Skip to content

Private equity and portfolios

How VMS holding companies are rethinking data in the AI era

By SourceX Editorial · Updated

Short answer

Vertical market software holding companies are rethinking data by separating customer data stored in their products from the operating records each business creates, such as support tickets and engineering history. Holdcos are leaving data decisions with each business, building shared AI capabilities, acquiring for proprietary records or licensing records out. Contract terms decide which approach is workable.

Key takeaways

  • Customer data stored in a VMS product is usually governed by customer terms, not owned outright by the holdco.
  • Support, implementation and engineering records are the company's own operating history and are often easier to use.
  • Decentralized holdcos make progress with opt-in programs and shared templates rather than central mandates.
  • A data-moat acquisition thesis only holds if the target's customer terms allow the intended use.

How are VMS holding companies rethinking data?#

VMS holding companies are rethinking data by treating the records inside acquired products as something to govern across the group, not just a by-product of running software. For most of the buy-and-hold era, acquirers valued vertical software for recurring revenue, sticky customers and modest capital needs; data was a feature of the product, not a line in the investment case.

Generative AI changed two things at once. Customers now expect AI features in the specialized tools they use every day, and model developers now look for real operating records from specialized industries. Both pull holdco leaders toward the same question: what records do we actually hold across the group, and what are we allowed to do with them?

Four holdco approaches, as of October 2026#

Four broad approaches to data appear across VMS holding companies as of October 2026, and many groups combine them. The table below describes patterns, not any one company's strategy, and is dated because the field is moving quickly.

The decentralized buy-and-hold model, often associated with Constellation Software, leaves the most room for variation between products. Its strength is local judgment by the people who know each customer base; its weakness here is that no one in the group may hold a complete view of what records exist or what the contracts allow.

The data-moat thesis deserves the most scrutiny in diligence. A product can hold years of detailed customer records and still give its owner few rights to use them beyond running the service, so the moat may belong to the customers rather than the acquirer. Reading the customer data, aggregated data and AI clauses before signing is what turns the thesis into a fact.

Four holdco approaches, as of October 2026
ApproachHow it worksWhat it means for records in acquired products
Decentralized ownershipEach business decides its own AI and data plans; the holdco supplies capital and shared practicesRecords stay under each business's control; any AI use or licensing is opt-in, product by product
Shared AI platformA central team builds AI capabilities that businesses plug into their productsRecords flow to group processing; customer contracts must allow the shared use
Data-moat thesisAcquisitions favor products whose records are hard to replicateDiligence must confirm rights to use the records, not just their existence
Outbound licensingSelected businesses license de-identified operating records to model developersRequires a rights review, preparation and approval for each business

The record distinction that decides what is possible#

The distinction that decides what is possible is between customer data stored in the product and the operating records the software company itself creates. A marina's slip reservations and work orders inside a marina management product are usually governed by that customer's agreement; the software company's own support tickets, implementation notes and engineering history are its own records.

The record distinction that decides what is possible
Record typeWho usually controls itTypical posture for AI use
Customer data stored in the productThe customer, under the SaaS agreementRestricted to providing the service unless the terms allow more
Usage and telemetry dataDepends on the usage data clauseOften usable for product improvement; outside licensing needs review
Aggregated or de-identified dataDepends on the aggregated data clauseMay allow analytics; third-party licensing needs specific review
Support tickets and chatsThe software company, with customer content insideCandidate for licensing after de-identification and rights review
Issues, code reviews and releasesThe software company, excluding customer codeCandidate for licensing and internal AI tools
Implementation and onboarding notesThe software companyCandidate once customer confidential details are removed

Why internal operating records come first#

Internal operating records come first in most practical VMS data programs because they carry fewer contractual hurdles than customer data. The company created its support tickets, Jira issues and code reviews while running its business, and those records show how vertical problems actually get diagnosed and fixed.

Those records still need care. A support ticket can quote a customer's configuration or paste a screenshot of customer records, so preparation removes customer and personal details before anything leaves the business. But the starting position is usually clearer than for customer data, where the answer turns on terms written years earlier by previous owners.

What decentralization means for data decisions#

Decentralization means a holdco cannot simply order every business to contribute data. Business leaders own their results and customer relationships, and a program that feels imposed from the center will meet resistance and, often, legitimate customer concerns.

Groups that make progress tend to offer a program rather than a mandate. The center provides contract templates, a review process and a clear description of what qualifies; each business decides whether to take part and keeps approval over anything released.

  • Publish a short description of which record types qualify and which are excluded.
  • Offer shared legal review of customer terms and vendor terms.
  • Agree one preparation standard for removing personal and confidential details.
  • Let each business approve its own release under its normal financial arrangements.
  • Share results across the group so other businesses can judge whether to join.

Five questions a holdco CEO should answer first#

A holdco CEO should answer five questions about the group's records before committing capital to any of these approaches or asking businesses to take part. None of them needs files; each can be answered from metadata and a read of current contracts.

Groups that cannot answer the first question usually find the rest stall too, which is why a simple group-wide inventory tends to come before any platform or licensing decision.

  • Does anyone at group level hold a current list of products, systems and record families?
  • Which products' customer agreements address aggregated data or AI use, and which are silent?
  • Who in each business can approve a release of records, and what does the holdco need to see first?
  • Which products face a help desk, CRM or hosting migration that could cut off older history?
  • How would customers in each vertical react to AI features in the product compared with third-party licensing?

Illustrative: a small VMS group deciding where to start#

Illustrative: a fictional VMS holding company owns many small products, including software for self-storage operators, equipment rental yards and landscaping contractors. Each product runs independently with its own support and engineering teams.

The holdco CEO asks each business leader to answer a short metadata questionnaire. The equipment rental product has years of Intercom conversations linked to Linear issues and release notes, and its customer terms are silent on AI. The self-storage product holds rich customer data, but its terms limit use to providing the service. The landscaping product changed help desks twice and kept little history.

The group pilots outbound licensing of the equipment rental product's support and engineering history, with customer details removed. It plans updated aggregated-data and AI language for the self-storage product's terms at renewal, and leaves the landscaping product out for now.

Where SourceX fits in a VMS group#

SourceX works with the operating business that holds the records, not with the group as a single supplier. Each product that opts in runs its own SourceX five-step transaction, and the SourceX Enterprise Data Value Framework gives the holdco a consistent way to compare products on the same drivers, such as uniqueness, domain expertise, recency, rights and privacy burden, before choosing pilots.

Every released package carries a SourceX Evidence Packet, so the holdco has a dated record of what each business licensed and on what terms. SourceX's rights in a deidentified dataset are set out in the signed supplier agreement, and licensed records remain owned by the business that supplied them.

Frequently asked questions

Can a VMS holdco license customer data from its products?

Only where the customer agreements allow it, and many do not. Most SaaS terms limit use of customer data to providing the service, with separate clauses for usage or aggregated data. The company's own support, implementation and engineering records are usually a more practical starting point.

Does building AI features conflict with licensing records out?

Not necessarily, but the two should be planned together. A broadly drafted exclusive license can restrict the company's own use, and customers may react differently to product features than to third-party licensing. Reserve internal use explicitly in any outbound license.

Should acquisition diligence change because of AI?

Adding a few questions is worthwhile: what customer data clauses say about aggregation and AI, how much support and engineering history exists, whether the target has shared data before and whether recent contract updates added AI promises. The answers affect both product plans and licensing options.

Do business leaders keep control under a group program?

In a decentralized group they should. The center can supply templates and review, but each business decides whether to participate and approves its own release. That keeps customer relationships with the people who manage them every day.

Are small products too small to matter?

Typical fit for licensing is a company with 50+ full-time employees at peak and several years of history, though smaller specialized companies may be reviewed for a specific buyer request. In a VMS group, small products describing the same workflow can also be assessed side by side.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify