Encrypted drives vs seller-hosted access for large dataset delivery

For multi-terabyte records, encrypted drives suit one-time, fixed snapshots and slow connections, while seller-hosted access suits datasets the company wants to keep in its own environment under its own logs. SourceX never hosts multi-terabyte datasets, so the handover method is agreed with the company and recorded.

Which method should a company choose?

Choose encrypted drives when the dataset is a fixed snapshot, the network path is slow or the company wants the data to leave only once on physical media. Choose access in the company's own storage when it wants to keep custody, watch access logs and revoke access at a date it controls. A managed transfer fits in between when both sides already trust a transfer service.

SourceX never hosts multi-terabyte datasets. Large deliveries stay in the seller's own storage or ship on encrypted drives, and the handover is recorded. Delivery happens only after an executed agreement and the company's authorization, and nothing is binding until the company signs.

Side-by-side comparison

FactorEncrypted physical drivesSeller-hosted accessManaged transfer service
Custody during transferCourier and carrier chainStays with the company until pulledThird-party service holds data in transit
Who controls accessHolder of drive and keysCompany, through permissions it setsBoth sides, via service settings
Key handlingKeys sent separately from drivesCredentials issued per person and revoked laterService keys plus access links
VerificationChecksums and a count of drivesAccess logs and checksumsService logs and checksums
Speed for very large setsLimited by shipping time, not bandwidthLimited by buyer's download bandwidthLimited by both ends' bandwidth
RevocationHard once shipped; depends on the agreementEasy: switch off accessDepends on the service
Chain of custody paperworkHeavier: shipping, receiptsLighter: logsMedium
Best forOne-time snapshots, slow linksStaged review, tight controlMid-sized sets, mutual trust

When do encrypted drives win?

Drives win when the bandwidth math does not work or the company wants a clear, one-time physical handover. A shipped drive has a clean start and end: it leaves on a date, arrives on a date and is verified on arrival.

Their risks are practical. Drives can be lost or delayed, and the keys must travel separately. Agree in advance who generates the encryption keys, how they are shared, what happens if a drive does not arrive and how the buyer certifies destruction or return of any media it no longer needs.

When does seller-hosted access win?

Seller-hosted access wins when the company wants its own logs, can restrict access by person and date, and wants the right to switch it off. It also suits staged review, where a buyer inspects a sample first and is granted wider access only after approval.

The risks are on the company's side. If staff create overly broad shares, the data can leak internally or externally. The guide to internal access controls lists the controls to set up first, and the buyer must also agree not to copy beyond the licensed scope.

When might a managed transfer fit?

A managed transfer service can work for mid-sized sets when both sides already use the same tool and security terms. The company should check the service's retention, encryption and logging settings, and who can see files in transit. It adds a third party to the chain, which some owners prefer to avoid.

Decision rule: the 3-question handover test

Ask these three questions in order, and use the first clear answer.

  1. Does the company want custody to stay with it until the last moment? If yes, choose seller-hosted access.
  2. Is the dataset a fixed snapshot that must leave only once? If yes, choose encrypted drives.
  3. Do both sides already trust the same transfer tool, and is the dataset moderate in size? If yes, a managed transfer may fit.

If none applies, discuss a hybrid: a reviewed sample through seller-hosted access, then the bulk on drives.

What should be agreed whichever method is chosen?

  • Who generates and holds the encryption keys.
  • How checksums or file counts will be verified on arrival.
  • The handover date and the person authorizing it.
  • How the handover is recorded; the delivery manifest template is a starting point.
  • What happens to working copies and media after handover.
  • How the buyer reports and handles anything delivered by mistake; see what happens if something sensitive slips through.

Common mistakes

MistakeWhy it hurtsFix
Shipping keys with the driveOne loss exposes everythingSend keys separately and later
No checksum on arrivalYou cannot prove what arrivedAgree the check in advance
Broad share links "for convenience"Anyone with the link can openUse per-person access with expiry
No record of the handoverDisputes cannot be resolvedRecord what, when, who and how
Keeping working copiesCopies outlive the projectDelete on a dated checklist

How to explain this to an owner

Customers sometimes ask the company how their information is handled, and the reply templates for customer questions help. A sponsor weighing brand exposure should also read the portfolio reputational risk guide.

When none of this matters

If the dataset is small enough to move comfortably over a normal secure connection, the choice is simple. The decision becomes real only above the size where moving files takes days or where the company's policy requires physical media.

Illustrative scenario

Illustrative and fictional. A 220-person logistics software company has about a decade of tickets, shipment exception records and engineering reviews spread across ten systems. Its IT director prefers to keep custody, so the company offers a reviewed sample through its own storage with per-person access that expires. After the buyer approves the sample, the bulk set is written to encrypted drives because the buyer's connection is slow. Keys are sent separately, checksums are compared on arrival and the company records both steps. The company signs only after counsel has read the handover terms.

Which method suits which situation?

SituationLikely fitReason
Fixed snapshot, slow connectionsEncrypted drivesShipping avoids bandwidth limits
Staged review before full accessSeller-hosted accessAccess widens only after approval
Strict company policy against external copiesSeller-hosted accessData stays in the company environment
Both sides already share a transfer toolManaged transferFewer new steps to approve
Very sensitive categoriesSeller-hosted, with smaller scopeFewer copies and clearer logs

Next step

If a company you know holds years of records across many systems, register as a partner and make the introduction. SourceX handles the process from qualification through delivery, and partners never handle records. The referral FAQ covers the rest.

Common questions

Does SourceX store the dataset?

No. SourceX never hosts multi-terabyte datasets. Large deliveries stay in the seller's own storage or ship on encrypted drives, and the handover method and details are recorded. The company decides which route fits its policies and the agreement.

Who owns the drives and keys after delivery?

That is set in the agreement. A good agreement says who holds the media, who holds the keys, how long the buyer may keep them and how return or destruction is confirmed. Settle these before the first drive ships.

Can access be revoked in a seller-hosted setup?

Yes, the company can switch off access that it controls, subject to the agreement. That is one reason owners who want strong control prefer seller-hosted access. The license terms should say what the buyer must do with data it has already copied.

Is shipping drives slower than a transfer?

For very large sets it can be faster in practice, because shipping time does not depend on bandwidth. For smaller sets a secure online route is usually quicker. The right answer depends on size, location and the connection on both ends.

When is delivery allowed to start?

Only after an executed agreement and the company's authorization. Redaction and de-identification requirements are agreed with the company before any work begins, and the handover is recorded when it happens.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment