Sell Data to AI
Home Data Asset Score Pricing API documentation US labs and CROs list
For brokers
How to become an AI data broker Data broker business model Buyer programs compared Qualify a company AI training data companies
For data companies
Firmographic data providers Company data API
Seller guides
How to sell data to AI companies Is it legal? FAQ and glossary About
Check domain/company
Selling well

How to Prepare Your Company Data for Sale to AI Buyers

The buyer runs the export, the de-identification and the payment. The decisions about what leaves your company are yours, and they are best made before anyone sends you an offer. Six steps, in order.

Last checked: 7 October 2026. Buyer terms are quoted as published on that date.

6 stepsinventory, scope, exclusions, retention, secrets, signers
20+ / 30+employee minimums published by Mode and micro1
Manifestand samples first; never the full dataset before a price
60 to 90 daystypical time to close, practitioners say

Why prepare before you apply

Preparation does two jobs. It removes the delays that sit on the seller’s side, and it means you negotiate knowing exactly what you are offering and what you are not.

None of this requires sending data anywhere. It is internal work: lists, a written scope, a few checks and a decision about who approves. Most of it also helps with the broader process described in how to sell data to AI companies, and it shortens the stages covered in how long an AI data deal takes.

Work through the steps in order. Each one uses the output of the one before: the inventory feeds the scope, the scope tells you where to look for exclusions, and the exclusions and retention check decide what the secrets scan has to cover. The last step, naming who signs, turns the result into a decision your company can actually make.

1 Inventory

List every system, its owner and its history

Start with the systems buyers name. For each one, record who administers it, how many years it covers, roughly how much is in it, and how it can be exported.

CategorySystems buyers listRecord for each
Communication and documentsGmail, Outlook, Google Drive, SharePoint, Slack, Microsoft Teams, Notion, Confluence, Dropbox, DocuSign, Zoom recordings and transcriptsAdmin, years, rough volume, which teams use it
Work tracking and supportJira, Asana, Monday.com, Zendesk, ServiceNowProjects or queues, years, links to other systems
Sales and financeSalesforce, HubSpot, QuickBooks, Xero, NetSuite, PaychexWhich records hold customer or payroll data
Design and tradesAutoCAD, Figma, ServiceTitanWho owns the files: you or the client
CodeGitHub, GitLab and Bitbucket repositories with historyRepos, years, contractors, third-party code

Years matter. Mode asks for several years of records the company owns, and micro1 looks for mature operations and documented processes (both as published). Note where systems connect: a ticket that links to a commit, or a CRM record that links to an email thread. Connected records are what buyers describe wanting, and the links are easy to lose in a careless export. For code specifically, see codebases and git history.

2 Scope

Write down what you are willing to offer

micro1 says scope is agreed in writing; Mode says it buys “an agreed copy” (both as published, checked 7 October 2026). Arrive with your own draft so the agreed version starts from your words.

A good scope statement names the systems, the teams or projects, the date range and the data types, and refers to the exclusions list. It should be short enough that a non-lawyer at your company can read it and know what is leaving. If it takes a page to explain, the scope is probably too wide for a first deal.

Illustrative scope statement, fictionalJira projects OPS and FIN and the Operations and Finance Confluence spaces, January 2019 to June 2026, including comments and page history; excluding attachments, the HR space, any page or issue tagged with a client name, and every item on the attached exclusions list.
3 Exclusions list

Decide what never leaves, by category

The exclusions list is the most important document you will write. It protects your clients, your staff and you, and it makes the scope easy to defend.

Client-confidential material

Anything covered by NDAs or engagement terms with clients. See client confidentiality and data sales.

Privileged and legal

Communications with counsel, dispute files and anything under attorney-client privilege.

HR and employee records

Performance reviews, pay, health and leave records, disciplinary files, recruiting notes.

Health and regulated data

Patient information under HIPAA, and customer financial data that may fall under GLBA.

Customer personal data

Customer contact lists, payment details and account records. micro1 states no customer information is exposed; your list should make that easy to keep true.

Third-party material

Vendor manuals, licensed stock, purchased reports, open-source code and anything you did not create.

Add security runbooks, board materials and M&A files if you have them. Keep the list as categories plus named exceptions, and attach it to the scope. General information, not legal advice. Talk to your own lawyer before you sign.

4 Retention check

Confirm what you still hold, and what you should not

5 Secrets scan

Find credentials everywhere, not only in code

De-identification is aimed at people’s details. Passwords, API keys and access tokens are your job.

Where secrets hide

Code history, wiki pages, chat messages (“here is the login”), support tickets, shared spreadsheets, CI settings, email threads with vendors and screenshots.

What to do with them

Rotate every credential you find before any export, then exclude or redact the item. A rotated key is harmless if it slips through; a live one is not.

How to search

Use secret-scanning tools on repositories, including their full history, and keyword searches (password, token, key, login) in chat, wiki and ticket systems.

Who owns it

Your IT or security lead. They should sign off that the scan was done before the scope is final.

6 Who signs internally

Name the approvers before an offer arrives

Offers can come with deadlines. Knowing who must say yes, and what each person is checking, stops a good offer from expiring in someone’s inbox.

RoleWhat they decide or check
Owner or CEOWhether to sell at all, which buyers, and the final signature.
Finance leadPayment structure, milestones, tax treatment and how the income is booked.
Legal counselThe agreement, client contracts, exclusivity, warranties and indemnities.
IT or security leadExport access, the secrets scan, and what systems the buyer touches.
HR or people leadEmployee notice and how staff hear about it.
Privacy leadPersonal data, EU and UK records, retention and deletion promises.
Board or partnersApproval where your governing documents require it.

In a 25-person company several of these roles are the same person. That is fine, as long as each question has been asked by someone.

+ The manifest

What the manifest should contain

The six steps produce one document a buyer can review without seeing your data. Keep it short: one page per system is plenty for a first conversation.

FieldWhat to write
Company profileIndustry, full-time staff, where the team works, primary business language.
SystemsEach system in scope, with the teams that use it.
Date rangeFirst and last month covered, and any gaps from auto-deletion or migrations.
VolumeApproximate counts: tickets, pages, messages, repositories, hours. Rough is fine; invented is not.
ConnectionsWhere records link across systems, such as tickets to commits or projects to documents.
ExclusionsThe categories excluded and the reason for each, without naming clients.
FormatHow the data can be exported and what the export includes, such as history, comments or attachments.
SamplesWhat samples are available after an NDA, and how they were chosen.

The company profile row maps directly onto what programs publish as eligibility: employee counts, location, language and years of records. The eligibility checker uses the same inputs, so running it first is a quick way to see which programs your manifest should be sent to.

+ Samples

Choosing samples that are honest and safe

! Common mistakes

Six preparation mistakes that cost time or leverage

Applying first, preparing later

An offer that arrives before your inventory exists forces rushed decisions about scope and exclusions.

Scoping everything

“All our data” is not a scope. It cannot be checked, defended to staff or warranted in a contract.

Exclusions in someone’s head

An exclusions list that is not written down cannot be attached to the agreement or applied consistently.

Overstating history

Promising seven years when email auto-deleted after three damages trust at the review stage.

Scanning only code

Credentials in chat, wikis and tickets are as live as those in a repository.

Leaving out HR until the end

Employee notice is easier to plan than to repair. Bring the people lead in at the start.

Illustrative example, fictional, not an offer

A fictional 60-person logistics company after six steps

  • Inventory: 11 systems, 7 years of history in Jira, Slack and Confluence; email auto-deletes after 3 years.
  • Scope: operations tickets, dispatch channels and the Operations wiki, 2019 to 2026.
  • Exclusions: HR, finance, all customer contact data, two client accounts under strict NDAs, attachments.
  • Retention: one 2023 dispute under legal hold, kept out entirely.
  • Secrets: 40 credentials found in chat and wiki pages, all rotated.
  • Signers: CEO, CFO, outside counsel, IT manager.

The output is a one-page manifest and a few samples per system. No price appears because nobody can value data without reviewing it.

With the manifest ready, apply to more than one program at once. Practitioners advise sharing the manifest and samples, never the full dataset, before you have a price, and getting more than one offer; our guide to getting more than one offer explains how to compare them.

? Questions to ask the buyer

Questions your preparation lets you ask

A prepared seller can ask sharper questions, because the answers map onto decisions already made.

Write the answers down for each buyer. When more than one offer arrives, the comparison is on terms as well as price, and these notes are the terms.

Ready to apply

Programs and their published criteria

Quoted from each program’s own pages, checked 7 October 2026. Published ranges are not promises of amount, acceptance or timing.

micro1: 30+ employees, mature operations, documented processes, modern software tools, primarily English, US first; “$100k+ qualified,” “$500k+ large-scale,” “$1M+ highly unique.” Mode: 20+ full-time US office employees (accounting firms 10+, law firms 6+), several years of records the company owns; “$100K-$5M.” Grepped: any vertical; “$20K-$5M.”

Independent site. Some links are referral links: if your company signs with a buyer through them, the buyer may pay us a fee. You are not charged, and we never see your data.

Questions about preparing data for sale

What should a company do before applying to sell its data?
Six things: list the systems and years of records you hold, write a plain-language scope, build an exclusions list, check retention policies and legal holds, scan for secrets, and decide who has to sign internally. Then prepare a manifest and samples rather than a full export.
Do I need to clean or de-identify the data myself?
Buyers describe doing the de-identification themselves; Mode says it de-identifies before onward delivery, and micro1 says sensitive and confidential information is scrubbed (both as published, checked 7 October 2026). Your job is earlier: decide what is excluded entirely, remove secrets, and verify samples. Ask each buyer what it expects from you.
What is a data manifest?
A short document that describes what exists without handing it over: systems, teams, date ranges, approximate volumes, formats and what has been excluded and why. Practitioners advise sharing a manifest and samples, never the full dataset, before you have a price.
Who inside the company needs to approve a data sale?
At least the owner or CEO, plus whoever handles finance, legal, IT or security, and HR. Companies with clients under confidentiality terms, EU staff or customers, or a board or partners will need those people too. Decide this before you apply, not after an offer arrives.
Can I keep data past its retention period because a buyer might want it?
Be careful. If a policy, a contract or a law says data should be deleted after a set time, keeping it to sell can create its own problem. Records under a legal hold are a separate case: they must not be altered or destroyed. Ask your lawyer before you change any retention practice.
How long does preparation take?
It depends on the number of systems, the data types and how many client contracts need checking. A small company with a few systems can often work through the six steps in a few weeks of part-time effort. It is time well spent: it shortens the seller-side stages of the deal itself.
Do I need a lawyer before I apply?
Not to apply, but you will need one before you sign, and briefing a lawyer during preparation saves time later. Bring them in early if you hold client-confidential, health or financial data, or have staff or customers in the EU or UK.
Is it worth preparing if we are not sure we will sell?
Yes. The inventory, exclusions list and retention check are useful on their own: they show what records you hold, where sensitive material sits and whether your retention practice matches your policies. If you decide not to sell, nothing has left the company.