AI data market
Selling code and ticket histories from a closed software company
By SourceX Editorial · Updated
Short answer
A closed software company can often license its code and ticket histories to AI developers after four checks: the company owns the code and can still sign, open-source code is separated, customer code and data are excluded, and secrets are removed from the full history. Linked history, from ticket to issue to review to fix, carries most of the value.
Key takeaways
- An AI data license grants use of a prepared copy; the code itself can still be sold separately in an asset sale.
- Ownership depends on employee and contractor assignment agreements, not on who wrote the commits.
- Secrets must be found across every commit and branch, not just the latest version.
- Ticket-to-fix chains are less reproducible than code alone, which makes them central to value.
- Export full repositories and ticket systems before hosting plans and subscriptions lapse.
What a closed software company can actually offer#
A closed software company can offer the record of how its software was built and maintained, not just the final code. The useful families are git repositories with full commit history, pull requests and code review comments, Jira or Linear issues, help desk tickets from Zendesk or Intercom that link to those issues, CI logs, incident postmortems and design notes in Confluence or Notion.
AI developers building coding and support agents value the chain that connects them: a customer report becomes a ticket, the ticket becomes an issue, the issue becomes a pull request, a reviewer pushes back, and a release ships the fix. A code snapshot without that history is far easier to find elsewhere.
This is no longer a hypothetical market. Forbes reported in April 2026 that after cielo24 was closed through the wind-down firm SimpleClosure, its remaining internal chat, project-tracking tickets and emails became items for sale to AI developers, and reported in August 2026 that startups such as SimpleClosure and Sunset now offer to buy wind-down companies' data for AI training.
Founders usually say selling, and some do sell their codebase outright to an acquirer. A license to an AI developer is different: the company, or its estate, keeps ownership and grants use of a prepared copy. The two can happen in sequence, as long as the acquirer of the code knows about any license already granted.
First: confirm ownership and who can sign#
Ownership of the code turns on paperwork, not on who typed it. Employees usually assign inventions and work product through employment or proprietary information agreements; contractors only assign if their contract says so. Code written by founders before incorporation, code inherited from an acquisition and code built by an outsourced agency each need their own check.
Signing authority after a shutdown is a separate question. Depending on whether the company is winding up, dissolved, in an assignment for the benefit of creditors or in bankruptcy, the signer may be the board, a wind-down officer, an assignee or a trustee. A lender's security interest over intellectual property may also require a release or consent.
The four-part checklist before any deal#
The four-part checklist covers the issues that most often shrink or stall a closed company's code package. Work through it with the former CTO or lead engineer, since they know where the exceptions live.
| Check | What to look for | Usual fix |
|---|---|---|
| Ownership | Missing contractor assignments, founder code from before incorporation, acquired modules | Exclude unclear modules or obtain confirmatory assignments |
| Open source | Vendored libraries, forked projects, copied functions, license files | Exclude third-party directories or keep notices and disclose them |
| Customer code and data | Customer-specific forks, integrations built under contracts that give customers ownership, database dumps, test fixtures with real records | Exclude, and confirm any contractual deletion duties were met |
| Secrets | API keys, passwords, tokens, private keys and environment files anywhere in history | Scan every branch, revoke live credentials, exclude or rewrite affected files |
| Personal details | Names and emails in commits, tickets and review comments | De-identify before delivery under the agreed method |
How to find secrets across a full git history#
Secrets have to be found across the full git history, because a key deleted from the current code is still present in every earlier commit. Scan all branches and tags, not only the main branch, and include issue attachments and CI logs, where tokens often appear in pasted output.
Open-source scanners help. Gitleaks is an MIT-licensed tool that detects passwords, API keys and tokens in git repositories and files; its maintainer stated in May 2026 that it is feature complete and will receive security patches only. TruffleHog, an AGPL-3.0 scanner, says it classifies hundreds of secret types and can log in to check whether a found secret is still live, which means it sends real authentication requests and should be run with care.
A closed company has a particular risk here. Its own cloud accounts may be shut, but keys to third-party services can still work. Revoke anything still active before delivery, and remember that automated scanners reduce risk rather than eliminating it, so a human reviews what they flag.
Why ticket histories matter as much as code#
Ticket histories matter as much as code because they explain why the code changed. A pull request that fixes a race condition is more useful for training a coding agent when it comes with the customer's report, the engineer's diagnosis in Jira and the reviewer's comments.
This also affects value under the SourceX Enterprise Data Value Framework. Reproducibility reduces value: public code is abundant, but the private record of decisions, failed attempts and review debates is not. Human-generated signal and domain expertise increase value, and both live mostly in tickets and reviews rather than in the final files.
Preserve before you switch anything off#
Preservation comes before any deal, because a closed company's systems disappear on billing cycles, not on legal timelines. Do these steps while accounts are still active, and note any contractual duty to delete customer data, because that duty still has to be met.
- Mirror-clone every repository with all branches, tags and history, including archived repositories.
- Export pull requests and review comments, which live on the hosting platform rather than in git itself.
- Export Jira or Linear projects with comments, attachments, links and workflow history.
- Export help desk tickets with their links to engineering issues and their resolution fields.
- Write down schema notes: custom fields, status meanings, labels and service names only insiders know.
- Keep exports encrypted, with a short access list and a record of who holds copies.
Illustrative: a closed construction software startup#
Illustrative: a fictional startup built scheduling software for specialty contractors and shut down after its funding ran out. The board named the founder as wind-down officer. Records sat in a GitHub organization, a Jira instance and Intercom, all on monthly plans.
The founder mirrored the repositories and exported Jira and Intercom before cancelling the plans. The checklist found two modules written by a contractor without an assignment clause, a customer-specific integration the customer owned under its contract, and cloud keys committed in early history. The founder excluded the modules and the integration, revoked the keys, and de-identified the tickets.
The resulting package of first-party code, reviews and linked issues was licensed non-exclusively, and the remaining code IP was later sold to an acquirer that took it subject to that license. Both transactions relied on the same ownership file.
How SourceX handles closed-company code#
SourceX runs closed-company code through the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. The first conversation covers metadata only, such as hosting platforms, repository counts, years of history and linked systems, so no code leaves the company before the founder decides to proceed.
The SourceX Evidence Packet documents provenance, licensing rights including assignment gaps and exclusions, permitted use, the privacy record covering de-identification and secrets scanning, and release authorization from the wind-down signer. Large repositories stay in the seller's own storage or ship on encrypted drives.
Frequently asked questions
Does it matter if the product never reached many customers?
Less than founders expect. Engineering history, reviews and design decisions can still be useful even with a small customer base. What matters more is whether the history is linked and whether the code reflects real production work rather than prototypes. Thin ticket history narrows the package but does not end the conversation.
Do former employees need to consent?
Usually the company, not the employee, owns work product under employment agreements, so consent is not typically the issue. Personal details are: names, emails and messages in commits and tickets are normally de-identified. Counsel should confirm the agreements cover everyone whose code is included.
Is a product built mostly on open-source frameworks still licensable?
Yes. Most modern software is built on open-source frameworks. The licensable part is the first-party code, its history and the linked tickets and reviews. Framework code can be left out or referenced through dependency manifests, since buyers can obtain it from public sources.
Can AI developers use code that contains a few customer names in comments?
Not without preparation. Customer names, hostnames and identifiers in comments, test data and logs are removed or replaced during de-identification. If customer-specific logic runs throughout a module, that module is usually excluded rather than cleaned line by line.
Should we license the code before or after selling the IP to an acquirer?
Either order can work if each side knows about the other. Licensing first means the acquirer takes the code subject to a disclosed license. Selling first means the acquirer decides whether to license at all, and the estate gives up that option. Agree the sequence with the signer and counsel so neither deal surprises the other.
Sources
- Forbes reported on April 16, 2026 that after cielo24 was closed through SimpleClosure, its remaining internal chat, project-tracking tickets and emails became items for sale to AI developers. Source
- Forbes reported on August 19, 2026 that startups such as SimpleClosure and Sunset now offer to buy wind-down companies' data for AI training. Source
- Gitleaks is an MIT-licensed tool for detecting secrets such as passwords, API keys and tokens in git repositories, files and stdin. Source
- On May 21, 2026, the gitleaks README was updated to state that Gitleaks is feature complete and that future releases will be security patches only. Source
- TruffleHog, an AGPL-3.0 open-source secret scanner, says it classifies over 800 secret types and can log in to confirm whether a secret is live. Source
Related resources
- InsightRecords written with AI assistance: do they lose value for licensing?
- InsightSelling an MEP engineering firm: what buyers value in 2026
- IndustryBPO & contact centers data
- QuestionDo AI labs buy code?
- QuestionDo AI labs buy medical data?
- InsightCan you license CAD and engineering drawings to AI companies?
See if your company qualifies
A short company assessment. No data uploads are needed.