vCISO additional revenue: refer clients, keep security decisions with them
A vCISO can add revenue by introducing US clients with 50+ full-time employees at peak and years of well-governed records to SourceX, which manages licensing of business records to AI developers. The vCISO only makes the introduction. The company, its counsel and SourceX decide scope, de-identification and security controls, and any reward comes from SourceX's fee.
Why a vCISO sees fit before anyone else
A vCISO already holds the map most companies lack: which systems store which records, how long each record class is kept, who owns it and how it is classified. That knowledge makes you well placed to spot clients whose operating history may interest AI developers, and to introduce the owner to SourceX, which handles every step of a license from rights review through payment.
The work you do every month surfaces it. Data inventories built for a risk assessment, classification schemes, retention schedules, asset registers, vendor risk reviews and decommissioning approvals all tell you whether a company has years of connected records or a thin, fragmented estate. The catch is your role. Clients trust you to reduce data risk, so any referral has to leave every security and privacy decision exactly where it belongs: with the company.
The three-lane rule: who decides what
Keep three lanes separate and say so out loud when you make the introduction.
| Decision | The company | SourceX | You, as referring vCISO |
|---|---|---|---|
| Whether to explore a license | Decides | Explains the process and fit | Raises the idea once |
| Which records are in scope | Decides | Works through the company's data inventory | No role |
| De-identification and redaction | Approves | Agrees requirements with the company before any work begins | Advises only if the client asks, within your existing engagement |
| Delivery security | Authorizes | Delivers only after an executed agreement and the company's authorization | No role on SourceX's side |
| Price and terms | Agrees and signs | Agrees one all-in price | No role |
The fourth row is where conflicts arise. If the client asks you to review the security of a delivery while you stand to earn a referral reward, disclose that interest in writing and let the client decide whether a separate reviewer is needed.
Which clients in a vCISO book fit
| Signal | Where you see it | Why AI buyers care |
|---|---|---|
| Many systems in scope | Asset register or data map listing email, chat, CRM, finance, ticketing, engineering and file storage; strong companies often run 10-15+ systems | Connected systems show whole workflows |
| Long retention | Retention schedule keeping operational records for years, plus archived legacy systems | Long histories show how decisions and processes evolved |
| Clear classification | Labels separating internal operational records from personal, financial or health data | Makes scoping and redaction practical |
| Company-created records | Data flow diagrams showing the company generates the records rather than processing them for customers | Buyers need clean rights |
| Size and maturity | 50+ full-time employees at peak, contractors excluded, and several years of documented operations | The baseline SourceX applies to every company |
If you also act as a client's Qualified Individual under the FTC Safeguards Rule, take extra care. The rule (16 CFR Part 314) requires covered financial institutions to maintain a written information security program with a designated Qualified Individual. Customer information at those clients is regulated and would need counsel's review before anything else happens; operational records about the business may still be worth assessing.
The 4C check before you raise it
Answer these from what you already know, without asking the client for anything new.
- Created: did the company produce these records about its own operations?
- Classified: are personal, financial and health data identified well enough to be scoped out or de-identified?
- Contracted: do customer contracts, employee notices and privacy policies leave room for licensing?
- Capable: can someone at the company still export complete history from current and archived systems?
Pair the 4C check with the baseline: a US company, 50+ full-time employees at peak, several years of documented operations and a sponsor with signing authority, such as the owner, CEO or CFO. The company fit checker offers a quick preliminary screen that is non-binding and asks for no contact details, and who qualifies lists the full criteria.
Check the privacy promises first
Before any client gets excited, someone should read what it has already promised. FTC staff have stated (January 2024) that companies' promises not to use customer data for undisclosed purposes, such as training or updating models, are enforceable whether made in privacy policies, terms of service or promotional materials. That is staff guidance, not a rule, but it is a good reason to suggest the client's counsel reviews existing commitments before customer data is considered for any license.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
When to raise it in the vCISO calendar
| Moment | Why it works | The question to ask |
|---|---|---|
| Annual risk assessment | You are refreshing the data inventory anyway | Which record classes have we kept longest, and are they still exportable? |
| Retention policy review | Disposal decisions are being made | Before we shorten retention on business records, does the owner want them assessed? |
| Legacy system decommissioning | An archive is about to be destroyed | Has leadership decided what happens to this history? |
| Board or leadership security briefing | The CEO or owner is in the room | Would leadership want to know if our retained records could earn a license fee? |
| Acquisition or integration | Two estates are being combined | Who owns the acquired company's archives now? |
How the introduction works
- Mention the idea to the CEO or owner and confirm they want to explore it.
- Sign up as a partner, then pass your referral link to the CEO or enter the company in the referral form, limiting yourself to basic fit details.
- When the company applies through that link, your referral code is attached to its application.
- SourceX talks to the sponsor about headcount, years of operation, the spread of record-holding systems and who owns the data.
- The company completes a data inventory and agrees de-identification and redaction requirements before any work begins.
- SourceX and the company agree price and terms; AI labs and data buyers review; nothing binds the company until it signs.
- Delivery waits for two things, a signed agreement and the company's go-ahead; payment to the company follows.
At no step do you export records, share your data map or describe the client's systems to SourceX.
What to say to the CEO
How rewards work for vCISOs
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward becomes payable only after the buyer pays and SourceX receives its fee; an introduction, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed.
Your client's payment is unaffected, since the reward is carved from SourceX's fee. It suits vCISOs as occasional, event-driven income rather than a retainer line. If you work inside an MSP or MSSP, the guide to additional revenue streams for MSPs shows where introductions fit next to managed services, and fractional technology leaders can use the vCIO and fractional CIO page. Compliance advisers who run SOC 2 or ISO programs have their own page, with extra independence checks.
When not to raise it
- Headcount at peak was below the baseline of 50+ full-time employees (contractors excluded).
- Most records are consumer personal data, protected health information or regulated customer financial data.
- The company holds the data on behalf of its own customers.
- Archives were destroyed under policy, or nobody can export them.
- Someone already licensed the same records for AI training.
- Leadership would not consider an exclusive license for an agreed term.
Next step
At your next risk assessment, run the 4C check on one client with deep retention. If it passes, register as a partner and give the CEO your link to sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does referring a client create a conflict with my vCISO role?
It can, which is why disclosure matters. Tell the CEO in writing that you are a SourceX referral partner and may earn a reward if a license closes. Stay out of decisions about scope and delivery on SourceX's side, and if the client wants a security review of a delivery, let it decide whether someone without a financial interest should do it.
Will SourceX ask me to approve the client's security controls for delivery?
No. The referring partner's role ends at the introduction. Requirements for redaction and de-identification are settled directly between the company and SourceX before work starts, and nothing is handed over until the agreement is signed and the company approves delivery. The company's own security team or advisers set its requirements in that agreement.
Can a client with regulated customer data still qualify?
Possibly. Regulated personal, financial or health data is usually scoped out or de-identified, and a company whose records are mainly protected health information or consumer data is a poor fit. Operational records about the business itself, such as tickets, projects, approvals and engineering history, are assessed separately in the rights review, with the company's counsel involved.
What should I tell a CEO who worries about a breach during delivery?
That nothing is delivered until the company has signed an agreement and authorized the delivery, and that the company signs off on redaction and de-identification rules up front. The company decides what is in scope. Its security team can write its own requirements into the agreement, and it can walk away at any point before signing.
Does my vCISO practice need to be based in the US?
No. Partners can be based in any supported country. What must be in the US is the company you introduce, and it needs 50+ full-time employees at peak (contractors excluded), a multi-year operating record, the right to license its data and someone authorized to sign. Check local tax and professional rules where you are based.
Related pages
- Check Company Fit for Data Licensing
- Which US businesses are a fit for a SourceX data licensing introduction
- Additional revenue streams for MSPs, and where client introductions fit
- A referral program for vCIOs and fractional CIOs: how it works
- A referral program for compliance consultants working on SOC 2, ISO 27001 and CMMC
Free resources
- AI readiness assessment — Ten questions, five dimensions, a score out of 100.
- EBITDA calculator — Reported and adjusted EBITDA from net income.
- MOIC calculator — Multiple on invested capital from realized and unrealized value.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment