data.day

The Fix: The Red Pen Checklist for PII, Pricing, and Personnel

Redaction is not cosmetic; it is boundary-setting. Here is the practical checklist of what must be masked, what can be summarized, and what should never enter the room.

Redaction is Boundary Setting

There is a misconception that a Data Room is a confessional. It is not. It is a museum exhibit. You determine what is on display, how it is lit, and how close the visitors can get to the art.

When you fail to redact, you are not being “open.” You are failing to set boundaries. You are telling the buyer that you do not distinguish between public information and trade secrets.

The Amateur Move: The “Open Book” Policy

I often see founders upload their entire QuickBooks backup file. They think this saves time.

“Here is the financial history,” they say.

This file contains:

  • Every vendor you have ever paid.
  • The exact dates you were late on rent.
  • Notes in the memo fields that say things like “Bonus for cleaning up the mess.”

This is not data; this is dirt. By giving them the raw database, you allow them to run their own queries. They will find patterns you didn’t even know existed. You have lost control of the narrative.

The Defense: The Red Pen Checklist

We must sanitize the room. This does not mean lying; it means layering. We release information in tiers. Tier 1 is safe. Tier 2 is sensitive. Tier 3 is radioactive and stays in the vault until the wire hits.

Here is your mandatory checklist before opening the gates.

1. Personnel (The Human Liability)

People are your biggest asset and your biggest privacy risk.

  • Home Addresses/SSNs: ALWAYS Redact. There is no diligence reason for a buyer to have this.
  • Salaries: Aggregate or Anonymize in early stages. Use “Role/Level” instead of names.
  • Harassment Complaints: Segregate. These do not go in the general HR folder. They go in a restricted “Disclosure Schedule” folder, accessible only to legal counsel.

2. Pricing & Customers (The Secret Sauce)

  • Customer Names: Code them (Client A, B, C) until late-stage diligence. If the deal leaks, you don’t want your competitors calling your client list.
  • Granular Margins: Summarize. Show blended margins by cohort. Do not show the exact profit on a specific contract if it reveals your proprietary pricing algorithm.
  • Unsigned Contracts: Remove. If it isn’t signed, it isn’t revenue. It’s a wish. Move it to a “Pipeline” document, clearly labeled as forecast, not actuals.

3. Intellectual Property (The Crown Jewels)

  • Source Code: NEVER upload. Provide an architecture diagram. If they need to verify code quality, use a third-party audit or a “Clean Room” inspection on a secure laptop.
  • Patent Applications (Unfiled): Redact specific claims. Show the filing status, not the invention logic.

[TO EDITOR: Guidance for illustration. A table comparing ‘Tier 1 (Safe)’ vs ‘Tier 3 (Radioactive)’. Tier 1: Org Chart, Audited Financials, Standard Terms. Tier 3: Source Code, SSNs, Unredacted Cap Table.]

The Rule of “Materiality”

Ask yourself: Is this information material to the valuation of the company at this exact moment?

If the answer is “No,” redact it. If the answer is “Yes, but it is dangerous,” summarize it.

Your goal is to provide enough evidence to prove value, without providing enough ammunition to destroy it.

FAQs

What if the buyer refuses to proceed without unredacted data?

You verify their intent. You move to a 'Clean Room' protocol where only their third-party auditor sees the raw data, not the buyer themselves.

Should we redact customer names?

In the early stages? Absolutely. Use code names (Client Alpha, Client Beta). Reveal the key only after the LOI is signed or diligence is advanced.

Is it better to delete a column or black it out?

Black it out. Deleting a column changes the structure and looks like manipulation. A black bar acknowledges the data exists but signals it is currently off-limits.