MSPs: answering client security questions about a data license
When a client asks an MSP whether licensing its data is secure, the honest answer is that security depends on scope, handling and agreement terms the client controls. Before any export, get written authorization from the sponsor, agree scope and exclusions, settle who holds credentials, and keep files in the client's storage or on encrypted drives.
Why clients ask their MSP first
A managed service provider sits closer to a client's systems than almost anyone else outside the company. When an owner hears about data licensing, the first call is often to the IT provider: "Is this safe? Can you pull the data? What are the risks?"
That makes the MSP a trusted voice and also a party with its own obligations. The MSP holds credentials, runs backups and may be bound by contracts that limit what it can do with client data without instruction. The answers below keep the MSP useful without taking on a decision that belongs to the client.
The roles are separate. The client decides whether to license. SourceX qualifies the company and works through price, terms and buyer review, while the company completes its own data inventory. A partner introduces and never handles records. The MSP, if engaged, performs technical tasks only on the client's written instruction.
What should the MSP say when asked "is it secure?"
Do not promise outcomes you cannot verify, and do not speak for the buyer's controls. The MSP can describe the client's side: access, staging, logging and deletion. For what never to promise, see what partners should never promise an owner about privacy.
What to agree before running any export
Use this as a pre-export checklist and keep a signed copy.
- Written authorization from the sponsor (owner, CEO, CFO or authorized representative) naming the systems and the purpose.
- Scope: systems, date range and exclusions, such as HR channels and customer content.
- Redaction and de-identification requirements agreed with the company before any work begins.
- Who holds credentials, and how they are issued and revoked.
- Where files stay: the client's own storage, or encrypted drives for large deliveries.
- Who may view the exported files and who may not.
- Logging turned on for the export tools and the staging area.
- A deletion step for working copies after handover is confirmed.
- A check of the MSP's own contracts for limits on using client data.
Who handles what?
| Task | Client | MSP | SourceX | Partner |
|---|---|---|---|---|
| Decide whether to license | Yes | Advises on technical impact | Qualifies and explains | No |
| Authorize exports in writing | Yes | Requests it | No | No |
| Hold admin credentials | Yes | Under client instruction | No | No |
| Run exports | Approves | Performs if engaged | Agrees the delivery method | No |
| Agree redaction rules | Yes | Implements technical steps | Agrees with the company | No |
| Record the handover | Reviews | Logs actions | Coordinates | No |
| See confidential records | As needed | Only as required | Per agreement | Never |
Where do the files stay?
For big datasets the MSP will usually be asked to keep files inside the client's own environment or to prepare encrypted drives, because SourceX does not host multi-terabyte data. The handover is recorded so the client can show what was delivered. The comparison of encrypted drives and seller-hosted access goes through the trade-offs, and the delivery manifest template shows how to record what moved.
What are the MSP's own limits?
Before the MSP touches a client's data for this purpose, check these.
| Question | Why it matters | Action |
|---|---|---|
| Does the MSP agreement allow work outside the managed scope? | Exports may be a new service | Add a short written statement of work |
| Does the MSP also serve the client's customers? | Their data may be in the same systems | Exclude it unless those customers consent |
| Does the MSP use shared admin accounts? | You cannot prove who did what | Create per-person accounts |
| Does cyber insurance cover this work? | Coverage may differ | Ask the broker |
| Does the MSP hold data for other tenants in the same tools? | Cross-tenant mix-ups | Verify tenant boundaries first |
How to raise it with a client
Timing matters. The easiest moments are the quarterly business review, a system migration or a contract renewal, when the MSP is already discussing records and retention. The guide on recognizing suitable client businesses helps you decide which clients to raise it with, and the managed service provider overview covers the role in more depth.
A similar question comes up for commercial bankers, where the issue is keeping the topic separate from a credit decision. For the MSP, the equivalent is keeping it separate from the service contract.
What if a client asks about everyone who might see the data?
Tell them the access list is the client's to define. Point to the stakeholder objection map and the guide on who outside the company should know. A sponsor's view of reputational risk is useful if the client is private equity backed.
How rewards work for an MSP
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. Rewards become payable only after the buyer pays and SourceX receives its fee, and no reward is guaranteed. The reward is a share of SourceX's fee and is never deducted from what the company receives.
Be open with clients that you may earn a reward if they proceed. Review your client agreements before you register, and read the program terms.
When not to bother
Skip it if the client never reached 50+ full-time employees at peak (contractors excluded) or has no way for its own staff to approve an export. Also skip it if the data in your tools belongs to the client's customers, not the client.
What to say when you make the introduction
Which moments in the MSP calendar work best?
| Moment | Why it fits | Client question to ask |
|---|---|---|
| Quarterly business review | Retention and archives are already on the agenda | Which old systems do you still keep? |
| Platform migration | Old tools are about to be retired | Do we have a complete export before shutdown? |
| Contract renewal | Scope is being reset | Do you want exports added as a project? |
| Security audit | Access lists are being reviewed | Who currently holds admin rights? |
| Acquisition integration | Two sets of archives meet | What happens to the acquired company's records? |
Next step
Choose one client that fits and ask whether the owner would like a short introduction. Register as a partner to make it. The referral FAQ answers process questions.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Can an MSP run the export without telling the client's staff?
No. The MSP should act only on written authorization from the client's sponsor, and the client decides who else is told. Quiet exports also create trust problems if they are discovered later, so agree the communication plan with the sponsor first.
Does the MSP need to see the data to run the export?
Often it can run an export without reading content, but it may need access to systems and staging areas. Limit access to what the task requires, log it and record what was done. Anything sensitive should be handled under the redaction rules the company agreed.
Who holds the encryption keys on shipped drives?
That is part of the handover plan. Keys should be handled separately from the drives and shared only with the people the agreement names. Agree who generates, stores and revokes them before anything ships.
What if the client's customers' data is in the same systems?
Exclude it unless those customers' rights and consents allow it. Data that belongs to someone else without consent is a red flag for qualification. Ask counsel and check the client's contracts first.
Is the MSP liable if something goes wrong?
That depends on your agreements with the client, so define responsibilities in writing before work begins and check your insurance. This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
Related pages
- What should partners never promise a business owner about data privacy?
- Encrypted drives vs seller-hosted access for large dataset delivery
- Delivery manifest template for licensed records
- How MSPs can recognize suitable US client businesses for data licensing
- Referral opportunities for managed service providers
- How can a commercial banker introduce a data licensing opportunity without tying it to credit?
Free resources
- Cash flow calculator — A 12-month cash forecast with shortfalls highlighted.
- Referral earnings calculator — Hypothetical partner earnings with the per-company cap.
- Cash conversion cycle calculator — DIO, DSO, DPO and the cash conversion cycle.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment