A software company that shuts down usually has one asset left that nobody priced: its code. The repositories, their history, the tickets and the docs represent years of work by a real team, and that work does not lose its value because the business stopped. The risk in the first month is practical, not legal: accounts get cancelled in the wrong order, the last engineer leaves with the only admin login, and a codebase that could have been sold or reused disappears. This checklist keeps the options open while you close everything else.
Shutdowns are common, so there is no shame in planning one well. Carta counted 254 startup shutdowns on its platform in the first quarter of 2024 alone, up 58% from a year earlier, and it notes the true number is likely higher.
Why does the order of shutdown steps matter so much?
Most of a startup’s code lives in hosted services that are paid monthly on a company card. When the card is cancelled or the account closed, the host may eventually delete the data. The admin mailbox that receives password resets is often on the company domain. If the domain lapses, so does access to everything tied to it, and anyone who later registers it could receive your password reset emails.
That creates a simple rule: cancel the things that hold the code and the keys last. Cancel hosting, ad accounts and paid analytics first, once you have exported what you need. Keep source control, the domain and the main admin email running until the code is backed up and a decision about it is made.
What should you do in the first 30 days?
| When | Step | Why it matters |
|---|---|---|
| Days 1 to 3 | Secure admin access to source control, cloud and domain | Former staff may hold the only logins |
| Days 1 to 7 | Freeze the repositories (archive, do not delete) | Read-only protects history and keeps options open |
| Days 3 to 10 | Back up every repository with full history | A zip of the latest files loses the history |
| Days 5 to 14 | Export tickets, docs and design files | These tools are often cancelled first |
| Days 7 to 21 | Rotate every key and password | Leaked keys can still work years later |
| Days 10 to 30 | Decide who can sign for the company and what happens to the code | Needed before any sale or dissolution |
Secure admin access
List every account that holds code or controls access: GitHub, GitLab or Bitbucket, the cloud provider, the domain registrar, the app stores and the admin email. Make sure at least two people who will remain involved, usually a founder and a director, hold owner rights on each. Remove former employees and contractors. Turn on two-factor authentication everywhere.
Freeze, do not delete
Archiving a GitHub repository makes it read-only for everyone and can be reversed. That is the right default during a shutdown: nothing changes by accident, and nothing is lost. An archived repository still counts as complete code with its full history.
Back up with history
Clone every repository with all branches and tags, not just a download of the current files. The git history, meaning every commit and branch, shows how and why the software changed, and it is one of the things that makes old code worth more. Our guide on why git history matters explains what a zip export loses. Pull requests and review comments live on the host, not in git, so export them separately. Store the backup on encrypted storage the company, not an individual, controls, because old history usually still holds keys.
Export tickets, docs and designs
Issue trackers, wikis and design tools are often the first subscriptions to be cancelled. Export issues from GitHub Issues, Jira or Linear, wiki pages and runbooks, and design files from Figma. Our guide to docs, tests, tickets and designs covers what is worth keeping and what to leave out.
How should you handle secrets and customer data during a shutdown?
Rotate first. Any API key, password or token that was ever committed to a repository should be revoked or rotated. GitHub’s own guidance on removing sensitive data calls this the first step. This matters more than usual in a shutdown, because nobody will be watching the accounts. GitGuardian’s 2026 report found that 64% of valid secrets leaked in 2022 were still not revoked in 2026.
Deleting a file in a new commit does not remove it from history, so a secret committed years ago is still in every clone. Our guide to removing secrets from old code explains the full process.
Keep customer data separate from code. The production database, user records, logs and support chat history are a different asset with different duties. How long you keep them depends on your contracts and data protection law, so ask your lawyer; this is not legal advice. For the code itself, the simplest position is that no personal data should travel with it. Seed files, fixtures and test data sometimes contain real customer emails, and they need checking too.
Who can sign for the company once it is winding down?
Any sale of company code needs a written, signed transfer. In the US, a transfer of copyright ownership is not valid unless it is in writing and signed by the owner or its authorized agent, and the UK has a similar rule. While the company exists, a director or officer with authority usually signs. Investors or co-founders may need to approve, depending on your shareholder agreement.
Timing matters. In the UK, anything a company still owns when it is dissolved passes to the Crown, including its code. If a liquidator or administrator is appointed, they hold the power to sell instead of the directors. Our guide to selling code after dissolution or insolvency covers those cases. The practical advice is to decide about the code before the company is dissolved. This is general information, not legal advice; a qualified lawyer should confirm the right signatory for your company.
What are your options for the code after the shutdown?
Once the code is safe, you can choose calmly between selling it, open sourcing it, keeping it archived, relaunching or deleting it. If the product made no money at the end, marketplaces that price businesses on revenue or profit are usually not a fit, because they sell running businesses.
The Blue Ocean Code is one option for a shut-down product. Odys AI Labs, the research and development arm of Odys, buys the source code of software that is no longer used and uses it for AI training and R&D. We may also work on it with research partners, and the agreement sets out exactly what rights transfer. It pays cash only, one agreed price, paid on transfer, with an offer after review and no obligation. No code changes hands before a signed written agreement, and it never asks anyone to install or run anything. It never takes databases or customer data and never uses your brand or relaunches the product as yours. The shut-down SaaS situation page explains what such code is typically still worth.
If the old product also had a marketing website with traffic, that is a separate asset; The Blue Ocean Websites buys websites of former businesses.
What to do next
- Today: confirm two people hold owner access to source control, the domain and the admin email.
- This week: archive and back up every repository with full history, then export tickets and docs.
- Before dissolution: decide what happens to the code, and if selling fits, send us a few details for a free code valuation.
Frequently asked questions
Should I delete our GitHub repositories when the startup shuts down?
Not in the first weeks, and usually not at all until you have decided what to do with the code. Deleting ends every option, including selling it, open sourcing it or reusing it. Archive the repositories instead, which makes them read-only and can be undone, and keep a full backup with git history somewhere the company controls. Decide on deletion only after legal and the board have agreed.
What happens to the code if the company is dissolved before we sell it?
It depends on the country. In the UK, anything a dissolved company still owns, including its code, passes to the Crown as bona vacantia, and getting it back means restoring the company or buying it back. Other countries have their own rules. Decide what to do with the code before dissolution, and ask a lawyer about your specific case.
Do we need to keep the production database after shutting down?
That depends on your legal duties to customers, accountants and regulators, so ask your lawyer. What matters for the code is that the database is separate from it. A buyer of source code for research has no use for customer records, and The Blue Ocean Code never takes databases, user records, customer data or chat logs, so you can deal with data under your own retention and deletion rules.
Which accounts should we cancel last?
Cancel the source control host, the domain registrar and the main admin email last. Source control holds the code and history, the domain controls email and logins, and the admin mailbox receives password resets for everything else. Cloud hosting, paid analytics and marketing tools can usually go first, once you have exported anything you need from them.
Find out what your old code is worth right now.
Tell us about the product in about a minute. No code needed. We review the details and come back with a cash offer or a plain no.
Get my free code valuation →