Before you wipe the servers: a records checklist for closing companies

Before wiping company servers, a closing company should inventory every device, image or export the records worth keeping, get written sign-off from whoever controls the assets, and only then release hardware to an ITAD vendor or liquidator against destruction certificates. A preliminary fit screen first shows whether the archive could be licensable through SourceX.

Why this checklist exists

When a company closes, hardware is among the first things sold, returned or recycled. Servers, NAS devices, backup appliances and laptops go to an IT asset disposition (ITAD) vendor or a liquidator, and once a drive is wiped or shredded, every record on it is gone. Before wiping company servers, image or export what is worth keeping, get written sign-off, and screen the archive for licensing value.

Mid-size companies often keep more on premises than people expect: file servers with a decade of project folders, a legacy ERP database, an old on-premises mail server, backup sets from systems retired years ago. Those archives can hold the operational history that AI labs and data buyers license through SourceX. They can also hold customer and employee information the company has obligations to protect, which is why authority, retention and destruction need to be decided together.

Two legal points often apply. If the company is a non-bank financial institution under the FTC's Safeguards Rule (the FTC lists examples such as mortgage brokers, finance companies, collection agencies and tax preparation firms), its written information security program covers the customer information on these devices (FTC Safeguards Rule guide). And a business covered by the CCPA must tell California consumers at collection how long it retains their personal information (Cal. Civ. Code 1798.100 et seq.), so check what was promised before deciding what to keep. This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.

The checklist

1. Inventory every device

  • List physical and virtual servers, NAS and SAN units, backup appliances, tape libraries, desktops, laptops, external drives and company phones, including anything in a colocation cage or offsite storage.
  • For each device, note what it holds, the years covered, the last successful backup and who has admin credentials.
  • Record encryption status and locate recovery keys; an image of an encrypted drive without its key is unreadable.
  • Separate leased equipment, which must be returned, from owned equipment, which can be sold.
  • Mark devices of departed employees whose files were never moved to a shared location.

2. Confirm authority and sign-off

  • Identify who controls the assets now: the board or owner, an assignee, a trustee, a receiver or a secured lender.
  • Ask counsel about litigation holds, regulatory retention periods and tax record requirements before anything is wiped.
  • Check whether a lender holds a security interest in the equipment or the data on it.
  • Get written approval of the wipe list from the person in control, listing devices by serial number.

3. Image or export before release

  • Take full images or complete exports of file servers, databases (with schema) and on-premises mail servers.
  • Keep backup catalogs and a working copy of the software needed to read proprietary backup formats.
  • Record hash values and file or record counts for each image, and keep a chain-of-custody log.
  • Store images in two company-controlled locations with documented access.

4. Screen for licensable archives

  • Run the company fit checker: 50+ full-time employees at peak (contractors excluded), several years of documented operations, rights to license and an authorized sponsor.
  • Tag each archive as the company's own operational records, client-owned material, or mainly consumer personal data or PHI.
  • Hold archives that could be licensable out of the destruction schedule until the review is done.

5. Release the hardware

  • Use an ITAD contract that specifies the method (overwrite, degauss or shred) and serial-level certificates of destruction.
  • Reconcile certificates against the inventory, serial by serial.
  • File the certificates with the company's closing records.

Cloud tools need the same discipline: the companion checklist export before you cancel covers SaaS subscriptions, and the guide to company email archives when closing a business covers mailboxes in more depth.

How to use the results

ResultWhat it meansNext action
Archive imaged, authority confirmed, fit screen positiveA licensing review is worth startingIntroduce the company to SourceX before the hardware leaves
Archive imaged but authority unclearNo one can approve a license yetResolve control (board, assignee, trustee) first
Archive mainly client-owned or PHIUnlikely to be licensableFollow the destruction plan once retention duties are met
Recovery keys missingEncrypted images are unusableRecover keys from the identity or device management console before wiping
Backups in a proprietary format with a lapsing software licenseData becomes unreadable when the license endsRestore and export to open formats now
No archive worth keepingNothing to licenseWipe, certify and close the item

Red flags that stop a licensing review

  • The file shares hold work the company did for its own clients, and those clients never agreed to any reuse.
  • Most of what sits on the drives is information about consumers or patients, with no consent, authorization or de-identification behind it.
  • The assignee, trustee or receiver now in charge has not been told about the archive.
  • An earlier AI-training license already covers the same material.
  • No remaining officer or fiduciary is able to approve a license, and no one can read the backups.

Ownership questions for each system are easier to settle with the system ownership checklist. For background on what usually happens to records after closure, see what happens to company data when a business closes.

How partners fit in

Partners make the introduction and share basic fit information, such as device types, years covered and peak headcount; the full baseline is on who qualifies. They never take custody of drives or images, and they never describe confidential contents. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, and the reward becomes payable only after the buyer pays and SourceX receives its fee.

Next step

Put the inventory and sign-off steps in front of whoever controls the assets before the ITAD pickup is booked. If an archive passes the screen, register as a partner and introduce the company while the data still exists.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Should we image the laptops of employees who already left?

Yes, if their files were never moved to a shared drive or mailbox archive. Departed staff laptops often hold the only copy of local project folders, exported reports and offline email. Image them before they go to the ITAD vendor, record the user and date range, and store the images with the server images under the same chain-of-custody log.

Is a certificate of destruction enough to prove data is gone?

It documents what the vendor says it did, so its value depends on matching it to your inventory. Ask for serial-level certificates that state the method and date for each device, reconcile them against your device list, and follow up on any serial that is missing. File the reconciled certificates with the closing records in case questions come later.

Can we sell the hardware and still keep the data?

Yes, and that is the usual way to keep both values. Image or export the drives first, verify the images, then have the devices wiped and sold or recycled. The data stays in company-controlled storage for retention and a possible licensing review, while the liquidator or ITAD vendor recovers what the hardware itself is worth.

Who pays for imaging when the company is short of cash?

Whoever controls the assets decides, weighing the cost against what the archive could be worth. A preliminary fit screen helps make that call before anyone spends money. If a license goes ahead, the company is quoted a single all-in price that already covers SourceX's fee, with nothing billed on top, so imaging is an outlay the company decides on with its own advisers.

Can the referring partner take the drives for safekeeping?

No. Partners make introductions only and never take custody of drives, images or exports. Media stays under the control of the company or the fiduciary in charge, held by the company's IT provider or a storage vendor it contracts with. Nothing reaches a buyer unless the company has signed a license, approved delivery and settled the redaction rules beforehand.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment