Skip to content

Wind-downs and transitions

Startup shutdown checklist: the data and records steps most guides miss

By SourceX Editorial · Updated

Short answer

A startup shutdown checklist should handle company data in a fixed order: inventory every system, decide on a legal hold, export and verify, assess what to keep or license, and only then cancel subscriptions and delete. Many founder guides cover cancelling tools but skip the inventory and assessment steps, which cannot be done once accounts close.

Key takeaways

  • Data steps run in a fixed order: inventory, legal hold, export, assess, then cancel and delete.
  • The systems inventory should name an admin owner and a billing owner for every tool.
  • A legal hold, where claims are possible, overrides deletion schedules and cancellation plans.
  • An export is not finished until counts, dates and attachments are checked against the live system.
  • Identity and email accounts close last, because every other export and login depends on them.

Where data fits in a startup shutdown#

Data fits into a startup shutdown alongside the steps every guide lists, from the board vote to the final tax return. Each standard step has a records task attached to it, and that task is the one that tends to be skipped.

Run the data steps in parallel with the legal and financial ones, not after them. By the time the dissolution filing is ready, most of the people who know where records live have already left.

Where data fits in a startup shutdown
Standard shutdown stepRecords task that goes with it
Board approval to wind downName a records custodian and give that person authority over every system
Notifying employees and ending employmentCollect admin credentials and keep key people available to explain systems
Notifying customers and ending contractsList return-or-delete obligations and any data handover promised
Paying creditors and settling claimsPreserve records relevant to disputes, warranties and collections
Final tax returns and dissolution filingKeep financial, payroll and corporate records for their required periods
Cancelling vendors and subscriptionsExport, verify and assess each system before it closes

Step 1: build a systems inventory#

The systems inventory lists every tool that holds company records, who administers it, who pays for it and how its data comes out. Start from the finance side: card statements and expense reports reveal tools that nobody on the engineering team knew about.

Keep the inventory in one shared spreadsheet owned by the custodian. Every later step, from the hold to the final deletion, updates the same row.

  • System name and purpose, such as Slack for chat, HubSpot for CRM, Intercom for support, Linear and GitHub for engineering.
  • Admin owner with working credentials, plus a backup admin.
  • Billing owner, renewal date and what the vendor does with data on cancellation.
  • Record families held and approximate years of history.
  • Export method: built-in export, API, vendor request or a third-party tool.
  • Known restrictions: customer data, personal data, privileged material.

A legal hold preserves records that may matter to a dispute, and it overrides any plan to delete. A hold is worth considering whenever there is threatened litigation, an employee claim, a customer dispute, a regulatory inquiry or a contested creditor position.

Counsel defines the scope: which custodians, systems and date ranges. Once a hold applies, suspend automated retention rules in tools such as Google Workspace or Microsoft 365, and do not cancel affected systems until their records are preserved in a defensible form.

Put the hold in writing. A short notice to the people who still hold records, naming the systems and date ranges covered, shows the hold was real if anyone later asks. Keep a copy with the systems inventory so the custodian knows which rows cannot be cancelled yet.

Step 3: export and verify#

Exporting and verifying means proving that each export matches the live system before the system closes. A ZIP file that downloaded without errors is not proof that anything inside it is complete.

Some exports need a vendor request or a higher plan, and some arrive well after they are requested. Start the slow ones first and keep those subscriptions active until the files are in hand.

  • Compare record counts, such as tickets, issues, deals or messages, between the export and the live account.
  • Check the earliest and latest dates in the export.
  • Confirm attachments and files are included, not just links to them.
  • Open a sample of records and read them end to end.
  • Store two copies in company-controlled, encrypted storage with an access log.

Step 4: assess before you delete#

Assessing before deletion sorts every export into records to keep for legal and tax reasons, records worth evaluating for licensing, and records to return or delete. Doing this before cancellation keeps open the option to license operating history, which can be one of the few assets a closed software company still has.

Step 4: assess before you delete
CategoryExamplesDefault action
Required retentionFinancial records, payroll, corporate minutes, contractsKeep for the periods counsel and the accountant set
Possible licensing valueSupport tickets, engineering issues and code reviews, CRM activityKeep pending a metadata assessment
Customer-owned or restrictedCustomer uploads, data covered by return-or-delete clausesReturn or delete as the contracts require
Low value, high sensitivityDirect messages, HR files beyond legal retention, personal foldersDelete once retention and hold duties end

Step 5: cancel and delete in the right order#

Cancelling and deleting in the right order prevents losing access to systems that still hold unexported records. The order runs from tools with no dependencies toward the identity layer that everything else logs in through.

  • Cancel tools whose exports are verified and assessed.
  • Keep any system under a legal hold active until counsel confirms its records are preserved; downgrading a plan can hide or remove older history.
  • Request and file deletion confirmations from vendors that offer them.
  • Close the single sign-on provider and email last, after confirming no remaining system uses them for login or recovery.
  • Record the final state: what was kept, where, by whom and until when.

Illustrative: a construction software startup closes its stack#

Illustrative: a fictional construction scheduling software company that grew to more than fifty employees decides to close. The founder starts from a generic shutdown guide and plans to cancel Intercom first to stop its fees.

The systems inventory, built from card statements, shows that Intercom holds several years of support conversations linked to Linear issues, and that a sales tool paid for on a personal card holds call notes. A former employee has a pending wage claim, so counsel places a hold on HR records and the founder's mailbox.

The team exports and verifies Intercom, Linear, GitHub and HubSpot, keeps the support and engineering history for assessment, exports the sales tool's notes for retention and then deletes its data, and closes Google Workspace last. The custodian signs off the inventory with a keep-until date on every row.

How SourceX fits into a shutdown#

SourceX fits into step 4. A metadata-only fit check, the first part of the SourceX five-step transaction, tells a founder whether exported records are worth keeping for a possible license before anything is deleted. No files are shared during the assessment.

If a package proceeds, the company keeps ownership, approves every step and receives a SourceX Evidence Packet documenting provenance, licensing rights, permitted use, the privacy record and release authorization.

Frequently asked questions

How long should a closed startup keep its records?

It depends on the record type and the laws that apply. Tax, payroll, employment and corporate records each have their own minimum periods, and contracts may add others. A retention schedule by record type, reviewed by your accountant and counsel, gives each export a keep-until date.

Who should own the data checklist?

One named custodian, approved by the board, with authority over every system and a budget to keep subscriptions alive during exports. Often it is the CEO, the COO or a wind-down officer, supported by a former engineer who knows how the systems fit together.

Can we just delete everything to reduce risk?

Not safely. Deleting records under a legal hold or a retention duty can create liability, and customer contracts may require return rather than deletion. Deleting everything also gives up any later option to license operating history. Delete deliberately, by category, after the assessment.

What if investors or a lender want the data?

Investors and lenders do not own company records just because they funded the company, but a lender may hold a security interest in assets that include data, and investor agreements may require consent for asset transfers. Check those documents before any sale or license, and involve them early if approval is needed.

Do customer contracts still apply after the company closes?

Obligations such as confidentiality and return-or-delete clauses often survive termination. The entity stays responsible for them during the wind-down, so the checklist should list each customer's terms and record how each one was met.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify