Selling a software company: separating customer data from licensable internal records

In a software company sale, data customers put into the product is governed by their contracts and the company's privacy promises, and is usually not licensable for AI training. Internal records the company created itself, such as code reviews, issue histories, incident reviews and support playbooks, may be licensable through SourceX, before or after closing, if contracts allow.

The short answer for software M&A advisors

Separate the two before anyone talks about value. Customer data, meaning whatever customers upload, type or generate inside the product, is governed by the master subscription agreement, the data processing addendum and the privacy promises the company made. Absent clear contractual permission, treat it as off the table for AI training.

Internal records the company created to build and run itself are different. Employee-written code and its review history, issue trackers, incident postmortems, architecture decisions and support playbooks may be licensable, subject to contracts, contractor terms and redaction.

The split matters because AI labs and data buyers want the internal side. Agents that write and review code, triage tickets or run incident response learn from records of how real engineering and support teams worked, step by step and with outcomes. A software company with years of that history may hold an asset the sale process never prices. It depends on the contracts, so treat what follows as a framework for questions to counsel, not a conclusion.

What the law and regulators say about ownership and promises

Four points from primary sources shape the analysis.

  • Employee work belongs to the company. The US Copyright Office's Circular 30 on works made for hire explains that work an employee prepares within the scope of employment is a work made for hire, so the employer is the author and owner. The statutory definition sits in 17 U.S.C. section 101.
  • Contractor work does not follow automatically. Under the same definition, commissioned work is made for hire only in listed categories and with a signed written agreement. Code from freelancers or outsourced teams belongs to the company only if a written assignment says so.
  • Rights can be split. 17 U.S.C. section 201 lets ownership be transferred in whole or in part, and lets any exclusive right be transferred and owned separately. That is the basis for licensing a defined set of records for AI training while the company, or its buyer, keeps everything else.
  • Customer promises are enforceable. FTC staff have written that commitments not to use customer data for undisclosed purposes, such as training models, are enforceable wherever they appear, including privacy policies, terms of service and marketing. A separate staff post warns that quietly changing terms to allow AI training after the fact may be unfair or deceptive. Both are staff guidance, not rules.

Copyright is only one layer. Contracts, privacy law and confidentiality duties can still restrict records the company owns outright.

Which records sit on which side of the line

Use this table in the first diligence pass. Each row is a starting assumption to test against the actual contracts.

Record classWho usually controls itStarting assumptionWhat to check
Content customers upload or create in the productThe customer, under the MSA and DPAOut of scopeData clauses, DPA purpose limits, privacy policy history
Usage telemetry and aggregated metricsDepends on the aggregated-data clauseCase by caseWhether de-identified or aggregated use is allowed, and for what purpose
Source code and commit history written by employeesThe company, as work made for hireCandidateOpen-source obligations, third-party code, customer-specific forks
Pull request reviews, design docs, architecture decision recordsThe companyStrong candidateEmbedded secrets, credentials, customer names
Issue tracker and sprint historyThe company, though tickets may quote customersCandidate with redactionCustomer-identifying details in descriptions and comments
Support tickets and macrosMixed: company process, customer contentCase by caseContract terms, personal data, redaction rules
Incident postmortems and on-call runbooksThe companyStrong candidateCustomer identifiers and security details
Code from contractors or offshore teamsThe contractor unless assignedHold until confirmedA signed IP assignment in each contractor agreement
Licensed third-party materialThe third partyOut of scopeThe license terms

The guide on telling company data apart from customer-owned data works through the gray rows, and the page on how long companies keep support tickets explains why ticket depth matters.

How deal timing changes who decides

The same records can be licensed before a process starts, carved out in the deal, or licensed by the buyer after closing. What changes is who signs and who must be told.

Deal stageWho decidesWhat to watch
Before a teaser or CIM goes outThe seller's owners and boardAny license must be disclosed in diligence; exclusivity terms may matter to strategic buyers
After an LOI, before signingThe seller, with the buyer watchingLOI exclusivity covers the sale itself, but a material new contract changes what the buyer is pricing; tell the buyer and ask deal counsel
Between signing and closingThe seller, bound by the purchase agreementInterim operating covenants often require buyer consent for contracts outside the ordinary course
Asset sale with excluded assetsWhoever ends up owning each record setWhether records are purchased or retained, and how transition access works
After closingThe buyer's leadershipIntegration plans that may retire the systems holding the history
Product sunset or wind-downThe owner, or a fiduciary if the company is insolventExports taken before systems are shut down

If a license already exists, the guide on disclosing a data license in due diligence covers how buyers usually ask about it.

A five-step separation process before any introduction

  1. Map systems by record class. List the product database, code hosting, issue tracker, support desk, CRM, chat and document tools, with years of history for each. Describe them; do not export anything.
  2. Pull the contract stack. Collect the standard MSA, DPA and order form templates, plus any negotiated enterprise terms with unusual data clauses.
  3. Trace privacy promises over time. Check what the privacy policy and terms said in each period the records cover, not only today.
  4. Confirm contractor assignments. Identify every outsourced or freelance engineering relationship and whether signed IP assignment language exists.
  5. Settle redaction rules first. De-identification and redaction requirements are agreed with the company before any work begins, and records leave only under an executed agreement the company has authorized.

The sponsor for a SourceX introduction is the owner, CEO, CFO or another authorized representative. On fit, the company needs to be based in the US, with 50+ full-time employees at peak (contractors excluded), a documented track record of several years and clear rights to whatever it would license. The who qualifies page has the detail.

Securities questions advisers ask

Registered M&A professionals sometimes ask whether a data-licensing introduction fits within their broker status. The M&A broker exemption in Exchange Act section 15(b)(13) is narrow: it concerns brokers effecting securities transactions solely in connection with transferring ownership of an eligible privately held company within the statute's size limits. It does not address data-licensing introductions, so do not rely on it in either direction. Ask your firm's compliance counsel how referral income from a commercial introduction should be treated and disclosed.

What sell-side advisers can tell the client

The M&A advisor partner page shows where this fits across a mandate, and the page on security risks owners raise helps with the objections that usually follow.

Rewards and disclosure for advisers

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. A reward is payable only after the buyer pays and SourceX receives its fee, it is never deducted from what the client receives, and no reward is guaranteed. Tell the client about the referral relationship in writing, and check your engagement letter for terms that limit outside compensation or define which transactions earn a success fee.

This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.

Next step

Run the record-class table on one current software mandate. If the internal side looks deep and the contracts look workable, register as a partner and introduce the owner, or have the CEO apply at sourcex.si/apply using your referral link.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Can a SaaS company license anonymized customer usage data instead?

Sometimes, but only if the customer contracts allow it. Many agreements include an aggregated or de-identified data clause, and its exact wording decides whether AI training is a permitted use. The privacy promises in force when the data was collected matter too. Treat it as a separate question from internal records, get counsel's reading of the clause, and expect buyers to ask for the contract language.

Does the buyer of the software company get the internal records too?

In a stock sale the records stay with the company, which the buyer now owns. In an asset sale the purchase agreement lists which assets transfer and which are excluded, and records normally follow the business unless they are carved out. If the seller wants to license records separately, the deal documents need to say so, and the buyer will want to know about any exclusive AI-training license.

Would a data license reduce the company's value in a sale?

It depends on the buyer. An exclusive AI-training license for an agreed term limits what the company can do with that record set during the term, which a strategic buyer may care about. Another buyer may see a completed license as evidence that the records have value. Disclose it early, share the scope and term, and let the client's advisers model it alongside the sale.

Are open-source components in the codebase a problem for licensing?

They need review rather than panic. Code the company's employees wrote is generally company-owned, but repositories also contain third-party and open-source code under their own licenses. Buyers and counsel typically want the company's own code, reviews and discussions separated from vendored libraries, with license obligations checked. That review belongs in the inventory and redaction work agreed before anything is delivered.

Can the M&A advisor run the data licensing process instead of SourceX?

As a referral partner, the advisor makes the introduction and gives basic fit information only, and never exports, uploads or describes confidential records. The licensing work itself, from inventory and rights review to buyer review, contracting and delivery, runs between the company and SourceX. The client can keep its advisers informed so the timing of a license fits the sale process.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment