Secure document sharing for M&A and corporate finance advisors

The information memo goes out before the data room exists.

Six buyers get the memorandum. One walks. Three weeks later the seller's margins turn up in a competitor's pitch. The early stage of a process is the least controlled part of it, and it is the part that runs on email. GCN.ONE gives each buyer their own encrypted share, revocable on its own, with a record of every download.

Send a file now See pricing
The riskiest documents go out before the data room opens

Teasers, the information memorandum, the first model - these travel by email weeks before anyone provisions a data room. They reach people who have signed an NDA and people who have not signed one yet, and once they are attachments they are copies you cannot withdraw.

A data room solves this later in the process, and solves it well. It does not help on the Tuesday you need the memorandum in front of nine buyers, and it is not something you spin up for a teaser. Meanwhile the documents that decide the price are the ones moving with the least control.

How a process works with GCN.ONE
1
One share per buyer
Each party on the list gets their own share of the memorandum. Everything is encrypted in your browser before upload, so our servers hold ciphertext they cannot read.
2
Revoke the ones that drop out
When a buyer walks, cut off their access. The others are untouched. Set an expiry so that nothing outlives the phase it belonged to.
3
Know who downloaded which version
Every open and download is recorded per buyer, per version, with a timestamp - and for any download you can issue a cryptographically signed delivery certificate.
Built for a live process
Individually revocable
Access is granted per buyer, so a party that drops out loses access without disturbing anyone else.
Version history
Add the updated memorandum to the same share and it replaces the old one without a re-send. The record still shows who took which version.
Nothing lingers after the phase
Shares expire on a schedule you set and the encrypted data is permanently deleted - no archive waiting to surface in a later dispute.
A signed record of every download
Cryptographically signed, timestamped, and independently verifiable by anyone - including the other side's counsel.
The delivery record, in plain terms

For any document that was actually downloaded you can issue a delivery certificate: a signed record of what was delivered, to whom, and when. The signature is cryptographic, so anyone can check it at our public Verify page - it does not depend on our word, or on our continued existence as a company.

Our audit log is tamper-evident and publicly anchored, so the history behind a certificate cannot be quietly rewritten. This is strong, independently checkable evidence of delivery. Whether specific statutory or contractual notice requirements are met in a given process is a question for the applicable law and the applicable documents; we make no claim to be a qualified delivery service under eIDAS.

Confidentiality and compliance

Encryption happens in the browser and the keys never reach us, so client confidentiality is protected structurally: there is nothing readable on our side to disclose. What the servers do see is metadata - sender, recipients, timestamps and sizes. All infrastructure runs in the European Union under EU jurisdiction and is built to GDPR standards.

Request our Data Processing Agreement (DPA)

Frequently asked questions

It is for the stage before one. A data room is the right tool for structured diligence with hundreds of documents and granular permissions; this is for getting the teaser and the memorandum in front of a buyer list today, with per-buyer revocation and a record of who took what. Many processes use both.

Yes. Verification is public and needs no account: anyone holding the certificate can confirm its authenticity at our Verify page.

Revoke their access, which stops anything further. What they already downloaded is on their machine and no service can reach into it - that is what the NDA is for. What you do have is a signed, timestamped record of exactly what they took and when.

Yes. GCN.ONE can run entirely on your own servers, with the same per-buyer revocation and the same audit trail, inside your environment. See the Enterprise page for how that works.
Try it on your next memorandum
A free account takes a minute. Send one document and see the record.