Software companies
Acqui-hire: what happens to the code and data the acquirer did not take
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
After an acqui-hire, the code and data the acquirer did not take usually stay with the startup entity, which still owns its repositories, issue history, support records and customer data. What it can do with them depends on the deal documents, so check the asset scope, any license to the acquirer and competitor restrictions before selling, licensing or deleting anything.
Key takeaways
- The startup entity survives an acqui-hire and keeps every asset that was not assigned to the acquirer.
- A non-exclusive license to the acquirer usually leaves the startup free to use the code, unless another clause says otherwise.
- Founders who joined the acquirer may be restricted from acting for the old company, so name a wind-down officer.
- Export repositories, Jira, Slack and support history before subscriptions lapse; admin access often sits with people who have left.
What happens to code and data after an acqui-hire?#
Code and data the acquirer did not take stay with the startup entity, which continues to exist until it is formally dissolved. That usually includes repositories and their history, Jira or Linear issues, Slack, Google Workspace or Microsoft 365 accounts, helpdesk records, the domain and customer data.
The startup's board, and any officer still in place, decides what happens next: sell the remaining assets, license them, open-source the code, or archive and delete under the retention policy. Each option is limited by what the acqui-hire documents gave the acquirer and what they promised it.
Agreement terms to check before acting#
The terms to check sit in several documents, not just the main agreement. Gather the asset purchase or IP assignment agreement, any license agreement, the founders' new employment and offer letters, side letters with investors, and the board resolutions that approved the deal.
Read them for what they leave behind as carefully as for what they transfer. A schedule that lists assigned repositories by name, for example, implies that unlisted repositories stayed with the startup.
| Term | Usually found in | Why it matters for leftover assets |
|---|---|---|
| Scope of assigned or purchased IP | Asset purchase or IP assignment agreement | Anything outside the scope still belongs to the startup |
| License granted to the acquirer | License agreement or a schedule | Exclusive licenses can block other uses; non-exclusive ones usually do not |
| Restrictions on transfers to competitors | Main agreement or a side letter | May bar sales or licenses to named companies or categories |
| Confidentiality of acquirer information | Main agreement | Shared roadmaps and diligence materials must stay out of any package |
| Founder non-compete and outside-activity terms | Employment or offer letters | Can limit what founders may do for the old company |
| Investor consent rights and liquidation terms | Charter and investor agreements | Decide who approves asset sales and who receives proceeds |
Who can still act for the startup?#
The people who can act for the startup are its remaining directors and officers, and after an acqui-hire there may be very few. Founders who joined the acquirer often have employment terms that limit outside work or create conflicts when they negotiate on the old company's behalf.
Many startups appoint a wind-down officer, or ask an investor director to take the role, with authority confirmed by board resolution. That person needs admin access to the code host, workspace and helpdesk, which frequently still sits with founders or engineers who have left.
Write down the wind-down officer's authority in plain terms: which accounts they control, what they may sign without further approval, and which decisions go back to the board. Investors and the acquirer will both ask, and a clear resolution answers them once.
Options for the code and data left behind#
The options for leftover code and data range from selling them to deleting them, and several can be combined. Licensing operational records does not transfer ownership, so it can sit alongside a later asset sale if the terms of both allow it.
| Option | Fits when | Watch for |
|---|---|---|
| Sell remaining IP to another buyer | The product still has users or a niche buyer exists | Restrictions in the acqui-hire documents; buyer diligence on code ownership |
| Open-source the code | There is no buyer and goodwill matters | Third-party code, secrets in history, customer-specific code |
| License engineering and support records to AI developers | Repositories, reviews and issues hold years of linked history | Rights review, customer data exclusions, signer authority |
| Archive and delete under retention policy | Nothing has further use | Tax, employment and dispute retention needs |
| Assignment for the benefit of creditors | Debts exceed what remains | Assets then sit with the assignee, who decides |
What to preserve before accounts close#
Preserve complete exports before any subscription lapses, because many vendors limit access or delete data after cancellation. Salesforce's Main Services Agreement, for example, makes customer data available only if requested within 30 days after termination, and Slack does not offer exports of private channels and direct messages on its Free or Pro plans. Keep paying for the tools long enough to export, confirm who holds admin rights, and export into storage the startup controls.
Before any external use, scan the repositories for credentials. Gitleaks, an MIT-licensed secret scanner for git repositories, files and standard input, is one common option; its maintainer has stated it is feature complete and will receive only security patches, so factor that in when choosing a tool.
Record what each export contains and what it leaves out, such as private Slack channels the plan could not export or attachments a tool skipped. A short manifest beside each archive saves the next person from guessing.
- GitHub or GitLab: full clones with all branches and tags, plus pull requests, review comments and issues through the API.
- Jira or Linear: issues, comments, changelogs and attachments.
- Slack: the admin export the plan allows, with a note of what it leaves out.
- Google Workspace or Microsoft 365: mailboxes and shared drives for key roles.
- Zendesk or Intercom: tickets or conversations with internal notes.
- Confluence or Notion: specs, runbooks and postmortems.
Illustrative: a developer tools startup after an acqui-hire#
Illustrative: a fictional developer tools startup building a test automation product is acqui-hired. The acquirer hires the engineering team and takes a non-exclusive license to the codebase; the startup keeps ownership of the code, its review history, the issue tracker and its support conversations.
An investor director is appointed wind-down officer. She reads the agreements and finds no restriction on licensing operational records, but a ban on transferring the code to two named competitors of the acquirer. She keeps the subscriptions running long enough to export everything.
The engineering history, with pull request reviews linked to issues, goes into a metadata fit check. Customer content in support conversations is held back pending a rights review, and the remaining code is offered for sale with the competitor restriction disclosed to bidders.
How SourceX approaches post-acqui-hire records#
SourceX approaches post-acqui-hire records through the same SourceX five-step transaction it uses for operating companies: Supply, Rights, Preparation, Approval and Delivery. The Rights step reads the acqui-hire documents for restrictions, and Approval comes from whoever holds authority to sign for the startup.
The wind-down officer describes systems and history first, without sharing files. If a package proceeds, the SourceX Evidence Packet records who authorized the release and on what authority, which also helps the wind-down officer report decisions to the board and investors.
Frequently asked questions
Can a founder who joined the acquirer sign for the old startup?
Sometimes, but check first. The founder may still be an officer on paper, yet the new employment terms can restrict outside activity or create conflicts. A board resolution naming a wind-down officer, or the acquirer's written consent, removes doubt about who can bind the startup.
Does the acquirer get a say in what we do with leftover assets?
Only to the extent the documents give it one. Look for rights of first refusal, competitor restrictions, exclusivity in any license and confidentiality terms. If the documents are silent, the startup decides, subject to its own board and investor approvals.
Can we license code that the acquirer also has a license to?
Often yes if the acquirer's license is non-exclusive, because a non-exclusive license leaves the owner free to grant others. Exclusive licenses, field-of-use terms or side letters can change that, so have counsel read the license before scoping anything.
What happens to customer data after the acqui-hire?
Customer data stays subject to the startup's customer agreements and privacy commitments. Customers usually need notice and a chance to export before service ends, followed by deletion or return as promised. Customer personal data is generally excluded from any data license unless the rights review confirms otherwise.
Should customers be told about the acqui-hire?
Yes, if the product will stop or change. Customers need to know whether service continues, who supports it and how to export their data if it ends. Check customer agreements for notice and assignment terms, and coordinate the message with the acquirer so the two announcements do not conflict.
Who receives money from licensing leftover assets?
The startup does, and it then flows according to its obligations and charter, with creditors generally paid before shareholders and preferences applied among shareholders. That is why investors often hold consent rights over asset sales and licenses during a wind-down, and why counsel should confirm the distribution.
Sources
- Gitleaks is an MIT-licensed tool for detecting secrets such as passwords, API keys and tokens in git repositories; on May 21, 2026 its README stated it is feature complete and future releases will be security patches only. Source
- Under the Salesforce Main Services Agreement, customer data is made available for export if requested within 30 days after termination; after that SFDC has no obligation to keep it. Source
- Slack does not offer exports of public and private channels plus direct messages on Free or Pro plans. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.