+

Boundeal builds an enterprise-grade virtual data room with a startup-sized engineering team

  • Consolidates development workflows on a single platform
  • Embeds automated security throughout the SDLC
  • Enables a lean team to onboard quickly and scale production delivery
Boundeal builds an enterprise-grade virtual data room with a startup-sized engineering team
IndustryTechnology
Employees10
LocationNewark, Delaware

Want to see what GitLab Ultimate can do for your team?

Start your free trial

Boundeal’s lean founding team relied on GitLab to build a secure, enterprise-oriented deal execution platform from day one, without the operational overhead of stitching together multiple DevSecOps tools.

Virtual data rooms (VDR) have traditionally been little more than secure document storage platforms to support mergers, fundraisers, and due diligence processes — a place to upload files and control who can see them. Bohdan Zakharchuk, CEO and co-founder of Boundeal, saw an opportunity to build something more: an AI-powered VDR designed for secure, high-stakes business transactions, combining enterprise-grade document security with intelligent AI agents trained for specific deal workflows that enable customers to analyze documents faster, identify risks, extract key insights, and streamline decision-making.

"We wanted to build Boundeal not just as a sharing platform for documents but as an AI-powered deal execution platform, which we plan to grow horizontally across financial markets,” Zakharchuk says.

That ambition to serve private equity firms, investment banks, and startups running high-stakes transactions comes with a non-negotiable requirement: security has to be built in from the start, not added later.

“For startups that need built-in security, I recommend starting to use GitLab as early as possible, from zero lines of code.”

- Bohdan Zakharchuk, CEO & Co-Founder, Boundeal

One platform instead of a stitched-together toolchain

As a startup with no existing tools or legacy systems to migrate, Boundeal could choose its foundation deliberately. Boundeal's founding team evaluated GitHub and Azure DevOps, but both would have required integrating multiple third-party solutions for CI/CD, security scanning, compliance preparation, and DevSecOps workflows. GitLab provided all these capabilities natively as a single platform.

The decision came down to a cost calculation that looked past the license price tag. Although GitLab licensing may have the appearance of costing more than some competitors, the reduced maintenance effort and operational simplicity of having a single tool made it the better investment. "As a single platform, GitLab is more cost effective long-term and easier to manage than maintaining several different tools and licenses," Zakharchuk explains. “For a small engineering team, the value isn't only in license cost, it's in reducing the operational overhead of maintaining separate CI/CD, security, package management, testing, and development tools. Having all those workflows integrated in GitLab lets us spend more time building the product instead of maintaining the toolchain."

Today, Boundeal manages more than 10 development and DevSecOps workflows through GitLab, including merge request review, SAST, secret detection, dependency vulnerability scanning, container scanning, package management, CI execution, unit and integration testing, environment management, and post-deployment UI and API quality gates.

As a result, Boundeal’s engineering organization is able to ship with the frequency of a much larger team. Over a recent 90-day period, six active contributors completed 127 merge requests and 206 production deployments across 16 frontend, backend, and infrastructure pipelines. During the same period, Boundeal ran 317 CI pipelines with an average runtime of approximately six minutes, giving developers fast feedback on builds, automated tests, security checks, and deployment readiness. For CI workloads that do not require direct connectivity to Boundeal's AWS infrastructure, the team also uses GitLab Runners. Over a recent 60-day period, these workloads consumed approximately 6,000 runner minutes, reducing the need for Boundeal to maintain dedicated build infrastructure for every CI use case.

“GitLab gives our engineering team considerable leverage,” Zakharchuk says. “We're operating a multi-component SaaS platform with automated code review, testing, security scanning, CI/CD, and post-deployment quality gates without needing separate teams to operate every part of the toolchain.”

Consolidation carried extra weight given what Boundeal builds. The company operates in one of the most security-sensitive SaaS markets, where customers expect enterprise-grade security, compliance, and auditability, so Zakharchuk wanted security embedded throughout the software development lifecycle rather than bolted on later. That means security controls are not separate activities performed before an audit or release; they are part of the standard engineering workflow every time the team builds and ships software. GitLab also acts as the orchestration layer for Boundeal's software quality gates. Changes move through merge request review, unit and integration testing, SAST, secret detection, dependency and container vulnerability scanning before deployment. After deployment, automated end-to-end UI and API tests validate each environment, providing an additional quality gate before changes progress further.

While some startup founders may default to GitHub, Zakharchuk encourages them to consider the full picture based on their product, audience, and expectations, especially from a security perspective. "If you're building a product where security, compliance, CI/CD, auditability, and preparation for audits like ISO 27001 or SOC 2 matter, there's a complete toolchain available in GitLab that GitHub simply lacks. For startups that need built-in security, I recommend starting to use GitLab as early as possible, from zero lines of code."

“Startups are often told to move fast, and worry about processes and security later. But when you're building security-sensitive software, postponing engineering discipline creates technical and security debt that eventually becomes very expensive.”

- Bohdan Zakharchuk, CEO & Co-Founder, Boundeal

Building AI that respects permission boundaries

Boundeal's platform includes an AI Deal Assistant that helps users make sense of large document sets with hundreds or thousands of sensitive documents. But building an AI feature inside a platform built on strict access controls introduced a complex design challenge.

Because users inside the same data room often have different document permissions, Boundeal's AI architecture cannot simply index everything a project contains and expose it to a shared model context. Instead, AI responses must be generated within the same authorization boundaries governing the underlying documents. "A Boundeal user might have permission to see document A but not document B," Zakharchuk explains. "So our AI Deal Assistant has to respect exactly the same permission boundaries as the VDR itself. That's why we designed AI around the principle that authorization comes before intelligence.”

That same scrutiny extends to how Boundeal evaluates AI tools for its own engineering workflow. Zakharchuk says the team is interested in adopting GitLab Duo Agent Platform in the future as they expand their AI-assisted development practices, particularly for vulnerability explanation, merge request review, and security remediation guidance.

"GitLab Duo Agent Platform should help reduce cognitive load on the team and expedite many of our development practices."

- Bohdan Zakharchuk, CEO & Co-Founder, Boundeal

Graduating from the GitLab Startup Program and expanding into new markets

Having joined the GitLab Startup Program at a very early stage, Boundeal is now in its second year and on track to graduate from the program and keep growing. GitLab will continue to be the foundation of Boundeal’s DevSecOps workflow, helping automate software delivery, improve security, and support an expanding team.

Zakharchuk expects the team’s use of GitLab to evolve, and looks forward to exploring opportunities to take full advantage of the platform’s AI orchestration capabilities and expand into more advanced, enterprise-grade security controls. Additionally, as the engineering team grows, Zakharchuk anticipates onboarding to be quick and seamless. “New developers can be up and running on GitLab in about one day and start making an immediate impact as we scale the business.”

What’s next? Boundeal's roadmap extends beyond VDR into a broader AI-enabled deal execution platform, including AI-assisted risk and anomaly detection in uploaded documents for deal types like private credit. As the company expands into the U.S. market focusing on M&A firms, fundraising, and startups which require SOC 2 and ISO 27001 certifications, having engineering practices already centralized in GitLab is paying off. That readiness shows up in conversations with prospective customers and auditors alike.

"GitLab is the backbone of a broader control environment we're building, and helps us implement and demonstrate important controls required for certifications like SOC 2 and ISO,” Zakharchuk says, “The advantage is that we're not just creating evidence for an audit after the fact — we've been operating this way from the start — and that's extremely valuable for a small company preparing for enterprise customers."

For a startup building one of the most security-sensitive kinds of software there is, the trajectory from a 10-person founding team with no tools in place to building enterprise-grade software for global customers reflects the bet Zakharchuk made from day one: that engineering discipline and security can't be bolted on later, and that the right platform lets a small team act like a much bigger one.

All information and persons involved in case study are accurate at the time of publication.