on who they are and what they can pass back, and let counsel draft the terms. The rest of this post is how I walk founders through it.
Why a strategic investor is different
A financial investor wants to know whether your technology can support the business they are buying a piece of. Their technical diligence is about risk: key-person dependency, security, whether the architecture can scale, whether you own your code. I covered that in what investors actually ask about your architecture.
A strategic investor wants that too. But it has a second reason to look. The corporate parent has its own product roadmap, its own engineers, and its own view of which markets it might enter. Even with good intentions, what its people learn about your data model, your pricing logic, or the trick that makes your product fast can shape decisions inside the parent company. Nobody has to steal anything for that to hurt you. They only have to remember it.
I have seen this play out in a mild form more than once. A founder gives a corporate investor a deep architecture session. The round does not happen. Eighteen months later the parent ships a feature that looks a lot like the founder's core workflow. Was it copied? Usually there is no way to know, and that uncertainty is the point. You want a process where the question never comes up.
What to share, in what order
Think of disclosure as a ladder. Each rung gives the investor more confidence and gives you more exposure. Only climb when the deal has earned it.
Rung one: the written summary
Start with the same material you would put in the technical half of your data room: an architecture overview, the stack, hosting, security posture, team and ownership of the code, major dependencies and licenses. This answers most of what a reviewer needs at the term-sheet stage without exposing anything that is hard to rebuild.
Rung two: a guided session, not a repository
If they want more, run a live walkthrough. Your engineer shares a screen, answers questions, and shows the parts that prove a claim. The reviewer sees the code, but does not take it home. Keep a short written note of what was shown and to whom.
Rung three: an independent reviewer
If the investor needs real repository access before signing, ask that the review be done by an outside firm or an independent technical advisor who reports findings, not code. The parent company gets a report on risk. It does not get your implementation. Many diligence processes already use third-party reviewers, so this is a normal request, not a hostile one. If you have not been through that kind of review before, read the VC sent a technical advisor to diligence you first.
Rung four: direct, limited access
If they still need direct access, make it read-only, time-boxed, logged, and limited to named people. Remove secrets from the repository first, including from history. Revoke access on a fixed date whether or not the deal closes.
The clean team idea
Lawyers have a term for the people allowed to see competitively sensitive information during a deal: a clean team. The concept is simple. A small, named group reviews the sensitive material. Those people are not involved in the parent company's competing product, pricing or strategy work, at least for an agreed period. They share conclusions with the deal team, not the underlying detail.
I am not a lawyer, and this is not legal advice. Clean team terms and antitrust questions vary by jurisdiction and by how close the investor is to being a competitor or acquirer. Have counsel who has done this before draft or review the terms. But you should know to ask for it, because many first-time founders do not know the option exists, and corporate investors rarely volunteer it.
What I tell founders to ask for, in plain language:
- Named reviewers. A list of exactly who will see technical material, with their roles.
- Separation from product teams. None of the reviewers works on a product that competes with yours.
- Findings, not copies. Reviewers report risk conclusions to the deal team. No code, schema or internal documents are forwarded.
- Return or destruction. All copies are deleted if the deal does not close, with written confirmation.
- An NDA that names the technical material specifically. A generic NDA written for financial documents may not cover a code walkthrough well.
What to hold back entirely
Some things do not need to be shown to anyone before close, strategic or not:
- Customer data. Never. Use synthetic or anonymized samples if a reviewer needs to see data shapes. The same principle applies to what you give diligence in production.
- The secret sauce, line by line. If your advantage is a specific algorithm, pricing model, or data pipeline, describe what it does and show that it works. Showing how it works can wait.
- Unreleased roadmap detail. Share direction, not specs, for features that would matter to the parent's own product team.
A reasonable investor will accept this. If a strategic insists on full, unrestricted access to everything before a term sheet, treat that as information about how the relationship will go.
Signs the request has gone too far
Most corporate investors behave well. These are the patterns that make me slow down:
- The reviewers turn out to be product managers or engineers from the parent's competing team.
- They want access before there is a term sheet, or with no clear timeline.
- Questions drift from "does this work and is it safe" to "how exactly did you build this part."
- They resist a clean team or a findings-only review without a good reason.
- They ask for exclusivity while the review runs, which gives them time and information without commitment.
None of these is automatically disqualifying. Each is a moment to pause and ask why.
How this connects to the rest of diligence
Done well, staged disclosure does not slow the deal much. A clean summary plus a guided session answers most technical questions in a week or two. It is the unprepared founder who loses time, because they end up assembling documents under pressure and over-sharing to compensate. If you want to know how long each stage should take, I wrote up how long technical diligence takes and why it stalls.
The work you do here also helps if the strategic later wants to acquire you. Buyers go deeper than investors, as covered in an acquirer's technical diligence is not your investor's, and a founder who already has a disciplined disclosure process is in a much stronger position.
FAQ
Is it normal to refuse repository access to an investor?
Refusing outright is unusual. Staging it is normal. Offer a written summary and a guided session first, then an independent reviewer if they need more. Most investors will accept that sequence.
Does an NDA protect my code from a corporate investor?
It helps, but an NDA alone does not stop people from remembering what they saw. That is why limiting who sees it, and having reviewers report findings rather than forward material, matters more than the NDA wording.
Should I hire someone to run this process?
If you do not have a senior technical person who has been through diligence, it is worth having one in the room. A one-time technical teardown before the raise tells you what a reviewer will find, so you can decide what to show and in what order.
What if the strategic investor is also a likely acquirer?
Be more careful, not less. Information shared during an investment stays with them if they later bid for you. Ask counsel about clean team terms early.
If a corporate investor is asking for code access now and you want a second opinion on what to share, book a call and we can walk through it.