How NDAs work when you sell a small business
A plain-language guide to NDAs in small business and SaaS sales: mutual or one-way, what they cover, non-solicits, term, and what they cannot do.
Published , 6 minute read
Almost every sale of a small online business starts with a non-disclosure agreement. The seller wants to share revenue, customers and how the business works. The buyer wants to see enough to make an offer. The NDA is the handshake that lets that exchange happen: the buyer promises to keep what they learn confidential and to use it only to evaluate the deal.
It is a useful document. It is also a limited one, and sellers who understand its limits make better decisions about what to share and when.
Mutual or one-way
A one-way (unilateral) NDA protects only one side. In a sale, that is usually the seller: the buyer receives confidential information and promises to protect it.
A mutual NDA protects both sides. That sounds like overkill for a sale, but buyers share things too: their identity, their fund size, their plans for the business, sometimes details of their other companies. Many buyers, especially repeat acquirers, prefer mutual NDAs because they sign dozens and want one standard form. Mutual NDAs are also faster to agree, because neither side feels the terms are tilted against them.
For most small deals, a short, balanced mutual NDA gets signed quickly. A long, one-sided NDA drafted to protect the seller against every possibility tends to trigger a round of edits from the buyer's lawyer, which delays the part of the process where momentum matters most.
What a typical NDA covers
The wording varies, but most NDAs in business sales have the same building blocks.
- Definition of confidential information. Usually broad: financial data, customer information, product details, and the fact that the business is for sale at all. Some NDAs cover only information marked as confidential. For a sale, a broader definition is usually safer for the seller.
- Permitted use. The buyer may use the information only to evaluate and negotiate the acquisition. Not to build a competitor, not to approach your customers, not for any other deal.
- Who else can see it. Buyers need their accountant, lawyer, lender or investors to look at the numbers. Most NDAs allow sharing with these "representatives" if they are bound by similar confidentiality duties, and make the buyer responsible for them.
- Exclusions. Information that is already public, that the buyer already knew, that they received from someone else without a duty of confidence, or that they developed independently is normally excluded. These exclusions are standard and reasonable; resisting them tends to slow things down without adding much protection.
- Compelled disclosure. If a court or regulator requires the buyer to disclose something, they may, usually after telling you so you can object.
- Return or destruction. When the deal ends, the buyer returns or destroys what they received, with the common exception of copies kept in automatic backups or required by law.
- No obligation to do the deal. Signing an NDA does not commit either side to anything else.
- No promise of accuracy. Sellers often state that information is provided as-is, with any promises about accuracy left to the purchase agreement.
Non-solicitation of employees and customers
This is the clause that matters most to many small business sellers, and it is often missing from generic templates.
A non-solicit of employees and contractors stops the buyer from trying to hire your people for a period, often one or two years. If you have a key developer or support lead, you want this. The buyer is about to learn exactly who holds the business together.
A non-solicit or no-contact clause for customers and suppliers stops the buyer from contacting your customers, vendors or partners about the business without your permission. In a small SaaS, a buyer calling your largest customer "just to check" can do real damage, and a competitor posing as a buyer could use your customer list directly.
Whether these clauses are enforceable, and for how long, depends on where you are and how they are written. Courts in some places look closely at restrictions on hiring and on competition. This is one area where a short conversation with a lawyer is worth it.
How long it lasts
NDAs usually set two different periods: how long the parties will be sharing information, and how long the duty to keep it confidential lasts after that. For small business sales, confidentiality periods of one to three years are common. Some NDAs protect trade secrets for as long as they remain trade secrets, which is sensible for things like proprietary code or algorithms.
A very long term is not automatically better. Buyers push back on it, and for most operating information (last year's revenue, last year's churn) the value fades quickly anyway.
What an NDA cannot do
This is where sellers overestimate the document.
- It cannot un-share anything. Once a buyer has seen your customer list, an NDA gives you a claim if they misuse it. It does not make them forget it.
- It is only as strong as your willingness to enforce it. Enforcing an NDA means proving a breach and going to court, often in another state or country, against someone who may have few assets. For a small seller, that is expensive and slow.
- It does not stop general competition. A buyer who walks away can still build a similar product using general knowledge and skill. Stopping that would take a non-compete, which is a different and more heavily scrutinized clause.
- It does not protect information you share before it is signed. Teasers and listing pages are public by design.
- It does not verify who the buyer is. A signature from a throwaway email address is not worth much.
The practical answer is to treat the NDA as one layer of protection, not the only one. Share in stages: a teaser before the NDA, detailed financials after it, and customer names, bank statements and contracts only after a letter of intent. Know who you are dealing with, and keep a record of exactly what each buyer saw. Our guide to what to put in a SaaS data room sets out what belongs in each stage.
Practical tips for sellers
- Use a standard, balanced form. Buyers sign familiar forms quickly.
- Add the non-solicit clauses if your template lacks them.
- Get the NDA signed by a named person with a verified email, not "Acquisitions Team".
- Keep a copy of every signed NDA, with the date and what was shared afterwards.
- Do not send your financials as email attachments. Once a file is attached, you have no control over where it goes next.
How Arrhis handles NDAs
In Arrhis, each buyer gets their own link. They verify their email and sign the NDA in the page before they see anything beyond the teaser, and the signed copy is stored against that buyer. The NDA is an agreement between you and the buyer; Arrhis provides the software and is not a party to it. You can see the structure we use on our NDA template page. After signing, buyers see your numbers with the source of each one labelled, and customer names stay locked until you mark their LOI signed. Before you open a room, work through the due diligence checklist buyers use.
Create a deal room or walk through the demo room as a buyer would.
Related guides
- The SaaS due diligence checklist buyers actually useWhat buyers check before acquiring a small SaaS: financials, revenue quality, tech, legal and IP, operations and customers, with what good looks like. 5 minute read.
- How buyers verify MRR, and why screenshots are not enoughHow acquirers check a SaaS's MRR: annual plans, trials, coupons, failed payments, revenue versus MRR, and matching payouts to bank deposits. 5 minute read.
- How to create a read-only restricted key in StripeStep by step: create a Stripe restricted key with read-only access for due diligence, which permissions to grant, and how to delete it afterwards. 6 minute read.