Archive first, decide second. Archiving is the right move on the day a product ends, because it freezes the code and keeps the history intact. But leaving it archived indefinitely is not a neutral choice: secrets go unrotated, the people who understood the code move on, and the company that owns it may not exist in a few years. If the product is truly finished and the code is your team’s own work, a sale usually beats an open-ended archive.
Archiving is a pause button, not an exit
On GitHub, you can archive a repository “to make it read-only for all users.” Issues, pull requests, code, wiki, releases and commits all become read-only, and “you can also unarchive repositories that have been archived.” Nothing is lost and nothing is decided. Two details catch people out: archiving a public repository leaves it public, and it changes nobody’s access. It only stops new changes.
A sale is a decision. Odys AI Labs, the research and development arm of Odys, buys the source code of software that is no longer used, for cash, and uses it for AI training and R&D. The deal is one agreed price, paid on transfer, after a review based on what you tell us. Once it is done, the code is no longer a line on your list of things to look after.
The archive and the sale, line by line
| What you care about | Leave it archived | Sell it |
|---|---|---|
| Cost | Little or nothing in fees, but someone has to keep an eye on it | No fees; we help with cleaning |
| Cash | None | One agreed price, paid on transfer |
| Reversible | Yes, unarchive at any time | No, once signed and transferred |
| Secrets in the code | Still there until someone removes them | Removed before transfer, with our help |
| Who still has access | Everyone who had it, including ex-staff | Set by the written agreement; never published |
| Knowledge of how it works | Fades as people leave | Captured in history, docs and tickets at the moment of sale |
| If the company dissolves | The code goes wherever company assets go | Already sold; no loose end |
| Effort today | A few clicks | A form, a call, a written agreement |
What an archive quietly costs
The cost of an archived repository is not the hosting. It is everything that keeps happening around it while nobody looks.
Secrets stay live. GitGuardian’s 2026 report found that 32.2% of internal repositories contain at least one hardcoded secret, against 5.6% of public ones. An archived private repository is usually an old internal one, so the odds are not in its favor. Archiving makes the code read-only, but it does nothing to a cloud key sitting in a config file.
Access lists grow stale. Former employees, contractors and agencies who were added years ago often still have read access. Read access is enough to clone everything.
Dependencies age. Black Duck’s 2026 open source report found that 92% of audited codebases contain components four or more years out of date. An archive does not fix that, and every year makes a restart harder, which weakens the main reason for keeping the code “just in case.”
Ownership drifts. Code belongs to whoever holds the rights: usually the company. If that company is dissolved, the code goes with it. In the UK, Companies Act 2006 s.1012 makes anything a dissolved company still owns bona vacantia, property of the Crown. Founders often discover this only when they want the code back. UK directors or members can generally apply to restore a dissolved company within 6 years, which brings its assets back; otherwise the Crown’s Bona Vacantia team may sell the IP, but there is no guarantee you will be offered it. Our guide to selling code when a company is dissolved or in liquidation explains the options. This is general information, not legal advice.
When leaving it archived wins
Keep the archive, and do not sell yet, if any of these apply:
- You have a concrete plan to restart. A named person, a date and a reason the original problem is now solvable. A vague “maybe one day” does not count.
- The code still earns money somewhere. If an old customer still pays for a self-hosted version, it is a running product, and we do not buy software that still makes money.
- You are not sure who owns it. If contractor code was never assigned in writing, or a co-founder dispute is open, freeze it and sort out the rights first.
- A legal hold or contract requires you to keep it. Litigation, an audit or a client agreement can oblige you to preserve code exactly as it is.
- Parts of it are still in use internally. A shared login service or billing module that other products depend on is not retired yet.
When selling wins
Sell when the product is over and nobody is coming back to it. That is the typical situation for a shut-down startup, a side project that ran its course or a retired product inside a larger company.
Selling wins most clearly when the archive is still in good shape: full git history, tickets that can be exported, docs and tests. Those are the things that fade first. A codebase sold while someone still remembers why things were built a certain way is easier to describe on a call and easier to clean properly. Our page on what companies can do with the code of retired products covers who usually signs inside a company.
It also wins when you want the loose end closed. After transfer, the access list and the “what if” stop being your problem. Keys that ever sat in the code should already be rotated by then, because a sale does not revoke a credential that leaked years ago.
A one-hour checklist before you archive
Archiving is only useful if what you freeze is complete and safe. Before you click the button, spend an hour on this:
- Find every repository. Products often span several: the web app, the mobile app, the API, infrastructure scripts, a design system. List them all.
- Check the history is really there. Run git log on a fresh clone and confirm it goes back to the first commits, not just a final squashed import.
- Export what lives outside the code. Ticket systems such as Jira, Linear and GitHub Issues, wikis and design files are often cancelled with the subscription. Export them now.
- Rotate credentials. Any key that ever appeared in a .env file, config file or commit should be revoked or rotated, archived or not.
- Review access. Remove former staff, contractors and agencies who no longer need to read the code.
- Write down who owns it. Note which company holds the rights and who can sign for it. Heirs, liquidators and future you will thank you.
Can you do both?
Yes, and in this order it works well. Archive the repository now so nothing changes or disappears. Then, when you are ready, ask for an offer. Archived code can be sold, and GitHub lets you transfer a repository to another account with its issues and pull requests, which keeps the history intact.
The only part that does not combine is keeping a working copy after a sale “just in case.” What happens to your copies after transfer is set in the written agreement, and you should read that clause before signing.
Which to choose
A plain rule:
- If you can name a person and a date for a restart, keep it archived and put the date in your calendar.
- If the code still earns money or its ownership is in doubt, keep it archived and fix that first.
- If neither applies, archive it today and ask for an offer this month. The archive protects the code while you decide; the offer tells you what waiting is costing.
What to do next
- Archive every repository of the ended product and review who still has access.
- Rotate any key you can find in config files, .env files or the history.
- While the people who know the code are still reachable, tell us about the product for a free code valuation.
Frequently asked questions
Does archiving a GitHub repository delete anything?
No. Archiving makes the repository read-only for everyone, including its issues, pull requests, wiki, releases and commits, but it keeps all of it. Owners can unarchive it later. That is why archiving is a good first step after a shutdown: it stops accidental changes without losing the history that makes old code useful to anyone.
Can I sell code that has been archived for years?
Yes, in most cases. Age on its own does not disqualify code. What matters is that it is a complete product written by your own team, that it makes no money today, and that you own the rights or can sign for the company that does. Years in an archive often mean the secrets are stale, but they still need checking and removing before transfer.
Is a private archived repository safe from leaks?
Safer than a public one, but not safe by default. GitGuardian found that internal repositories are about six times more likely than public ones to contain hardcoded secrets. Anyone who still has access, including former staff and contractors, can clone it. Review who has access, rotate any key that was ever committed, and remove people who no longer need it.
What happens to archived code if my company is dissolved?
The code belongs to the company, not to you personally, so it follows the company's fate. In the UK, anything a dissolved company still owns passes to the Crown as bona vacantia. Rules differ by country, and this is general information, not legal advice. If a dissolution is coming, decide what to do with the code before it happens, with a lawyer's help.
Find out what your old code is worth right now.
Tell us about the product in about a minute. No code needed. We review the details and come back with a cash offer or a plain no.
Get my free code valuation →