Email is how most confidential documents actually move, and email is a handover: once the attachment leaves, you have no idea who read it, who forwarded it, or where it lives now. A KXCO Meridian data room replaces the handover with a reading room. You upload the documents once, invite people by name, put every one of them behind a recorded NDA, and keep the file. This guide walks the whole product as it stands today, from the first upload to closing the room when the deal completes.
01What a data room is for, and what it is not
A Meridian data room is a private, view-only space for sharing sensitive material with named people: due diligence, fundraising, board papers, legal disclosure, M&A, a product a partner needs to evaluate without keeping. Readers see the documents in a locked viewer. They do not receive files.
Three facts frame everything else in this guide.
- Every Meridian account has data rooms built in. Sign in at meridian.kxco.ai and open Data Room from the sidebar. There is nothing extra to buy to get started. The forwardable master link and multi-party features described later are Enterprise capabilities.
- Readers never need an account. They arrive on an emailed link, prove who they are by signing the NDA, and read. Nothing to install, nothing to register, no password to forget.
- The product is deterrence plus evidence, not magic. It removes the easy ways to take a document and records everything that happens. It does not claim to stop a camera pointed at a screen, and section 14 states every limit like that one in plain words.
02Create a room and upload documents
From the console, create a room with a clear name, "Series A · Diligence", and an optional description. Each room is a self-contained space, separate from your signing documents and from your other rooms. You can also set an access code, a second factor beyond the emailed link, useful when you want the code to travel through a different channel than the invitation.
Then upload. Several files at once, more at any time, up to 500MB per file, and the room takes more than paper:
- PDF and Office documents are converted and rendered page by page into secure images. The raw file is never placed at a public URL, so there is no link that hands over the original.
- Images become single-page documents, available immediately.
- Video is transcoded on the server and streamed only inside the locked viewer, with a poster frame and its duration shown in the console while it processes. A site walkthrough or a founder's pitch can sit in the room next to the model it explains.
Uploads land in the room, not on the open web. Deleting a document removes the stored bytes and the rendered pages, not merely the listing.
Documents now carry version chains. Upload a new version of any document and every reader switches to it instantly; the old version leaves every reader surface at the same moment, and a byte-identical file is refused. The room then compares the versions and gives you a report of what changed, rate and date changes flagged as material, with the before and after wording quoted verbatim. The new version inherits the old one's disclosure tier, so a protected document can never widen by accident.
03Inviting readers by email
Invite people one at a time or in bulk, pasting addresses separated by commas or new lines. Each reader receives their own unique link, tied to one email address and one room, and you also get a copyable list of links to send through your own channels if you prefer. If the room has an access code, the reader enters it before anything else loads.
Two clocks run on access, and the difference matters:
- An unused invitation expires after seven days. A link sitting unopened in an inbox goes stale on its own.
- A reader who signs the NDA gets a permanent return link, emailed to them, that lasts until you revoke it. People come back to diligence materials for weeks, and making them chase a fresh invitation every seven days punishes exactly the readers you want engaged.
Revoke works instantly against both. Revoking an invitation kills the link and the permanent pass together, and a reader mid-session is cut off within minutes when their session token expires.
Readers who do hold a Meridian account get one more convenience: Shared with me in the sidebar lists every room their verified email has been invited to, with a fresh link one click away. Invitations keep working for people with no account at all; this is a shortcut, not a requirement.
04The NDA gate
Before a single page loads, every reader must accept a non-disclosure undertaking addressed to you, by name. The gate order is fixed: the link admits them, the access code (if set) is entered, the NDA is signed, and only then do documents render. There is no route into the room around it.
The undertaking is short and readable: the material is confidential, it is not to be shared without your written permission, and unauthorised disclosure of intellectual property or inside information on a listed security can be a criminal matter, under UK governing law. The reader types their full name and agrees.
What makes this more than a checkbox is what gets recorded:
- The reader's name, email, the exact NDA text and version, timestamp, IP address and device.
- A post-quantum ML-DSA-65 signature over the acceptance, the same signature standard, NIST FIPS 204, that signs documents across KXCO.
- A signed NDA certificate as a PDF, emailed to both of you. The reader holds a copy of what they agreed to, and you hold the evidence without asking for it.
- The acceptance hash is anchored to the Armature L1 record, so the evidence has a timestamped existence outside the application that wrote it.
Three ways to sign. Typing your full name remains the default. A reader can instead sign with a Web3 wallet (a structured EIP-712 signature, no transaction and no gas, the wallet address bound into the record) or with a KXCO Identity key (a pure ML-DSA-65 challenge-response, post-quantum end to end, the key's fingerprint bound into the record). Whichever method the reader chooses, it is the same NDA, the same certificate emailed to both parties, and the same anchor; the platform's ML-DSA-65 signature stands behind every method, so the durable evidence never rests on classical cryptography alone.
An optional NDA is a negotiation you have to win room by room, reader by reader. A mandatory one is just how the door works. Nobody has ever read a document in a Meridian data room without a recorded undertaking standing behind the view, which is precisely the fact you want available if a document turns up where it should not be.
05The locked viewer
Documents open in a viewer built to let people read and nothing else.
- No download, no copy, no print, no text selection. Pages are rendered as images inside the viewer, and the original file is never reachable at any URL, guessed or otherwise.
- A light confidential watermark is tiled over every page, so a photograph of the screen carries its own label.
- The view blurs the moment the tab loses focus, which defeats the casual screen-share and the over-the-shoulder glance, and idle sessions time out on their own.
- Page requests are rate limited at a threshold no human reader ever meets, which cuts off a scripted sweep of a room without ever refusing someone turning pages.
- Video streams inside the same gate. It plays only in the locked viewer, behind the same session and NDA checks as the pages.
Everything the reader does is logged as it happens: room opened, page viewed, for how long. That record is yours, in the console, and section 10 covers what it becomes.
06The forwardable master link
Named invitations assume you know who the readers are. Often you do not: the deck goes to a banker who sends it to their list, or a room link sits behind a "request access" button. For that there is the master link, on Enterprise rooms.
One link, forwardable on purpose. Anyone who receives it, however many hops out, hits a gate that asks for their name and email. Then, before anything is granted:
- They confirm the email. A confirmation link is sent to the address they typed, valid for thirty minutes. A fake or mistyped address never confirms, never becomes an invitation, and leaves no trace on your roster.
- They sign the NDA, exactly like a named invitee, with the same recorded evidence and the same emailed certificate.
- They become a row on your roster, tagged as a forwarded arrival, with their own permanent link and their own activity trail.
The console gives you the controls that make a spreading link safe to spread. Copy shares it. Download roster exports every viewer as a CSV: who they are, when they arrived, what they signed. Reset rotates the link's secret, which kills every copy in circulation at once while your named invitations and existing signed readers carry on untouched. Turn off closes the gate entirely.
A forwarded email normally costs you the audit trail. Here it feeds it: every person the link reaches has to identify themselves, prove the email is theirs and sign before they see a page. The link spreads; the anonymity does not.
07Short links and link previews
A master link is a long token. For a link you will say out loud, print on a deck or type from memory, give the room a short link: meridian.kxco.ai/r/yourword, set in the console next to the master link controls. It forwards into the same gate, so nothing about the identity, confirmation or NDA flow changes.
One deliberate privacy choice is worth knowing about. When any data-room link is pasted into a chat, a text message or a social feed, the preview card that unfurls is a generic KXCO Data Rooms card. It never shows the room's name. A deal name is itself confidential information, and a link preview in a group chat is not where it should first appear. Authorised readers still see the real room name once they are through the gate.
08Multi-party rooms
A diligence room has two sides. A live transaction has more: the company supplying documents, the firm running the process, the investors reading, and the lawyer someone wants brought in late. Enterprise rooms carry all four as first-class roles.
| Party | Who they are | What they can do |
|---|---|---|
| Owner & co-administrators | The firm running the room | Everything: upload, release, invite, revoke, tier documents, approve requests |
| Contributors | The company or party supplying documents | Upload into intake; read what their role allows; see their own originals |
| Viewers | Investors, counterparties, advisers | Read released documents; propose an introduction |
| Introduced parties | Late arrivals a viewer vouched for | Narrowest read-only access |
The mechanics that make four parties safe in one room:
- Documents are tiered. General material, intake, term sheets and protected documents are separate rungs, and who sees which tier is an explicit allow-list per role. A document whose tier the system does not recognise is shown to nobody: unknown fails closed, never open.
- Contributor uploads land in intake. Only the owner and the uploader see a new document until the owner deliberately assigns its tier. Nothing a contributor uploads reaches an investor by accident.
- Clearance is separate from role. Standard clearance reads the redacted rendering where one exists. Full clearance reads originals, and the server refuses to grant it until that person has a signed NDA on record, and refuses it entirely for introduced parties. A contributor always sees the originals of their own uploads.
- Information requests are tracked, not chatted. The owner raises a request against a contributor, "send the 2025 audited accounts", and it stays open until fulfilled or closed, on the record.
- Introductions are proposed, never self-served. A viewer proposes bringing someone in; the owner approves; the system mints the invitation. Nobody widens a room's audience except the party who owns it.
09Ask the documents: the room AI
A room with three hundred pages has answers in it that take a reader an afternoon to find. Each room can switch on an assistant, per room and off by default, that has read everything in it.
- Cited question and answer. A reader asks in plain language and gets an answer with citations to the exact documents and pages it relied on, so the claim can be checked rather than trusted. Owners have the same box over their own room.
- Questions that need the seller reach the seller. When the assistant cannot answer, or a reader wants your word for it, the question routes to you as a tracked thread: categorise it, close it, answer privately or publish the answer to the whole room. Citations you attach to an answer must match the documents they point at, and the assistant can draft a reply from the room's contents, clearly labelled, with nothing sent until you send it.
- Summaries and translation. A room summary for the reader arriving cold, and reading in other languages, so a bilingual deal does not need two rooms. The application itself runs in English, Simplified Chinese and Traditional Chinese.
- A redaction workflow. The room can flag material you may not have meant to expose before you release a document: personal data, bank details, named counterparties, prices and margins, deal terms. You review each flag, draw your own boxes on the page where the scan missed something, and burn the approved set into the pages readers see. Findings are flags for your judgement, not silent edits, and the assistant will not quote what sits under a burned box to a reader who sees the redacted rendering.
- Predicted questions. The room reads its documents and drafts the fifteen to twenty-five questions buyers are most likely to ask, each citing the passage that raises it; a question that cannot cite its trigger is discarded. You write the answers before the first call, and publishing an answered question to the room is per question and reversible.
- A consistency check. The room reads documents against each other and flags material inconsistencies: a rate that differs between a contract and the model, conflicting dates, party names that drift. Both sources are quoted verbatim on every finding, and findings are visible to you and your co-administrators only.
Two design decisions matter more than the features:
- The AI respects the room's permissions, on the server. Its answers draw only on the documents that specific reader is allowed to see. The restriction is enforced where the documents are retrieved, not requested politely in a prompt, and a reader whose visible set is empty gets nothing. Introduced parties get no summary at all.
- Indexing happens on KXCO's own server. The text of your documents is not shipped to a third-party embedding service to make search work.
The assistant is a faster way into documents you are entitled to read, and the citations exist so you check the page rather than quote the answer. It is not advice, and a redaction scan that found nothing is not a warranty that nothing sensitive is there.
10Activity and analytics
The record the viewer writes becomes the intelligence you read.
- A live activity trail per room: who opened it, which pages they viewed, when, for how long. You are emailed the first time each room is opened.
- A page heat map across the room, showing where attention actually concentrated. The clause every investor stops on is information you want before the first call.
- Per-person engagement, reader by reader, so "they went quiet" and "they read the financials four times on Tuesday" stop being the same fact.
- The roster CSV on master-link rooms, exporting every viewer with their arrival and NDA record, ready for a CRM.
- Recent activity on your dashboard, so the latest events across every room find you without opening each one.
- A deal-health score per reader. Recency, sessions, reading depth, coverage (term-sheet pages weigh double) and progress through the deal, combined into one number by a formula you can inspect: every score expands to show the raw inputs behind it. Scores are yours alone; readers never see how they are being read.
- A signed event feed underneath it all. The same activity is available to KXCO's internal deal tooling as structured events: visit summaries rather than raw page-turns, delivered by pull or by webhook, every delivery signed with ML-DSA-65. Events carry identities and counts; document content never enters the stream.
11Co-administrators
Rooms used to have exactly one operator. A live deal often needs two, and now a room can carry co-administrators: colleagues or counterparts with full console power over that room, upload, invite, revoke, the master link and its reset, everything the owner can do to operate it. NDA certificates still go to the room's owner, and co-administrators see every acceptance in the console. It is a per-room grant, not an account setting, so the person you trust with one transaction gains nothing over the rest of your rooms.
12Closing a room: migration and export
Deals end, and a room should end with them rather than lingering half-alive with a dozen live links into it.
- Migrating a room freezes it in one action. Every guest link stops resolving at once, invitations, permanent passes and the master link together. Reopening it later restores them just as cleanly.
- Export gives you the archive: a single bundle containing the original files and a manifest of what the room held. Your evidence trail, the NDA acceptances and activity records, remains in the console.
- A transaction that grows up moves to Meridian. A data room is where a deal starts; a cap table, capital calls and settlement live on Meridian, and the export bundle is built to carry the room's contents across. The import is a deliberate act, not an automatic feed.
- The room's knowledge can export to the Round Table ontology engine. Verified facts, consistency findings, Q&A threads and engagement, packaged as typed claims that each carry their source quote. Every export needs your written reason and a platform administrator's approval, both recorded inside the bundle; the bundle is ML-DSA-65 signed, its hash is anchored, and original files never travel with it.
13The deals desk
Rooms tell you what a reader did. The deals desk, at meridian.kxco.ai, tells you where the transaction stands. It is a full pipeline built into every Meridian account, and its defining property is that it never disagrees with the room record: a deal's timeline is read live from the linked rooms' event record, not copied into a second database that drifts.
- Deals move through pipelines you define. The default pipeline mirrors a Meridian transaction (prospect, NDA signed, in diligence, term sheet, closing), each stage with a probability a deal can override. Add your own pipelines for fundraising, M&A or partnerships, each with its own stages; a stage that still has open deals on it cannot be deleted. Drag a deal between columns to move it, and every stage and probability change is kept as history, with who moved it and when.
- Link one or more rooms to a deal and the deal inherits their intelligence: the activity timeline shows NDA signings, reading sessions, questions and version changes as they happen, and the deal's health score is the same inspectable formula the room console shows, averaged across its rooms.
- Companies and contacts carry their own history. A contact's profile shows every room their email was invited to and how engaged they were in each; a company rolls up its contacts, deals, rooms and engagement in one view.
- Notes, calls, emails, meetings and tasks sit on the deal. Tasks take an assignee and a due date, overdue ones are flagged, and reminders arrive through the notification channels below.
- Share a deal with your team by email, with three roles: a viewer reads, a member edits fields and moves stages, an admin can also close and share. Two things sharing never does: it never grants access to your data rooms themselves, and it never exposes document content, because the shared timeline is the same content-free event record. Every CRM action lands on a permanent audit log.
- Reporting covers pipeline value and weighted value by stage, win rate with close reasons, deal-health distribution, stage conversion computed from real history, and a forecast bucketed by expected close month.
- Outside CRMs can stay in the loop. Connect HubSpot or Pipedrive with an API token, or Salesforce once its connected app is configured on the server, choose a direction per object, and decide who is the system of record. With Meridian as the record, an outside change can create a deal here but never overwrite one, and every sync decision, including the skips, lands on a per-connection log.
14Alerts on Telegram and Slack
Deal teams live in chat, so Meridian meets them there, on Telegram through an official bot and on Slack through an official workspace app. Both carry the same alerts and both obey the same rule: messages are built from the platform's event record, which never contains document text.
Telegram links in a minute: open the deals desk, press Link Telegram, and send the one-time code to @KXCONexus_bot as /start <code>. Codes are single-use and expire within the hour; nothing arrives in a chat you have not explicitly linked.
Once linked, the bot sends clean messages for NDAs signed, readers cooling, new questions, consistency findings, document version changes, Round Table export decisions, deal stage changes and task reminders, each with a deep link that opens the right page or the exact deal in Meridian. It also answers:
| Command | What it does |
|---|---|
/deals | Your open deals with health scores |
/deal <name> | One deal in detail: probability, rooms, tasks, next step |
/tasks | Your open tasks, overdue ones flagged |
/health | Deals that are cooling or cold |
/room <name> | Activity summary of a room you run |
/settings | Notification categories and the daily or weekly digest |
/mute · /unmute · /unlink · /help | Exactly what they say |
Preferences live in two places, the bot's /settings and the Notifications card on the deals desk: toggle any of the nine alert categories per channel and choose a daily or weekly digest instead of, or alongside, live alerts. Signature alerts are one of those categories, so a document opened, signed, completed or declined reaches the same chat as the room and deal alerts.
Slack works the same way once a workspace admin has installed the KXCO Meridian app: press Link Slack on the deals desk, then run /nexus link <code> anywhere in Slack. Every answer is scoped to the account that linked, never to the workspace. The /nexus command covers the same read-only ground as the Telegram bot, deals, deal <name>, tasks, health, room <name>, search, status and help, and Slack adds three things of its own.
- Channels. Run
/nexus map <deal>in a channel and that deal's events flow there for the whole team;/nexus unmapstops them. Mapping requires edit rights on the deal, and channel messages are the same content-free summaries as everything else. - The App Home tab shows your pipeline, open tasks and deal health at a glance, scoped to your own linked account.
- Link previews. Paste a Meridian deal or room link and it unfurls with a short content-free summary, but only when the person pasting it has access. Otherwise Slack stays silent, so a pasted link never confirms to a stranger that a deal exists.
One deliberate exception to read-only: /nexus task opens a small form that adds a task to one of your deals. It is the same audited action as typing the task on the deals desk, nothing more.
Three properties, all structural. The integrations are read-only about your deals: nothing can be approved, moved between stages or shared from chat, and the single exception, adding a task from Slack, lands on the same audit log as the deals desk. Every message is built from the platform's event record, which never contains document text, so a message can name a room or a stage but can never leak a page. And each integration only ever answers about deals and rooms the linked account already holds; unlinking cuts both notifications and answers instantly.
15Security and the record
- Post-quantum signatures throughout. NDA acceptances are signed with ML-DSA-65, the lattice signature standard NIST published as FIPS 204, the same cryptography that signs documents across KXCO Meridian.
- Evidence bound to content. An acceptance records the hash of the exact NDA text shown, so a later edit to the wording is detectable rather than arguable.
- Anchored outside the application. Acceptance hashes are anchored to the Armature L1 record, giving the evidence a timestamped existence no application database controls. Anchoring happens after access is granted, so a briefly unreachable chain never blocks a reader, and no anchor is silently skipped.
- Originals are never web-served. Readers receive rendered pages through a gated route; the stored files have no public URL to leak.
- Access fails closed. Unknown document tiers are shown to nobody, full clearance is refused without a signed NDA, and the AI retrieves nothing for a reader entitled to nothing.
The cryptographic foundation is public and independently scanned: see the thirteen post-quantum packages KXCO publishes on npm and GitHub.
16The limits, stated plainly
A guide that lists only capabilities is a brochure. These are the boundaries of what a Meridian data room does today.
- No web product can stop a camera. Download, copy, print and selection are removed, the view blurs on tab-switch and every page is watermarked, but a determined person photographing their screen is outside software's reach. Treat the room as strong deterrence plus complete traceability, never as a guarantee against a determined leak.
- The watermark deters and labels; it does not identify the leaker by itself. It marks pages as confidential; attribution comes from the access log and the NDA record, which tell you who was in which document and when.
- A named invitation trusts the inbox it was sent to. If a recipient forwards their whole invitation email, the holder reads under that recipient's identity and signature. The master link exists precisely because forwarding is real: route expected forwarding through it, where every arrival must confirm their own email before anything is granted.
- An NDA is evidence, not a force field. The room makes the undertaking and its acceptance unarguable. Whether it holds up, and what it is worth against a given counterparty in a given jurisdiction, is a question for your lawyer, not for software.
- The redaction scan is an aid, not a clearance. It flags what it finds; it does not warrant that nothing was missed, and releasing a document remains your decision.
- AI answers are a reading aid. Citations exist so the page can be checked. Nothing the assistant produces is advice.
- Migration to Meridian is a bundle, not a pipe. The export carries the room's contents; importing them into a Meridian deal is a deliberate manual step.
- Analytics see the platform, not the world. The heat map and activity trail record what happened inside the room. What a reader did with their eyes, their memory or their phone is invisible to any product, and this guide does not pretend otherwise.
- A shared deal shares its metadata, deliberately. Someone you add to a deal sees its timeline of events, names and counts. They never gain entry to the rooms themselves, and they can never see document content through the CRM, but if the deal's existence is itself sensitive, do not share the deal.
- The forecast is arithmetic, not prophecy. Weighted pipeline is value times probability, and probability is your judgement. The report makes your assumptions visible; it does not validate them.
- Chat platforms are outside the perimeter. Telegram and Slack messages are content-free by construction, but the chats themselves live on Telegram's and Slack's infrastructure under their security models. Treat both as signal channels, never as places to discuss the contents of a document.
17Questions people ask
What is a KXCO Meridian data room?
A private, view-only space where you upload documents and invite people by email to read them behind a built-in NDA, with every view logged. Readers cannot download, copy or print, and no reader needs an account. Data rooms are built into every KXCO Meridian account at meridian.kxco.ai.
Do readers need an account?
No. Readers are invited by email and open the room through their own secure link, with nothing to install. After signing the NDA they are emailed a permanent return link, and a reader who does hold a Meridian account also sees every room they have been invited to under Shared with me.
Is the NDA legally meaningful?
Every reader accepts a click-to-agree NDA addressed to the room owner before any document loads, signing by typed name, by Web3 wallet, or with a KXCO Identity key. The acceptance is recorded with the reader's name, email, the exact NDA text and version, time, IP address and device, signed with a post-quantum ML-DSA-65 key, anchored to the Armature L1 record, and a signed NDA certificate is emailed to both parties. Whether any agreement holds up is a question for a court, not for software, and the room's job is to make the evidence unarguable.
Can readers download or copy documents?
No. Documents are rendered as watermarked page images inside a locked viewer with no download path. Copy, print and text selection are disabled, the view blurs when the tab loses focus, and idle sessions time out. It is strong deterrence with a full audit trail. It cannot stop someone photographing their screen, and it is never sold as if it could.
What is the master link?
A forwardable room link for Enterprise accounts. Anyone who receives it enters their name and email, confirms that email by clicking a link sent to it, then signs the NDA like any invited reader. Every arrival becomes a named, logged individual on your roster, downloadable as a CSV. Resetting the link kills every copy in circulation at once.
Can a room have more than two sides?
Yes. A room can carry four parties: the owner and co-administrators who run it, contributors who upload into a private intake tier, viewers who read what the owner has released, and introduced parties on the narrowest access. Documents are tiered, an unknown tier fails closed, and full clearance is refused by the server until an NDA is signed.
Does the room AI leak documents a reader cannot see?
No. The AI answers only from the documents that specific reader is allowed to see, the restriction is enforced on the server rather than in the prompt, and a reader whose visible set is empty gets nothing. Documents are indexed on KXCO's own server, so the text of your room is not sent to a third-party embedding service.
How long does access last?
An unused invitation expires after seven days. Once a reader signs the NDA they receive a permanent return link that lasts until you revoke it, and revoking cuts them off within minutes. Resetting the master link kills every forwarded copy at once.
Is there an extra charge for data rooms?
No. Data rooms are built into every KXCO Meridian account. The forwardable master link and multi-party features are Enterprise capabilities.
Does Meridian include a CRM?
Yes. Every account has a deals desk at meridian.kxco.ai: pipelines you define, deals linked to data rooms, a timeline read live from the room record, deal-health scores, tasks, team sharing with roles, reporting with forecasts, and connections to HubSpot, Pipedrive and Salesforce. Sharing a deal never grants access to the rooms themselves.
Are the Telegram and Slack integrations safe for confidential deals?
Both are read-only about your deals, answer only about deals and rooms the linked account already holds, and build every message from the platform's event record, which never contains document text. They can tell you an NDA was signed or a reader is cooling; they cannot leak a page. The single exception to read-only, adding a task from Slack, is the same audited action as typing it on the deals desk. Unlinking cuts everything instantly.
Data rooms run inside KXCO Meridian at meridian.kxco.ai, with the in-product quick-start at meridian.kxco.ai/data-room-guide and the product overview at kxco.ai/meridian. KXCO Meridian is operated by Knightsbridge Financial Ltd, trading as KXCO. KXCO is a software company and is not a party to any transaction conducted through a data room, nor a law firm, and nothing in this guide is legal advice. Cryptographic posture reflects NIST FIPS 203/204/205 alignment at Category-3 parameters; KXCO does not claim CNSA 2.0.