Data Custody Risk Is Real and Underpriced
Nine PBS sued Iron Mountain after losing access to 50TB of archival data covering 70 years of television history. The data is not destroyed but legally encumbered, which in practice means the same thing operationally. Commenters immediately connected this to the Internet Archive and asked hard questions about how Iron Mountain got the contract in the first place, pointing to what appears to be a four-person company as the storage operator.
The web link rot post ran adjacent to this, citing a study that followed 657,607 links to measure how much of the old web is gone. The answer is: a lot of it. Both threads are about the same failure mode: organizations assuming someone else is responsible for long-term data integrity.
The pattern: data custody is treated as an operational cost center until it becomes a catastrophic liability. The assumption that a vendor relationship implies data access is wrong. Contracts matter, SLAs matter, and egress rights matter more than most people negotiate for.
So what?
Any founder storing customer data with a third-party vendor should read the Iron Mountain story and then read their contract. Specifically: what happens to your data access if the vendor is acquired, goes bankrupt, or enters a legal dispute with you? If the contract is vague, that's the risk you're carrying.