Skip to content

Wind-downs and transitions

Chapter 7 trustee's guide to a debtor's cloud accounts and SaaS records

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A Chapter 7 trustee should treat a debtor's cloud accounts as estate assets at risk of deletion. In the first month, secure administrator access, stop automated deletion and vendor shutdowns, inventory every SaaS system and the records it holds, then decide which records to keep, abandon, destroy or offer for value. Unpaid subscriptions are the main threat.

Key takeaways

  • Unpaid SaaS subscriptions are the fastest way a debtor's records disappear after a filing.
  • Secure the domain registrar first, because control of the domain often decides control of email and admin recovery.
  • Pause retention and auto-deletion rules inside each system before exporting anything.
  • Inventory by system, recording the admin, billing status, record families and export route for each.
  • Licensing operational records is one route to value, alongside sale, abandonment and secure destruction.

Are a debtor's cloud accounts part of the estate?#

A debtor's cloud accounts are generally part of the estate to the extent the debtor held contract rights in the subscriptions and owned the records stored in them. The vendor owns its software, and its terms govern access, suspension and deletion, but the business records inside the account are typically the debtor's property.

Separate company accounts from personal ones early. Founders and managers often ran company work through personal Gmail, Dropbox or phone backups, and company records held there may need a turnover request through counsel rather than a password reset.

Counsel can advise whether the automatic stay or other provisions affect a vendor's ability to suspend or delete data. In practice, a prompt written request to each vendor, with the trustee's appointment documents attached, is the fastest protection.

First-month checklist: secure, stop deletion, inventory, value#

The first-month checklist runs in four stages, and the order matters because each stage protects the next. Do not export or cancel anything until the access and deletion steps are done.

Expect the stages to overlap. Vendors answer preservation requests at different speeds, so keep the inventory moving while requests are pending, but hold every export and cancellation until that system's access and deletion steps are confirmed.

  • Secure: take control of the domain registrar and DNS, the primary email tenant, the cloud hosting account and any password manager.
  • Secure: remove former employees' access, rotate shared credentials and log every admin change with the date and reason.
  • Stop deletion: write to each vendor with appointment documents and ask that the account be preserved or moved to a minimum or read-only tier.
  • Stop deletion: pause retention policies, auto-archive rules, inactive-user cleanup and scheduled purges inside each system.
  • Inventory: list every system with its admin, billing status, record families, years of history and export route.
  • Value: flag records needed for claims, taxes and litigation, then screen the rest for sale, license, abandonment or destruction.

How to regain admin access when the debtor's team is gone#

Admin access usually comes back through one of a few routes, and the domain is often the key. Many workspace vendors offer an admin recovery process that relies on proving control of the company's domain, so securing the registrar account comes first; check each vendor's documentation for its exact steps.

Keep a written access log from the first day. Each entry should name the system, the route used, who now holds the credentials and what changed, because creditors and the court may later ask how the trustee came to control each account.

How to regain admin access when the debtor's team is gone
SituationUsual route to access
A cooperative former adminSupervised handover, then rotate credentials and remove that person's access
No known admin for email or the productivity suiteProve domain control at the registrar, then follow the vendor's admin recovery process
Admin login tied to a personal phone for multifactor authenticationVendor support with trustee documentation, or cooperation from the former employee
Account suspended for nonpaymentVendor billing team; consider paying for preservation if the records benefit the estate
Systems run by a managed IT providerWritten request with appointment documents; expect questions about unpaid invoices
Company data in a principal's personal accountTurnover request through counsel

Which settings delete records automatically#

Automated deletion settings keep running after a business stops, and they are easy to miss because nobody is watching the admin console. Check each of these before any export starts.

Document each setting as you find it, with a screenshot and the date you changed it. That record helps if a creditor later asks why some records survived and others did not.

Vendor terms add their own clocks. The examples in the table come from dated vendor documentation and change over time, so confirm each against the vendor's current terms and treat the earliest possible date as the deadline.

  • Email retention and deletion policies in the email tenant.
  • Message retention settings in Slack or Microsoft Teams.
  • Ticket deletion or archiving rules in the help desk.
  • Inactive-user cleanup that removes a departed employee's files.
  • Storage lifecycle rules in cloud hosting buckets that expire old objects.
  • Plan downgrades that cap history or remove features when a paid tier lapses.
Which settings delete records automatically
VendorWhat its documentation saysWhat the trustee should do
ZendeskClosed tickets archive automatically 120 days after closing and drop out of views, though search and the API still reach them; after cancellation, account data is deleted under its deletion policyExport through the API or a full export rather than a view, and keep the account until the export is verified
Atlassian (Jira, Confluence)Its August 2023 data processing addendum describes paid accounts deactivating within 15 or 17 days after the subscription ends, deactivated paid-plan data kept 60 days, then a 30-day archive after deletionCheck the current addendum and export issues and pages before the subscription period ends
monday.comKeeps data after cancellation by default but does not guarantee it indefinitely and may delete data from inactive accountsExport boards before closing; a fully deleted account cannot be restored
ZoomAdvises downloading cloud recordings before cancellation; reactivating within 30 days can restore accessDownload recordings before any downgrade or cancellation
AsanaEnterprise retention policies can delete inactive data, with a 30-day undelete windowCheck whether a policy is configured and pause it before exporting

Inventory and value: which SaaS records matter#

SaaS records matter to the estate for three reasons: proving or defending claims, meeting tax and employee obligations, and possible value in a sale or license. One system can serve all three, so record the purpose on each inventory row.

Avoid overstating value at this stage. Licensing value is known only once a buyer engages, so the screen should simply sort records into candidates and non-candidates before any motion is drafted.

Inventory and value: which SaaS records matter
SystemRecordsEstate usePossible value
Accounting or ERP, such as QuickBooks Online or NetSuiteLedgers, invoices, payments, ordersClaims review, avoidance actions, taxesOrder and exception history in ERP modules
CRM, such as Salesforce or HubSpotAccounts, opportunities, activity notesReceivables follow-up, customer claimsSales process history with personal details removed
Help desk, such as Zendesk or FreshdeskTickets, macros, satisfaction ratingsWarranty and customer claimsSupport conversations linked to outcomes
Engineering, such as Jira or GitHubIssues, code reviews, releasesDiligence for a sale of the IPEngineering workflows, unless sold with the code
Email and chatMailboxes, channels, shared filesInvestigation and litigationLimited, given privilege and personal data
Payroll and HRPay records, personnel filesEmployee claims and tax filingsNone; keep, then destroy securely

Illustrative: a trustee secures a closed distributor's systems#

Illustrative: a fictional regional industrial distributor converts to Chapter 7 after its lender stops funding. The trustee finds NetSuite, Zendesk, Microsoft 365 and Samsara fleet telematics, all billed to a corporate card that is now declined, and the only admin was a controller who left before the filing.

The trustee secures the domain registrar, uses it to recover Microsoft 365 admin access, and writes to NetSuite and Zendesk with appointment documents asking for preservation. Retention policies are paused and full exports are verified on a separate machine.

Driver location data from Samsara is kept only as needed for claims and excluded from any value screen. NetSuite order exceptions and Zendesk tickets, which link customer problems to credits and substitutions, are flagged for a metadata-only licensing assessment before the trustee decides whether to sell, license or abandon them.

How SourceX supports trustees#

SourceX gives trustees a metadata-only fit check on operational records, run before any decision to abandon or destroy them. The trustee shares system names, years of history and record families, and no files leave the estate at that stage.

If records proceed, the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery runs with the trustee as approver and any required court order recorded as release authorization in the SourceX Evidence Packet. Large exports stay in storage the trustee controls or ship on encrypted drives.

Frequently asked questions

Should the trustee keep paying the debtor's SaaS subscriptions?

Only where the estate benefits. Paying for a minimum or read-only tier while exports are verified is often cheaper than trying to recover lost records later. Once exports are complete and checked, cancel the subscriptions the estate no longer needs and document each cancellation.

Can the trustee read former employees' email?

Company mailboxes are generally business records the trustee can review, but they may contain privileged communications and personal content. Agree on a review protocol with counsel, limit who reads what, and handle personal messages with care.

What if the debtor is a SaaS company holding its customers' data?

Data that customers stored in the debtor's platform is usually governed by those customers' contracts, which often require return or deletion at termination. Treat it separately from the debtor's own operating records and plan return or deletion with counsel.

Is a vendor's own backup enough to protect the records?

No. Vendor backups exist to restore the service, not to give the estate a copy, and they end with the account. Make your own export, confirm it opens and includes attachments and metadata, and store it under the trustee's control.

Does licensing estate records need court approval?

A license outside the ordinary course generally requires notice and court approval, often through a motion similar to a sale motion. Counsel decides the right procedure, so build that step into the plan before discussing terms with any buyer.

Sources

  • Zendesk archives tickets 120 days after they are closed; archived tickets remain reachable by search, direct link and API but do not appear in views. Source
  • Once a Zendesk account is cancelled, the account data is deleted under the Service Data Deletion Policy. Source
  • Atlassian's August 2023 DPA: paid accounts deactivate within 15 (monthly) or 17 (annual) days after the subscription ends, paid-plan data is retained 60 days, and an archive is kept 30 more days after deletion. Source
  • monday.com keeps data after cancellation by default but cannot guarantee it indefinitely and may delete data from inactive accounts. Source
  • Zoom advises downloading cloud recordings before cancellation and allows regaining access by reactivating within 30 days. Source
  • Asana retention policies can delete inactive data, which can be undeleted within 30 days before permanent deletion. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify